(WEB HOST INDUSTRY REVIEW) -- Certificate authority StartSSL (http://www.startssl.com/) experienced a security breach on June 15, the company said in an advisory posted on its website.
Operated by Israel-based StartCom (http://www.startcom.org/), the certificate authority has suspended "issuance of digital certificates and related services" and wrote in its advisory that its "services will remain offline until further notice."
The attack makes StartSSL one of at least five SSL certificate authorities in three months to be compromised by hackers for the purpose of hijacking fraudulent certificates in order to spoof the authenticated pages of websites.
The past few months have seen attackers breach the website of certificates reseller Comodo Brazil, a Comodo reseller website in Italy, and two unnamed Comodo registration authorties.
In a report by The Register, StartCom CTO and COO Eddy Nigg said that the hackers also targeted many of the same websites targeted during the March attack against Comodo, which resulted in the forging of SSL certificates for Google mail, www.google.com, login.yahoo.com, login.skype.com, addons.mozilla.com, and Microsoft's login.live.com.
In the case of the StartCom attack, the hackers were unable to successfully steal any certificates that would allow them to spoof websites in a comparable manner as in the Comodo reseller attacks.
The attackers were also unable to create a certificate that would give them the power to be their own certificate authority because the company's private encryption key was not stored on a computer connected to the Internet, said Nigg.
StartCom has operated StartSSL since 2005, as well as hosting provider MediaHost since 1999.
While it is unclear how many certificates StartSSL has issued since its inception, Nigg said the certificate authority is among the top 10 issuers.
According to Netcraft's SSL survey, more than 25 thousand websites use certificates issued by StartSSL. The certificates are recognized by Internet Explorer, Firefox, Chrome and other popular Web browsers.
Article Source http://www.thewhir.com/web-hosting-news/062211_StartSSL_Suspends_Certificate_Services_Following_Security_Breach permits to republish here.
<<<<<<<<<<<<<
Click Most Updated Discount Coupon Codes & My Personal Web Hosting Recommendations
Click http://nightwishmarketing.web.officelive.com/WebHosting.aspx
Stay Tuned!
Click http://nightwishmarketing.web.officelive.com/WebHosting.aspx
Stay Tuned!
<<<<<<<<<<<<