1. Click Subscription of Mr.Chris Farrell Membership $4.95 7 day Trial For Newbies/Dummies - Not Criminal IM Coach/Mentor.
2. Click DirecTV For US Satellite TV Subscription. Also Dish Network Call Now Toll Free : 877-287-3983 for an Obligation Free Chat.
3. Click 100DayLoans.com for cash advance payday loan 100 days repayment,SUBJEST to your State Laws Also Credit Reports and Scores
4. CLICK Coupon Codes & My Web Hosting Reviews/Recommendation
affiliate_link__affiliate_link__ ______
Showing posts with label Mozilla. Show all posts
Showing posts with label Mozilla. Show all posts

Monday, April 11, 2011

Mozilla Regrets Silence Over Stolen SSL Certificates

 By Nicole Henderson, March 28, 2011

A screenshot of Mozilla's add-on website


(WEB HOST INDUSTRY REVIEW) -- Open-source organization Mozilla (www.mozilla.org) regrets keeping mum about stolen SSL certificates last week, according to a report Friday by Computerworld. Hackers stole certificates from some of the Internet's largest sites, including Google, Skype, Microsoft, Yahoo and its own add-on website.

Late last year, a database of 44,000 inactive Mozilla usernames and passwords was publicly disclosed by Mozilla.

According to the report, on March 15 attackers used a valid username and password to acquire nine SSL certificates from a Comodo certificate reseller.

The certificates were for Microsoft's Hotmail, Google's GMail, Skype, Yahoo Mail and Mozilla's Firefox add-on site.

Comodo came out with the news of the breach on March 23, but Mozilla was informed sometime between March 15 and March 23, according to the report. None of the browsers went public with the hack until March 22.

Computerworld says Google patched Chrome on March 17, but Mozilla and Microsoft issued updates to Firefox and Windows on March 22 and March 23, respectively.

"In hindsight, while it was made in good faith, this was the wrong decision. We should have informed Web users more quickly about the threat and the potential mitigations as well as their side-effects," Mozilla said in the report.

It was suspected that the Iranian government was involved in the attack and theft, and "speculated that the certificates were stolen to set up fake sites where authorities could identify activists and monitor their email and other digital communications," according to the report.

"By keeping this quiet for eight days, Comodo and others put lives at risk," Jacob Appelbaum, researcher at the University of Washington's Security and Privacy Research Lab said in a statement. "[Iranian activists] were completely unable to protect themselves during that time. Users should have had this information sooner."

"This was a gigantic failure on Mozilla's part," Appelbaum told Computerworld last week. "They believe disclosure will harm users. That's bogus."


Article Source http://www.thewhir.com/web-hosting-news/032811_Mozilla_Regrets_Silence_Over_Stolen_SSL_Certificates permits to repubish here
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Click Most Updated Discount Coupon Codes & My Personal Web Hosting Recommendations if you are interested in those.
Stay Tuned!
 <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
   affiliate_link

Monday, January 3, 2011

Mozilla Addresses The Leak Of User Information

(The Hosting News)
On December 17th, Mozilla received an email from a third party notifying the company of a file that contained user records that was posted to a public web server. The information in this file listed users email, addressses, first and last names, and MD5 password hashes.

The Company relied through an email stating “We immediately took the file off the server and investigated all downloads. We have identified all the downloads and with the exception of the thrid party who reported the issue, the file has been downloaded only by Mozilla staff.”

Since the the company has removed the passwords from their site and are asking users to reset their passwords for all content used through Mozilla. “We have identidied the process which allowed this file to be posted publicly and have taken steps to prevent this in the future.
We are also evaluation pther processes to ensure your information is safe and secure” the email also declared.

Chris Lyon, directore of infrastructure security at Mozilla, said on Decemeber 27th through a blog post, that the file included 44,000 inactive accounts using older, MD5 pasword hashes. The company erased the MD5 passwords, leaving the accounts inactive. Lyon also stressed that current users employ a more secure SHA-512 password hash with per-user salts and therefore are “not at risk.”

Chester Wisniewski, senior security advisor at Sophos Canada, addresses the problems with MD5 passwprd hashes” “MD5 has cryptographic weaknesses that permit creation of the same hash from multiple strings. This permit securty experts to compute all the possible hashes and determine either your password or another string that will work even if it is not your password.” Chester commened Mozilla’s response to the incident but questions how the company accidentall published this information to begin with and why MD5 password hashes were still in the system.

“If you are a web site administrator or developer, are you still storing passwords using methods like Gawkwer(DES) or Mozilla(MD5)? We know they are broken, and it is important to migrate away from these algorithms in case you have a database accidentally make its way outside of your orginization,” Wisniewski summarized.

Source: Share this storyDigg this storyAdd to del.icio.usAdd to RedditPosted Wednesday, December 29th, 2010. Filed under Industry News. Trackbacks/Pings Trackback URL
Related ArticlesFirefox Announces Major Security Flaw UpdateDedicated Server Firm, SoftLayer, Provides IPv6 SupportHostDime Receives RIPE and LACNIC IP AllocationsNetriplex Announces Year-End Colocation SpecialView News by CategoryFeaturesIndustry NewsWeb Hosting EventsWeb Hosting Talk Newsletter
View the Original article