The Recent RA Compromise

March 23, 2011 | By Phillip Hallam-Baker

On March 15th 2011, a Comodo affiliate RA was compromised resulting in the fraudulent issue of 9 SSL certificates to sites in 7 domains. Although the compromise was detected within hours and the certificates revoked immediately, the attack and the suspected motivation require urgent attention of the entire security field.

At no time were any Comodo root keys, intermediate CAs or secure hardware compromised. The compromise occurred at an affiliate authorized to perform primary validation of certificate requests. The compromise was promptly reported to the owners of the domains affected and the major browser providers and to the relevant government authorities.

In this blog post I will set out the relevant events as they are currently understood. More detailed information can be found in the incident report. The following post will consider what the events imply for the threat model for Internet security and the posts after that will set out specific remediation actions required.

An attacker obtained the username and password of a Comodo Trusted Partner in Southern Europe.  We are not yet clear about the nature or the details of the breach suffered by that partner other than knowing that other online accounts (not with Comodo) held by that partner were also compromised at about the same time.

The attacker used the username and password to login to the particular Comodo RA account and effect the fraudulent issue of the certificates.

The attacker was still using the account when the breach was identified and the account suspended. The attacker may have intended to target additional domains had they had the opportunity.

Remediation efforts began immediately the breach was discovered. The certificates have all been revoked and no Web browser should now accept the fraudulently issued certificates if revocation checking is enabled. Additional audits and controls have been deployed as described in the detailed incident report.

The IP address of the initial attack was recorded and has been determined to be assigned to an ISP in Iran. A web survey revealed one of the certificates deployed on another IP address assigned to an Iranian ISP. The server in question stopped responding to requests shortly after the certificate was revoked.

While the involvement of two IP addresses assigned to Iranian ISPs is suggestive of an origin, this may be the result of an attacker attempting to lay a false trail.

It does not escape notice that the domains targeted would be of greatest use to a government attempting surveillance of Internet use by dissident groups. The attack comes at a time when many countries in North Africa and the Gulf region are facing popular protests and many commentators have identified the Internet and in particular social networking sites as a major organizing tool for the protests.

Government attacks against social networking sites are not a new phenomenon. In the wake of the 2009 protests, Twitter was disabled for an hour by a group calling itself the Iranian Cyber Army. In recent months we have seen a complete shutdown of the Internet in Egypt and in Libya. The Tunisian government authorities also attempted an attack against login credentials at social networking sites but through a JavaScript attack. A recent article in the London Daily Telegraph describes measures taken against the Tor onion routing infrastructure by Iran.

The new threat model evidenced by these attacks will be considered in greater detail in the next post.

Posted in Data Security

6 Comments

Leave Comment
  1. [...] use to a government attempting surveillance of Internet use by dissident groups.” Source: http://blogs.comodo.com/it-security/data-security/the-recent-ra-compromise/ GA_googleAddAttr("AdOpt", "1"); GA_googleAddAttr("Origin", "other"); [...]

  2. [...] by admin var addthis_product = 'wpp-256'; var addthis_config = {"data_track_clickback":true}; One of the most famous security company, Comodo had one of their RA compromised. For those who are unfamiliar with PKI technology and not too sure what a RA is, here let me explain to you a little. RA is also known as Registration Authority, where this sub-model of the PKI is responsible of issuing digital certificates. What happen here was while the RA was compromised, it was used by the attacker to issue a fraudulent SSL certificates. SSL stands for Secure Socket Layer and these certificate is mainly used by web servers in providing a ‘https’ environment. Issuing these fraudulent SSL certificates means that the attacker will attempt to use these certificates to host some malicious website. Quickly, it was mentioned that the root keys, the intermediate CA and the security hardware were not affected. Thus, the problem is only on the issued certificates. Comodo had already take the action of revoking all the fraudulent certificates and it should not be able to use now. Microsoft also released a patch to include the nine revoked SSL certificates by Comodo. How this could happen is that one of the staff’s username and password were stolen at the southern part of Europe. Attacker use this username and password to login and issue certificates. When the breach was identified, the attacker still using that username to login and they might be interested to go into other domain and perform the same thing. It was rumored that the IP of the attacker were from Iran however, this does not direcly put the blame into Iran without further investigation. It was just suspect that the attacker was from there. It was also further added by them that the domains targeted “would be of greates use to a government attempting surveillance of Internet use by dissident groups.” Source: http://blogs.comodo.com/it-security/data-security/the-recent-ra-compromise/ [...]

  3. StartSSL is also a very popular, especially self-employed like to use the CA, the console login page must be certified through the Client certificate encryption measures to find many people by the trust. Following the results back to Comodo killed on the event, this sector of the Swiss Army Knife is also known as CA shot last week, although part of the official certificate issued instructions not compromised, but the user is still very worthy of consideration.

  4. Vince says:

    Great blog my friend, keep posting!

  5. [...] 1.  http://blogs.comodo.com/it-security/data-security/the-recent-ra-compromise/ [...]

  6. josey jasen says:

    I just stumbled upon your blog and wanted to say that I have really

    enjoyed browsing your blog posts. In any case I’ll be subscribing to

    your feed and I hope you write again soon!

    http://theindianstudio.com/

Leave a Comment


+ two = 8

* fields are mandatory

Comodo Blogs

IT Security

Data Security