• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Twenty Three Thousand SSL certificates are to be revoked on March 1st, 2018.

March 1, 2018Simeon Georgiev

This is due to a security breach in a firm called Trustico. Trustico, is the certificate issuer for digicert based in the UK. This is going to be a landmark move that is going to definitely going to affect the Certificate Authority industry in the months to follow. This incident took place when Digicert asked to revoke certificates over a security issue that lead to Trustico selling directly to customers.

At that point the general manager for trustico had denied that the company had faced any security incident.

The events unfolded as such: – On 2nd Feb an email was sent to Trustico to cancel all of the fifty thousand certificates managed. This lead to Trustico dropping out of contract with Symantec (part of Digicert) and moving to partner with Comodo.

Digicert denied the request to cancel the fifty thousand certificates claiming that the industry rules do not show precedence. It was only when Trustico claimed to take legal action that this was moved ahead. Digicert ended the contract on the 25th of February, 2018 with Trustico that was confirmed on twitter by a Digicert employee.

As far as the actual certificates go, Digicert’s stance is that they will mass-revoke the certificates if the evidence proves that they were indeed compromised during the time the customers’ private keys were also affected. On the 27th of December Digicert received and email containing over twenty three thousand private keys from Trustico. In light of certificate authority rules the affected/compromised certificate needs to be terminated within twenty four hours of incident.

Digicert has sent over twenty three thousand emails to customers warning them about the impending termination of their certificates. This has raised suspicion that has several cyber security gurus publicly accusing Trustico of allegedly loggin copies of SSL certificate private keys. It is clearly stated that the companies are not supposed to have copies of private keys as per certificate authority rules.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Own a Machine Infected by Amnesia Ransomware? Here’s What You Can Do Next post A 1.3 Tbps DDoS attack courtesy of Memcached Servers

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

BitPaymer Ransomware Traced Back to Dridex Developers

February 1, 2018Simeon Georgiev
BitPaymer Ransomware Traced Back to Dridex Developers

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.