Hackbloc hacktivist collective - researching positive hacktivism

verizon

EFF Asks Verizon to Remove Un-Reliable Certificate Authority

The Electronic Frontier Foundation has asked Verizon, a certificate authority, to stop trusting the certificate issued to Etisalat.

Etisalat was caught using its authority to sign an update for blackberries in the United Arab Emirates which caused malicious code to be downloaded onto blackberry user's devices without their consent. This code (better called surveillance software) was used by the government of the UAE to spy on blackberry users.

Because browsers and other software trust Etisalat's authority, this means that any users SSL connection with any site could be hijacked completely transparently. This leaves their personal information vulnerable as well as their computers if they download executable code which is signed by Etisalat.

Hopefully Verizon revokes this certificate and the SSL trust system will be made slightly more secure. As long as trust for this system is not distributed and resides in a hierarchy, problems like this will continue to occur.

Syndicate content

User login

To prevent automated spam submissions leave this field empty.

Submit A Story

Have a tip for your editors? Send it to staff@h*ckbloc.org  You can use our pgp key which can be found here.

Donate to HackBloc!

Donate to hackbloc to help us keep it running!
Why You Should Donate





Powered by Drupal, an open source content management system