Darknet Vendors Sell Counterfeit TLS Certificates

Last August, Symantec announced it was selling its digital security certificate business to DigiCert. It followed a long-running quarrel with Google, which alleged that loose security controls at Symantec allowed bad actors to buy TLS certificates. Such certificates, for use with Transport Layer Security, provide authentication and data encryption between servers.

Counterfeit TLS certificates pose a big security risk. Fraudulent certificates issued in the name of real services could be used to support phishing scams. Fake certificates might also be used to intercept and decrypt traffic via a man-in-the-middle attack (see Microsoft Blacklists Fake Certificate).

Read full news article on bankinfosecurity.com

 


Date:

Categorie(s):