F-Secure is reporting that Diginotar, a CA trusted in common OSes and browsers, was repeatedly breached, and the defacements have lived on their website unnoticed for years. If you keep digging deeper, you'll find that although these web defacements are still live right now, they are not new. Much worse: they were done years ago.
Certificate Authorities are a critical keystone in the security of the Internet. For a CA to have been repeatedly breached over the course of years and not notice is totally unacceptable. This demands immediate consideration from the organizations that approve certificate authorities. Higher standards and stronger auditing are necessary. Diginotar Hacked by Black.Spook and Iranian Hackers - F-Secure Weblog : News from the Lab |