GlobalSign plans to reopen Tuesday despite web server hack
- 12 September, 2011 17:38
- Comments
GlobalSign expects to bring its certificate-issuing systems back online on Monday, and resume business Tuesday, it said over the weekend. The U.S. certificate authority (CA) stopped issuing new SSL certificates last Tuesday in order to audit its security, after being named as a target by the hacker who claimed to have attacked Dutch CA DigiNotar.
The server hosting GlobalSign's website was breached, the company said Friday. The server was isolated from other infrastructure related to certificates, the company said.
On Sunday the company confirmed its earlier plan to bring system components back online Monday in a sequenced startup, but said customers were unlikely to be able to process orders until Tuesday morning.
It said that there was no further evidence of breach other than the isolated web server. But it continued to monitor all activity to all services closely as an additional precaution, it said.
All forensics are being shared with the authorities and other CAs to assist with their own investigations into other potentially related attacks, GlobalSign said. It did not specify who the attacker was.
The company has employed security firm Fox-IT to investigate.
Fox-IT already has experience of this kind of investigation: It was hired by DigiNotar to discover how its servers were hacked. DigiNotar's servers had been used to issue hundreds of fake SSL certificates, including one for the domain google.com.
The attack on DigiNotar was discovered when an Iranian Gmail user noticed something amiss with the webmail service, and the problem was traced to the fake certificate.
Close to 300,000 unique IP addresses from Iran requested access to google.com between Aug. 4 and Aug. 29, while the rogue certificate was in use, according to Fox-IT's interim report for DigiNotar.
A hacker claimed last Monday in a message on Pastebin that he had broken into DigiNotar, and also had access to four other CAs including GlobalSign. The hacker is known as Ich Sun, or Comodohacker -- a reference to the person's claims earlier this year to have broken into the servers of another certificate issuer, Comodo.
John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Top 10 Mistakes in Data Centre Operations: Operating Efficient and Effective Data Centers
For years, the data centre industry has accepted that human operational error, not poor data centre design or engineering, is the number one cause of data centre downtime. Now is the time for companies to evaluate their data centre operations programs. They must be able to clearly articulate operational requirements and design an operations program based on the risk profile of the data centre. However, the road to creating an industry-best operations program will not be easy, especially for those companies whose core expertise is not in business critical facilities. Read on. -
Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more. -
HP ePrint Enterprise mobile printing solution
The merger of mobile devices and cloud services has become one of the most significant enablers of business productivity and innovation in the past decade. We now hold the power of communicating and computing in the palms of our hands, nearly anywhere business or life takes us. However, one key business process has eluded the mobility movement: printing. Even the most technically enabled business travelers find themselves hunting down print services while on the road and interrupting IT managers when visiting a branch office simply to print a document. But finally, a truly mobile print experience is available—helping enterprises to drive business productivity further. Read more.
-
Computers for Seniors for Dummies, 2nd Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Microsoft Office
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Seniors for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies








Comments
Post new comment