DigiNotar hacker threatens to expand spy attacks using stolen certificates

08.09.2011

DigiNotar, one of hundreds of firms authorized to issue digital certificates that authenticate a website's identity, admitted on Aug. 30 that its servers were compromised weeks earlier. A report made public Monday said hackers had acquired 531 certificates, including many used by the Dutch government.

Comodohacker also provided details on the DigiNotar hack, saying that he had penetrated the Dutch company's network even though it was protected by a hardware security module, or HSM, and supposedly safeguarded by token-management systems provided by RSA and Thale.

RSA made the news last March when it that let attackers steal information related to its SecurID token system. A later hack of Lockheed Martin, one of the U.S.'s largest military contractors, was .

Because almost all the people affected by the DigiNotar attack were from Iran, many experts suspect that the hack was sponsored or encouraged by the Iranian government, which wanted them to .

Comodohacker denied that today, but admitted he had shared the stolen Google certificate with others. "I'm the only hacker, just I have shared some certs with some people in Iran, that's all," he asserted.