Hackers steal SSL certificates for CIA, MI6, Mossad

04.09.2011

Several security researchers said the move by browser makers puts an end to DigiNotar's certificate business.

"Effectively a death sentence for DigiNotar," said Jeremiah Grossman, CTO of WhiteHat Security, in a .

Mozilla was scathing in its criticism of DigiNotar.

Nightingale ticked off the missteps that led Mozilla to permanently block all sites signed with the company's certificates, including DigiNotar's failure to notify browser vendors in July and its inability to tell how many certificates had been illegally obtained. "[And] the attack is not theoretical," Nightingale added. "We have received multiple reports of these certificates being used in the wild."

Markham went into greater detail on the hack and its ramifications. "It has now emerged that DigiNotar had not noticed the full extent of the compromise," said Markham in a Saturday post to his . "The attackers had managed to hide the traces of the misissuance -- perhaps by corrupting log files."