<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; digital certificates</title>
	<atom:link href="http://venturebeat.com/tag/digital-certificates/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Sat, 18 May 2013 10:15:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; digital certificates</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>Misstep could have led to fake Google site, man-in-the-middle attacks</title>
		<link>http://venturebeat.com/2013/01/03/google-digital-certificates/</link>
		<comments>http://venturebeat.com/2013/01/03/google-digital-certificates/#comments</comments>
		<pubDate>Fri, 04 Jan 2013 03:18:34 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[digital certificates]]></category>
		<category><![CDATA[man-in-the-middle attacks]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=598826</guid>
		<description><![CDATA[<p>Google no longer trusts a Turkish digital certificate distributor after the organization issued two "intermediate certificate authorities" that would allow anyone to impersonate a&#160;website.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=598826&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://venturebeat.files.wordpress.com/2013/01/google-logo.jpg" target="_blank"><img class="size-full wp-image-598835 aligncenter" alt="Google" src="http://venturebeat.files.wordpress.com/2013/01/google-logo.jpg?w=668&#038;h=473" width="668" height="473" /></a></p>
<p>Google got an early lump of coal on Christmas Eve <a href="http://googleonlinesecurity.blogspot.com/2013/01/enhancing-digital-certificate-security.html" target="_blank" target="_blank">when the company discovered</a> &#8220;an unauthorized digital certificate for the &#8216;*.google.com&#8217; domain.&#8221; This means someone out there was trying to pretend to be Google.</p>
<p>Google was able to follow the falsified certificate back to Turktrust, an organization that issues digital certificates in Turkey. Digital certificates show you and the website you&#8217;re accessing that you can trust each other. When you access Google, you&#8217;re supposed to trust that it is Google. If your certificate is fake, however, you don&#8217;t know whose website you&#8217;re actually accessing.</p>
<p>After Google got in touch, the certificate company realized that it had wrongly given out two &#8220;intermediate certificate authorities&#8221; in August 2011. As Google explains in a blog post, &#8220;Intermediate CA certificates carry the full authority of the CA, so anyone who has one can use it to create a certificate for any website they wish to impersonate.&#8221;</p>
<p>Because of this, both Google&#8217;s Chrome browser and now <a href="https://blog.mozilla.org/security/2013/01/03/revoking-trust-in-two-turktrust-certficates/" target="_blank" target="_blank">Mozilla&#8217;s Firefox</a> will no longer &#8220;trust&#8221; certificates form Turktrust. <a href="http://technet.microsoft.com/en-us/security/advisory/2798897" target="_blank" target="_blank">Microsoft has also followed suit</a> and gone so far as to identify the two organizations that received the intermediate certificate authorities. They are *.EGO.GOV.TR and e-islem.kktcmerkezbankasi.org.</p>
<p>&#8220;The *.EGO.GOV.TR subsidiary CA was then used to issue a fraudulent digital certificate to *.google.com,&#8221; said Microsoft in a blog post. &#8220;This fraudulent certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against several Google web properties.&#8221;</p>
<p><em>hat tip <a href="http://www.wired.com/threatlevel/2013/01/google-fraudulent-certificate/" target="_blank" target="_blank">Wired</a>; <a href="http://www.flickr.com/photos/scobleizer/4249731778/sizes/l/in/photostream/" target="_blank" target="_blank">Google image</a> via <a href="http://www.flickr.com/photos/scobleizer/" target="_blank">Robert Scoble</a>/Flickr</em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=598826&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/01/03/google-digital-certificates/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/01/google-logo.jpg?w=160" /><source url="http://venturebeat.com/2013/01/03/google-digital-certificates/">Misstep could have led to fake Google site, man-in-the-middle attacks</source>
		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/01/google-logo.jpg" medium="image">
			<media:title type="html">Google</media:title>
		</media:content>
	</item>
	</channel>
</rss>
