Experts warn of a weak link in the security of websites

Advertisement
By Miguel Helft, New York Times | Updated: 5 June 2012 02:26 IST
Highlights
  • Computer security researchers are raising alarms about vulnerabilities in some of the Web’s most secure corners: the banking, e-commerce and other sites that use encryption to communicate with their users.
Computer security researchers are raising alarms about vulnerabilities in some of the Web's most secure corners: the banking, e-commerce and other sites that use encryption to communicate with their users.

Those sites, which are typically identified by a closed lock displayed somewhere in the Web browser, rely on a third-party organization to issue a certificate that guarantees to a user's Web browser that the sites are authentic. But as the number of such third-party "certificate authorities" has proliferated into hundreds spread across the world, it has become increasingly difficult to trust that those who issue the certificates are not misusing them to eavesdrop on the activities of Internet users, the security experts say.

"It is becoming one of the weaker links that we have to worry about," said Peter Eckersley, a senior staff technologist at the Electronic Frontier Foundation, an online civil liberties group.

The power to appoint certificate authorities has been delegated by browser makers like Microsoft, Mozilla, Google and Apple to various companies, including Verizon. Those entities, in turn, have certified others, creating a proliferation of trusted "certificate authorities," according to Internet security researchers.

According to the Electronic Frontier Foundation, more than 650 organizations can issue certificates that will be accepted by Microsoft's Internet Explorer and Mozilla's Firefox, the two most popular Web browsers. Some of these organizations are in countries like Russia and China, which are suspected of engaging in widespread surveillance of their citizens.

Mr Eckersley said Exhibit No. 1 of the weak links in the chain is Etisalat, a wireless carrier in the United Arab Emirates that he said was involved in the dispute between the BlackBerry maker, Research In Motion, and that country over encryption. The UAE threatened to discontinue some BlackBerry services because of RIM's refusal to offer a surveillance back door to its customers' encrypted communications. Mr Eckersley also said that Etisalat was found to have installed spyware on the handsets of some 100,000 BlackBerry subscribers last year. Research In Motion later issued patches to remove the malicious code.

Yet Mr Eckersley said that Etisalat was one of the "certificate authorities" and could misuse its position to eavesdrop on the activities of Internet users.

In an open letter signed by Mr Eckersley, the Electronic Frontier Foundation is asking Verizon, which issued Etisalat's power to certify Web sites, to consider revoking that authority.

Verizon declined to comment. Etisalat did not respond to an e-mail requesting comment.

Mr Eckersley wrote that Etisalat could issue fake certificates to itself for scores of Web sites, including google.com, Microsoft.com and Verizon.com, and "use those certificates to conduct virtually undetectable surveillance and attacks against those sites." Etisalat could also eavesdrop on virtual private networks used by corporations to communicate securely around the world, he wrote.

"We believe this situation constitutes an unacceptable security risk to the Internet in general and especially to foreigners who use Etisalat's data services when they travel," he wrote, adding that the foundation did not know whether Etisalat had misused its authority yet.

Concerns about certificates have been raised before. When Firefox considered granting certificate authority to a Chinese company earlier this year, members of the Firefox community worried that the company might be pressured by the government to eavesdrop, for example, on the Gmail accounts of Chinese dissidents. Eventually, Firefox decided to go ahead with the process.

Other security experts said that they were concerned about the proliferation of certificate authorities.

"I think it is a really big deal," said Stephen Schultze, associate director of the Center for Information Technology Policy at Princeton University. Mr Schultze said that the problem "is not a reason to panic and stop doing online banking or e-commerce. But it is a bad enough problem that it should be receiving a lot more attention and we should be trying to fix it."

Some browser makers, however, suggested that while attacks were possible in theory, the system had worked reasonably well for more than a decade.

"It has proven itself historically to be relatively secure," said Johnathan Nightingale, Mozilla's director of Firefox development. Mr Nightingale said that many e-commerce sites were using a new type of certificate that required extensive verification. If a certificate authority was misusing its power to eavesdrop, he said, a user with technical skills could detect the attack, and the organization's power to issue certificates would be revoked.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  2. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  3. Heartiley Battery Streaming Now Online: Know Everything About Plot, Cast, and More
  4. Nothing Phone 3a Lite Review: The Best Mid-Range Design
  5. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  6. Google Says It Will Discontinue Its Dark Web Reports Due to This Reason
  7. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  1. Sub-Millimeter Robots Can Sense, Think, and Act Autonomously, New Study Finds
  2. Earth’s Atmosphere Has Been Leaking Onto the Moon for Billions of Years, Study Finds
  3. New Orbital Clues Reveal How Hot Jupiters Moved Close to Their Stars
  4. Heartiley Battery Out on OTT: Know Where to Watch This Tamil Sci-Fi Series Online
  5. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  6. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
  7. Ishq Vishk Rebound Out on OTT: Know Where to Watch This Rohit Saraf Starrer Romcom
  8. Theeyavar Kulai Nadunga Now Streaming Online: Where to Watch This Dark Psychology Thriller
  9. My Lottery Dream Now Available For Streaming Online On This Platform: What You Need to Know
  10. Global Smartphone Shipments to Slightly Shrink in 2026 Due to RAM Shortage, Higher Component Costs: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.