There is a widely held perception that us humans live in dangerous times. Al Qaeda has re-established its bases in Pakistan and Afghanistan. Hizbullah, Hamas and other radical Islamic groups are gaining strength. Except that the evidence shows we are living in the safest time in our history. So why do we feel so scared? We can all point the finger at something or another; the news media, movies, and politicians. Our feelings about the state of security are based on them. So, what about information security? Some parallels can be drawn, I suppose. We hear about the hackers, viruses, and laptop thefts. Truth be told though, is that millions of people get online everyday from work and home, send[…]

Online banking giant, ING will begin providing software to its customers in the hopes that they’ll be able to bank online without having their accounts hacked on compromised machines. …The software works by assuming control over the application programming interfaces or APIs in Windows…A more advanced type of malware – known as a “form grabber” – hijacks the “WinInet” API – which sets up the SSL (think https://) transaction between the user’s browser and the encrypted Web site. By hijacking this API, a form grabber can rip out usernames and passwords even when the user is submitting them into a site that encrypts the data during transmission because it grabs that information at the lower level of the operating system,[…]

Laura let me know about Jailbreak, a useful, free program that will let you export certificates marked un-exportable by Windows. Jailbreak is a tool for exporting certificates marked as non-exportable from the Windows certificate store. This can help when you need to extract certificates for backup or testing. You must have full access to the private key on the file system in order for Jailbreak to work. The download is available here.

Pascal Meunier writes The entry for CVE-2006-4339 reached 16941 bytes, with 352 references. This is an OpenSSL issue, and highlights how much we are dependent on it. Vulnerabilities in any security suite aren’t something you ever want to hear about, particularly something as ubiquitous as OpenSSL. Whenever you use an application that has SSL capabilities, there’s a good chance you’re relying on OpenSSL for security, especially if the software doesn’t come from a company that has its own proprietary security suite (such as Microsoft or Mozilla). VMWare, Opera, various products from Sun, any Apache instance using mod_ssl…there’s a lot out there that needs to be patched right now. You may want to do a quick search of your systems for[…]

The MSDN documentation for CertGetCertificateChain is pretty unclear when describing how the CERT_CHAIN_TIMESTAMP_TIME flag relates to the pTime parameter. The documentation for the function can be found here. The pTime parameter is described like this: A pointer to a FILETIME variable that indicates the time for which the chain is to be validated. Note that the time does not affect trust list, revocation, or root store checking. The current system time is used if NULL is passed to this parameter. Trust in a particular certificate being a trusted root is based on the current state of the root store and not the state of the root store at a time passed in by this parameter. For revocation, a certificate revocation[…]

Project Dogtag, the Red Hat Certificate System which was born from the Netscape Certificate Server (acquired from AOL), has been released as open source under a number of licenses. A customized version of Dogtag is the certification authority system which manages the entire U.S. Department of Defense CAC card system. I believe I heard once before that they issue on the order of 50,000 CAC cards a day. It is a real system with real users, and real good performance. This could be a tremendous event in the PKI industry. By open-sourcing Dogtag, lesser-known open efforts such as OpenCA will probably be pushed out. Microsoft’s PKI Services are available free with a Server operating system license, which is countered by[…]