SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2

Filed Under: Data loss, Featured, Microsoft, Podcast, Privacy, Vulnerability

Sophos Security Chet Chat logoThis week my guest for the podcast was Mike Wood, a Senior Threat Researcher at SophosLabs in Vancouver, Canada.

Mike is our expert on digital certificates and how malware authors try to use and abuse digital certificates for their own purposes.

I talked briefly about this month's Patch Tuesday, which fortunately is a small one compared to others this year.

I also briefly mentioned the compromise at DNS registrar NetNames. The attacker pointed the DNS for The Register, UPS and others to a Turkish hacker web site.

We discussed the latest version of Firesheep and how it is now able to steal your Google search history due to a flaw in how some Google sites handle cookies.

The meat of this Chet Chat was spent discussing the recent breach and impact of the hacker(s) who compromised certificate authority DigiNotar.

Mike went into some detail of how certificates have been abused and what these attackers might accomplish if they were to use bogus certificates they purloined from DigiNotar.

(8 September 2011, duration 27:22 minutes, size 12.5 MBytes)

You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 72 or subscribe to our RSS.

, , , , , , , ,

You might like

One Response to SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2

  1. Tom B ยท 1479 days ago

    Bravo Guys, Bravo

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Chester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics. You can follow Chester on Twitter as @chetwisniewski, on as Chester, Chester Wisniewski on Google Plus or send him an email at