Forgot your password?
typodupeerror

Submission + - Asking slashdot: How do you deal with blow from Certificate authority? 4

rastos1 writes: I work for a mid-size software company that develops CAD-CAM software for textile industry for many decades. Last weekend Sectigo (formerly known as COMODO until late 2018) revoked code signing certificate that our company bought in the beginning of 2018 from Sectigo reseller and used to sign all our SW products. On Monday morning we woke up to phones ringing from confused customers unable to launch our software. This has hit mostly Java applications launched from a web page because JRE checks the signature by default using OCSP. But also traditional executables and shared libraries would report invalid signature upon checking. We reached to Sectigo but for half a day we could not get any feedback. Later we got information that some malware was signed with our certificate. 2 days, many e-mails and phone calls later we understand that this is what happened: someone submitted one of our executables to virustotal.com — site that runs ~70 antivirus programs on submitted files and reports back whether they flag the uploaded file. 5 of antivirus packages flagged our executable. We tracked down the version and we positively know it was a false positive. There is random guy that wrote a tool that creates a monthly report of files flagged at Virustotal. Sectigo found the report, and, according to their statement, revoked all certificates used to sign executables flagged by some antivirus causing major disruption to us and downtime for our customers. We buy certificates from COMODO/Sectigo for more than a decade, but there was no attempt to contact us and clarify the situation.
How do you prepare and deal with such scenario? Did you know how little it takes to get your certificate revoked?
Electronic Frontier Foundation

Submission + - 2012 EFF Pioneer Award Winners Names Revealed (eff.org)

An anonymous reader writes: In 2012, EFF Pioneer Award winners are Hardware Hacker Andrew (bunnie) Huang , Anti-ACTA Activist and La Quadrature du Net cofounder Jérémie Zimmermann, and Groundbreaking Anonymity Group Tor "Every year, our Pioneer Awards celebrate those who have made a difference for digital freedom. We are extraordinarily proud of this year's winners and their unflagging dedication to protecting the rights of technology users around the world," said EFF Executive Director Shari Steele. "Whether it's your right to reverse engineer a game console, or to avoid the interference of overbroad IP enforcement, or to block websites or governments from tracking your every online move, these winners are working hard to protect our online freedom." 21st edition of the annual EFF Pioneer Awards ceremony will take place September 20 in San Francisco.

Submission + - UK man jailed for "offensive tweets" (bbc.co.uk)

Motor writes: "A UK judge has jailed a man for 56 days after he posted offensive comments on twitter about a footballer who had a heart attack during a game. He's also been thrown out of his university degree course weeks from graduating. His comments may have been offensive... but do they really justify a prison sentence and ruining his life?"

Slashdot Top Deals

"Nature is very un-American. Nature never hurries." -- William George Jordan

Working...