Thousands of bogus certs issued after GoDaddy bug blunder

Domain name registrar and hosting firm GoDaddy has been forced to revoke thousands of digital certificates this week, after a bug allowed them to be issued without proper validation. GoDaddy senior internet product and technology leader Wayne Thayer wrote that the company had been made aware of a flaw affecting its domain validation processing system over last weekend. The bug was introduced to GoDaddy's validation code back in July 30 last year, meaning a large number of digital certificates were subsequently issued without proper checks, Thayer admitted. The bug was discovered by a Microsoft customer, who emailed GoDaddy about the issue last weekend. Thayer said the bug was caused by the validation process completing successfully even if the control check returned a HTTP 404 not found status code, when looking for the presence of data on a web page that demonstrated a customer controlled a domain. Prior to the bug being introduced in July, the domain validation process would only complete if it received a HTTP 200 (success) code. In total, Thayer said, 8850 certificates were issued without proper domain validation. In the time it took for GoDaddy to investigate the bug, the number of problematic certificates went up to 8951 as a further 101 certificates were issued using cached and potentially unverified domain validation inforrmation, Thayer said. GoDaddy has started revoking the affected certificates. Thayer said GoDaddy is not aware of "any malicious exploitation of this bug to procure a certificate for a domain that was not authorised."

By Juha Saarinen

Recent Posts

Jan 10 2017

D-Link faces device security lawsuit

The US Federal Trade Commission has filed a lawsuit against D-Link, arguing that the company failed to take steps to ensure that the routers and internet-linked security cameras that it manufactures could not be hacked.

Jan 6 2017

Amazon India partners with Gujarat Govt

Amazon India has signed a Memorandum of Understanding with Gujarat Tribal Development Department to drive digital literacy among tribal entrepreneurs in Gujarat. According to the MoU that was signed during the Vibrant Gujarat Global Summit 2017, Amazon India will educate, train & enable tribal entrepreneurs to directly sell their products to Amazon customers not only in India but across the globe.

Spotlight

India and Cyber Security

How vulnerable are Indian companies

Indian enterprises are not confident about their ability to sense, resist and respond to cyber security threats, says a recent survey report by the global professional services firm EY. According to the report, 75 per cent of Indian respondents felt that their cyber security functions do not fully meet the organizations' needs. EY surveyed 1,735 global C-suite executives, including 124 CXOs from India. However, the report says 69 per cent of Indian respondents also reported an increase in their cyber security budgets in the past 12 months, while almost 75 per cent expected the budgets to go up further in 2017. The survey also revealed that outdated information, security architecture and controls have increased the risk exposure for India Inc., with as many as 61 per cent of respondents citing it as their topmost vulnerability.