Customers of HTTPS certificate reseller Trustico are reeling after being told their website security certs – as many as 23,000 – will be rendered useless within the next 24 hours. . This is allegedly due to a security blunder in which the private keys for said certificates ended up in an email sent by Trustico. Those keys are supposed to be secret, and only held by the cert owners, and certainly not to be disclosed in messages. In the wrong hands, they can be used by malicious websites to masquerade as legit operations.. A significant security mishap at Certify has resulted in 25,000 SSL certificates being rendered invalid after private keys were compromised.. HTTPS Certificate Revocation, Trustico Security Issue, Private Key Protection, Certificate Management. . LinuxSecurity.com Team
Source code and a private signing key for firmware manufactured by a popular PC hardware maker American Megatrends Inc. (AMI) have been found on an open FTP server hosted in Taiwan. . Researcher Brandan Wilson found the company The link for this article located at ThreatPost is no longer available. . AMI firmware source codes and signing certificates found on unsecured SFTP server, presenting major threat to security.. Firmware Security, Key Leakage, AMI Firmware. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.