Two anchors, one year

Every security architecture rests on a small number of things assumed not to fail. Two of the largest are the authenticator that proves a person is who they claim, and the certificate authority that proves a server is what it claims. In 2011 one of each was compromised, four months apart, and the sequence is worth teaching because neither failed the way a practitioner would .

Neither was broken cryptographically. One fell to an email; the other to a network with one password.

March 2011: RSA and SecurID

On 3 March 2011 an employee of EMC, 's parent company, received a message reading, in substance, that a file was being forwarded for review. The attachment was a spreadsheet named "2011 Recruitment plan.xls". Opening it triggered a exploit in Adobe Flash, which installed a remote-access backdoor. The attackers then did what attackers do: took credentials from memory, used them to reach other machines, harvested more credentials including privileged ones, and worked their way to what they had come for - data relating to SecurID, the hardware token then used by some 40 million people at 25,000 client organisations to prove their identity when logging in.

RSA called the intrusion an advanced persistent threat. Critics called it phishing. The most careful assessment came from Mikko Hyppönen of F-Secure, whose team recovered the original email: the message was not advanced and neither was the backdoor, but the exploit was, and because it was a zero-day, RSA could not have prevented it by patching. That distinction is the useful one, and it is uncomfortable in both directions - it refuses the comfort of "they should have patched" and equally the comfort of calling every intrusion sophisticated.

The consequence arrived in May. Lockheed Martin - the largest supplier of information technology to the United States government - detected an attack on its remote access using information derived from the RSA breach. L-3 Communications reported a similar attempt; Northrop Grumman temporarily shut off remote access. On 6 June RSA confirmed what had been suspected for months and offered to replace tokens across its customer base, at a cost put at around 66 million dollars. The real targets had never been RSA or the contractors; they were the programmes the contractors worked on.

The contemporaneous criticism that has aged best was not about the intrusion at all. wrote in May, before the confirmation, that the incident revealed the danger of companies not being open about security incidents: customers who depended on SecurID could not tell whether to get new tokens, change PINs or firewall their administrative servers, because they had not been told what had been taken. That, he said, was the real problem. It is the same finding the Microsoft entry records about a left uncorrected for six months, and the Fujitsu entry about a record withheld for a decade.

June to September 2011: DigiNotar

DigiNotar was a Dutch certificate authority. Its root was trusted by every mainstream browser, and one of its intermediates issued certificates for PKIoverheid, the Dutch government's public key infrastructure - the certificates behind the country's electronic government services.

Intruders were inside from around the middle of June. From 10 July they used that access to issue certificates: 531 fraudulent certificates for 344 domains, including Google, Skype, Mozilla's add-on site and Microsoft Update. DigiNotar began revoking on 19 July. It did not go public.

It was found by a member of the public. On 27 August an Iranian Gmail user posted on a Google support forum asking whether what he was seeing was a attack on the certificate. It was. A rogue wildcard certificate for Google was being used, in Iran, to read mail.

What Fox-IT then found, in a report published on 5 September and filed as an exhibit to a public securities filing, is a catalogue of failures that any auditor should have caught. All of the certificate authority servers sat in a single Windows domain, so one username and password reached all of them - and the password was weak enough to . The most critical servers carried malware that ordinary anti-virus software would have detected. Separation of critical components was absent or not working. The servers were physically in a secure room and reachable over the network. And the serial number of the rogue Google certificate did not appear in the company's own records, which meant nobody could say how many certificates had been issued: the only way to estimate the damage was to watch the revocation checks browsers make - the Online Certificate Status Protocol () queries. Those checks showed about 300,000 unique addresses, ninety-nine per cent of them in Iran, consulting the status of the fraudulent Google certificate - which is to say roughly 300,000 people whose mail was being intercepted, for the best part of two months.

DigiNotar had been audited annually against the European standard for certificate authorities.

Browsers removed the root. Mozilla went further and added explicit distrust, because a removed root can still be honoured if cross-signed, and included the PKIoverheid intermediates that did not chain to DigiNotar's own root. The Dutch government had to take operational control of a private company's certificate business to keep the state's services running, and tell seventeen million citizens that the certificates behind their electronic government could not be trusted. Prosecutors opened an inquiry into whether the delay in disclosure amounted to criminal negligence. On 19 September 2011 DigiNotar filed for bankruptcy. Fingerprints deliberately left in the attack scripts matched those from the breach of Comodo, another certificate authority, in March of the same year.

What the pair teaches

The failure was never the cryptography. RSA's algorithms were fine; SecurID's design was fine. DigiNotar's certificates were mathematically valid - that was the problem. Both were defeated through ordinary information-technology weaknesses: an email, a flat domain, a weak password, absent segmentation. The named TLS attacks are about flaws in protocols; this pair is about everything around them, and the second category has produced more damage than the first.

A trust anchor's compromise is silent by construction. A fraudulent certificate produces no error. A cloned token produces a successful login. Neither generates an alert, because both are the system working. That is why DigiNotar's own records could not answer the most basic question - how many certificates did you issue - and why the estimate had to be reconstructed from revocation traffic. If the certificate revocation machinery had not existed, nobody would have been able to count the victims at all.

Detection came from outside, in both cases. RSA's breach became visible when Lockheed's defences caught the follow-on attack. DigiNotar's became visible when a user in Tehran asked a question on a forum. Neither organisation found its own intrusion, and both took a long time to say so once they knew - DigiNotar more than a month after it started revoking.

Disclosure timing is a security control. This is the part practitioners under-weight. Both organisations had customers who could have acted - reissued tokens, pinned certificates, watched their own logs - and who could not, because they did not know. The engineering was already lost by then; what remained to be decided was how much the loss would cost everyone downstream, and that was decided by a communications choice.

And the audits passed. DigiNotar was periodically assessed against the recognised standard for its industry while its certificate authority servers shared one password. Compliance measured what could be documented, and the thing that mattered - could one credential reach every signing server - was not in the checklist. That gap between a passed audit and a defensible network is the single most useful thing to take from 2011 into any conversation about a compliance regime.

Sources