DigiNotar Files for Bankruptcy, Shows the Real Consequences of Hacks

Significant security breach and poor crisis management doom Dutch certificate authority .
Screen shot 2011-09-22 at 12.15.36 AM

The press and public reaction to many high profile hacks–think Sony, or the Pentagon–is that the breaches are embarrassments at best or setbacks at worst. But hacks can have grievous real-world consequences for companies, as Dutch certificate authority DigiNotar proved this week when it filed for bankruptcy after finding itself unable to recover from the consequences of a massive hack it suffered this summer.

DigiNotar, owned by Vasco Data Security out of Illinois, was the primary provider of digital security certificates for domains owned by the Dutch government; ironically, it was lax security on DigiNotar’s end that led to the hack, in June, that caused the company’s system to issue over 500 fraudulent digital certificates for companies such as Google and Skype. This allowed scam third party sites in possession of the Google certificate to dupe users into thinking the fraudulent site was legitimate and, possibly, providing personal information.

As one would imagine, the hack caused extensive damage to DigiNotar’s reputation, which proved fatal when the Dutch government pulled its business.

A third-party audit of the hack showed that DigiNotar wasn’t aware of the breach until mid-July, and that the company had lacked basic security protocols such as strong passwords, up-to-date software patches and anti-virus protection. The company also failed to go public with information of the breach until August, and only after reports of the hack were confirmed by Google. After DigiNotar refused to identify the other victims besides the search giant, and widespread criticism of how they handled the hack mounted, Google, Mozilla and Microsoft all announced they would permanently block all digital certificates issued by the company. From there, as one would expect, all trust in DigiNotar’s service integrity had vanished.

As, soon, may the company itself.

This entry was posted in Antivirus Software, Computer Security, Data Security, Internet and Online Business, Network Security, Spyware and Malware, Wireless Networks and tagged , , , , , , , , , , , , . Bookmark the permalink.
  • Richard Calvin

    In today’s field of technology that risk is right up front and obvious.  It is appearant that this companies management was more worried about satisfying their board of directors than it was securing its own servers.  Fatal flaw!

    If a company that sell security certificates, can’t supply security for its customers then maybe they shouldn’t be in the business of selling security items and it appears that it may not be much longer.  If their system was hacked there may be other issues that haven’t even been disclosed yet.  Such as confidential customer information.  I have to think that the Bankrutcy filing my be to midigate the potential lawsuits that are coming.  JMHO

  • http://www.lastres0rt.com Rachel Keslensky – Last Res0rt

    I think at least part of DigiNotar’s doom was the ease in which the solution to the problem was “Stop accepting ALL DigiNotar certificates”… if VeriSign had been compromised, the problem would’ve been much harder to handle due to how widespread their use is.

    Yet another case where size equals security.

  • http://buyresearchpaper.org/ http://buyresearchpaper.org/

    I really loved reading your blog. It was very well authored and easy to understand. I also found your posts very interesting. In fact after reading, I had to go show it to my friend and he enjoyed it as well!