Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach¶
BV, F. (2012). Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach: Report of the investigation into the DigiNotar Certificate Authority breach.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Domain-specific¶
- Digital signature
- The canonical real-world failures (DigiNotar 2011, the Symantec distrust events) were failures in the key-management and certificate-authority trust-anchor layer, not in the cryptographic primitive itself
This sourceThe intrusion into DigiNotar's certificate-authority servers, the abuse of its active CA keys, and the 531 rogue certificates identified, including one for .google.com. The man-in-the-middle use of the rogue .google.com certificate, accepted by standard software, against roughly 300,000 users almost all in Iran, with traffic meant for Google services likely intercepted.
Supported in partVerified against the source
- The canonical real-world failures (DigiNotar 2011, the Symantec distrust events) were failures in the key-management and certificate-authority trust-anchor layer, not in the cryptographic primitive itself
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Read against the text for 1 of 1 citation: 1 supported in part. Each verdict is shown under its citation below, with what in the work backs the sentence.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:20508984aaf8 · see in the full table