Comodo Notifies VeriSign of Major Security Vulnerability and Urges VeriSign to Correct, Remediate and Notify its Customers
Comodo Notifies VeriSign of Major Security Vulnerability and Urges VeriSign to Correct, Remediate and Notify its Customers
While Comodo is not in a position to fully evaluate the scope of the vulnerability, Comodo believes it is a significant security concern for VeriSign's customers (and users of their customer's Web sites) that rely on secure SSL Digital Certificates to transmit business and personal data.
Using publicly available information, Comodo found that a VeriSign customer account of a major financial institution can be easily accessed without authentication. Comodo believes that the vulnerability is not limited to this single account.
Communicating through the independent third party, Comodo urged VeriSign to take immediate steps to correct and remediate the vulnerability and notify all their customers who may be affected by this vulnerability.
"When we uncovered this serious security vulnerability, we knew we had to do the right thing to notify VeriSign immediately to correct the design problem," explained Melih Abdulhayoglu, chief executive officer and founder of Comodo. "With millions of customer's financial transactions at stake, we wasted no time to help correct the problem even though it wasn't ours to begin with."
Comodo followed the Vulnerability Disclosure Guidelines of the Common Computing Security Standards Forum (CCSS) by using an independent third-party as a medium for disclosure. It provided a disclosure document to VeriSign outlining the vulnerability.
About Comodo
Comodo is a leading brand in Internet security. With US Headquarters in New Jersey and global resources in UK, China, India, Ukraine, and Romania, Comodo provides businesses and consumers worldwide with security and trust services, including digital certificates, PCI scanning, desktop security, and remote PC support. Securing online transactions for over 200,000 businesses, and with more than 30 million desktop security software installations, including an award-winning firewall and antivirus software, Comodo is Creating Trust Online®. For more information, visit Comodo's website
About Common Computing Security Standards Forum (CCSS)
The Common Computing Security Standards Forum (CCSS), is a voluntary organization of security vendors, operating system providers, and Internet browser software creators who are working together to mitigate the risk of malware and protect Internet users worldwide. The consortium established guidelines for vendors to follow with respect to vulnerability disclosure, which originated from the Vulnerability Disclosure Framework published on January 13, 2004 by the National Infrastructure Advisory Council. For more information, visit www.ccssforum.org.
Company:
Comodo
Related press releases
-
Comodo Notifies VeriSign of Major Security Vulnerability and Urges VeriSign to C...
[2010-06-23 22:06:27]
Jersey City, NJ, June 23, 2010 - Comodo announced today that it requested an independent third-party notify VeriSign of a security vulnerability affecting its customers Web sites, including a major fi... -
Comodo Update on VeriSign's Security Vulnerability
[2010-06-29 03:42:51]
Jersey City, NJ, June 25, 2010 - Comodo a leading Certificate Authority and Internet security organization, today announced it acknowledges that VeriSign has made some recent fixes to its security iss... -
Comodo Surpasses Verisign by Securing 15% More Web Sites
[2010-04-20 23:44:37]
Jersey City, NJ, April 20, 2010 - Comodo, a leading brand in online security, announced today that it has surpassed the VeriSign brand in the number of SSL Certificates currently in use. Based on inde... -
VeriSign pending acquisition of low assurance SSL provider GeoTrust puts VeriSig...
[2006-05-25 00:00:00]
Comodo challenges VeriSign to end the practice of issuing low assurance, non-business authenticated SSL certificates without any means to establish true Internet and identity assurance as demanded by ... -
Comodo & VeriSign go head to head
[2005-06-14 00:00:00]
Comodo The only High Assurance SSL certificate authority with growth over the last 9 months. New York, 14th June 2005. Comodo Inc., the world's second largest High Assurance Certification Authority... -
Web Security Pioneer and Technical Innovator Dr. Phillip Hallam-Baker Joins Como...
[2010-08-12 00:08:16]
Jersey City, NJ, August 11, 2010 - Comodo, a leading Certificate Authority and Internet security organization, today announced a key addition to its management team with the appointment of Dr. Phillip... -
Comodo Offers Free Replacement Certificate to any Individuals Affected by Debian...
[2008-05-21 11:06:23]
Comodo issues security advisory on Debian vulnerability flaw, confirming that while Comodo Certificates are unaffected, some certificates created using Debian Distribution are vulnerable which is why ... -
Comodo Webinar Educates Aspiring Amazons
[2009-02-03 03:30:57]
Jersey City, NJ, February 03, 2009 - A February 12 online seminar presented by Comodo will tell emerchants how to build their customer bases by increasing customer trust. The webinar will explain t... -
APLUS.NET AND COMODO JOIN SSL FORCES
[2005-10-12 00:00:00]
Aplus.Net customers get immediate access to SSL products by Comodo San Diego, CA and New York, NY - October 4th, 2005 -- Leading Internet presence solution provider, Aplus.Net and global leader in I... -
Comodo SSL Certificates Not Affected By MD5 Flaw
[2009-01-08 05:28:16]
Jersey City, NJ, January 8, 2009 - Comodo CA Limited, the second-largest issuer of high-assurance digital certificates, today announced that none of its certificates is created using the MD5 hash func...
English
German
French
Spanish
Russian
Romanian



