Evidence shows CNNIC and CAC behind MITM attacks
Since 2013, we have repeatedly called on major software vendors to revoke CNNIC-issued certificates. Most notably, we raised this issue when we reported on the Cyberspace Administration of China’s (CAC) man-in-the-middle (MITM) attacks on Google, Microsoft’s Outlook, Apple, Yahoo and Github. Mainstream media have reported about these security vulnerabilities before and on March 24, Ars Technica reported on Google’s announcement that they have definitive evidence that CNNIC (China Internet Network Information Center) was behind a new MITM attack on Google.
From our October, 2014 blog post:
CNNIC has implemented (and tried to mask) internet censorship, produced malware and has very bad security practices. Tech-savvy users in China have been protesting the inclusion of CNNIC as a trusted certificate authority for years. In January 2013, after Github was attacked in China, we publicly called for the the revocation of the trust certificate for CNNIC. In light of the recent spate of man-in-the-middle (MITM) attacks in China, and in an effort to protect user privacy not just in China but everywhere, we again call for revocation of CNNIC Certificate Authority.
CNNIC is either complicit in the recent MITM attacks or has intentionally allowed these attacks to happen. We have been witness to the Chinese authorities using MITM attacks against Apple’s iCloud, Google, Microsoft’s Outlook and Yahoo in this month alone.
CNNIC is responsible for the “operation, administration and service organization of national network fundamental resources”. We have evidence that the recent attacks originated from the Chinese internet backbone. Attacks against Yahoo and Google have been implemented on the internet backbone for weeks.
Today we have concrete proof from Google that CNNIC (and by extension CAC) is indeed complicit in MITM attacks. Google states in its own blog post:
On Friday, March 20th, we became aware of unauthorized digital certificates for several Google domains. The certificates were issued by an intermediate certificate authority apparently held by a company called MCS Holdings. This intermediate certificate was issued by CNNIC.
CNNIC is included in all major root stores and so the misissued certificates would be trusted by almost all browsers and operating systems. Chrome on Windows, OS X, and Linux, ChromeOS, and Firefox 33 and greater would have rejected these certificates because of public-key pinning, although misissued certificates for other sites likely exist.
We are delighted that Google, Microsoft and Mozilla have taken steps to blacklist the intermediate certificate used in the attack. The Ars Technica story provides more details about Mozilla’s statement. Apple has not made a public statement about this issue. However, more action is needed. CNNIC is still trusted by these platforms and the Chinese authority can sign other intermediate certificates in order to launch future MITM attacks. We once again call for Google, Mozilla, Microsoft and Apple to revoke trust for CNNIC immediately in order to protect Chinese user data and user data worldwide.
Comments
Freedom India This is getting Download Old and New Collection Images 15 August 1947 Wallpaper http://www.happyindependencedaygif.com/
What's Going down i am new to this, I stumbled upon this I have discovered It positively useful and it has aided me out loads. I am hoping to contribute & aid different users like its helped me. Great job.
http://www.wimbledon2017live.com/
Geometry Dash World (MOD, Editor/Search/Gauntlets) - get ready for new adventures, new levels, new music and new monsters in the new part of Geometry
https://geometrydashworlds.com
The T20 Global League is a planned Twenty20 cricket tournament by the Cricket South Africa to be held in South Africa
http://www.t20globalleaguelive.com
Find Myxer software downloads at CNET Download.com, the most comprehensive source for safe, trusted, and spyware-free downloads on the Web.
https://myxerfreeringtonesdownload.com
A consortium of Non-Resident Indians (NRIs) in Hong Kong have bought the Bloemfontein franchise in South Africa's
http://www.isllivestream.in
http://www.bigbash2016.com
tube music video classes are really cool. You can also learn from apps like Fildo. All latest music videos are available for free on this app.
Fildo for Android
Click here to get
http://aptoideappdownload.com/
happy friendship day from
http://www.toponwebs.com
Gmail is the Google's email service. It has many advantages over Hotmail and Yahoo.
Gmail New Account Create
http://www.diwaliwallpapers2017.com
http://wishuponfullmovie2017.blogspot.com
http://www.diwaliwallpapers2017.com
Great Article! Thanks for the information. Do visit my site - http://www.durgapuja2017.xyz
nice post visit cvs health here https://myhrcvs.online/for more
Amazing!!! I like this website so much it's really awesome.I have also gone through your other posts too and they are also very much appreciate able and I'm just waiting for your next update to come as I like all your posts... well I have also made an article hope you go through it. Diwali 2017
Amazing I like your Post Diwali 2017
Amazing I like Your Posts, heck out our new blog about the festival of Lights which is famious with the name of diwali. Rangoli Designs
http://www.thanksgivingday2017.com/
Your blog is very nice. I am your regular reader.
https://theflashseason4episodewatchonline.com
https://theflashseason4watchonline.com
https://supergirlseason3episodewatchonline.com/#Supegirl_Season_3_Episod...
https://supergirlseason3episodewatchonline.com/#Possible_Cast_for_Superg...
https://supergirlseason3episodewatchonline.com/#Supergirl_season_Story_s...
https://supergirlseason3episodewatchonline.com/#Supergirl_Spoilers
https://supergirlseason3episodewatchonline.com/#Names_and_premier_dates_...
http://www.devicemantra.com
https://pancardstatusuti.com/
Kodi Application for your corresponding tools.https://whatsapphindifunnyjokes.blogspot.in/2016/06/blog-post_29.html
http://101tattooideas.com/
Very Nice Information
https://shayariworld2017.wordpress.com/
Really Good
https://shayariworld2017.wordpress.com/
Nice
https://amazingstufffan.tumblr.com/
https://simplelife2018.blogspot.com
https://simpleworld2018.livejournal.com/
https://shumile00.wixsite.com/2018
http://worldofjoy2018.bravesites.com/
http://www.diwaligreetingss.com
http://www.diwaligreetingss.com
http://www.diwaligreetingss.com
http://canonsupport.strikingly.com/#dell-support
MAC Tech Support provide fixes for some common problems that you may be facing with your MAC System.
http://applecutomerservice.webs.com/
YOu have cool stuff on your blog, Keep updating.
https://happynewyearsms.us
https://9wiki.info
https://bollywoods.today
https://9apk.me
https://cracks.website
https://oceanofgames.me
https://10bestsavers.com
https://9gogoanime.com
https://dragonballsuper.today
https://dragonballsuperonline.xyz
https://biography.fun
Great Article....
https://www.jewellerkaka.com
nice post http://customerserv123.livejournal.com/
nice post.
http://outlooktech.oneminutesite.it/chi_siamo.html
Great Post...
http://www.jewellerkaka.com
thanks for sharing this man and you can check my blog too here
http://www.ssccglresult2017.com
http://www.calicutuniversityresult.com/
http://www.ibpsporesult2017.com/
www.techsoid.com
lenovo support number offers help and fixes common occurring problems and provide solutions and quick fixes.
https://applecustomercare.jimdo.com/lenovo/
http://www.prefabportacabin.com
china is preventing the net neutrality!
http://applesupport.aircus.com/
http://shayari.quotesmswishes.com/hindi-shayari/
The Indian Super League is a men's professional football league in India. For sponsorship reasons, the league is officially known as the Hero Indian Super League.
http://www.isllivestream.in
http://www.bigbash2016.com
The Indian Super League is a men's professional football league in India. For sponsorship reasons, the league is officially known as the Hero Indian Super League.
http://www.isllivestream.in
http://www.bigbash2016.com
Myxer Free Ringtones App Download, Free Music Ringtones for Android: If you like to change your phone ringtone freely then you must have searched the
https://myxerfreeringtonesdownloads.com
https://speedposttrackings-gov.in
https://happynewyear2018imageshq.wordpress.com/
https://happynewyear2018imageshd.weebly.com/
https://happynewyear2018imageshq.blogspot.com.au/
https://newyear2018imageshd.tumblr.com/
https://happynewyearimages2018.jimdo.com/
Ei, eu adoro esta atualização, parece um sistema de tradição. e parece realmente uma abordagem incrível para compartilhar o inim e obrigado por estar aqui.https://resultadoenem2018.com/
https://oscarnominations2018.com/
any films that were awarded the latter will be shown in brackets next to the number of competitive wins.
education plays a promising role in day today life and even moore rech edu also . https://gateresult2018.com
https://sslcresult2018.com
https://cbseresult2018.com
nice..
https://www.sscresults2018.net/
https://www.sslcresults2018.com/
Love it..
https://www.wweroyalrumble2018results.com/
https://www.plustworesult2018.com/
good work..
https://www.ipl2018schedule.info/
Pages
Add new comment