Comodo attack appears to have originated from Iran
comodo.com
comodo.com
Combined with the Ars article [1] on those certificates that come bundled with the browser and the circumstantial evidence begins to pile up.
Presumably one can delete various CA's they don't trust from their cache, but that just makes the browser complain that mail.google.com is using a certificate that isn't trusted, it doesn't let you connect to a server from Google that is using a certificate you trust.
[1] http://arstechnica.com/security/news/2010/03/govts-certifica...
https://blog.torproject.org/blog/detecting-certificate-autho...
Bottom line is certificate revocation lists and OCSP don't mean anything to an attacker like Iran who is MITM'ing the relevant traffic.
Interesting to find what the Chrome team did to fix this:
http://src.chromium.org/viewvc/chrome/trunk/src/net/base/x50...
Good reason to upgrade!
(Edit: this happen a few weeks ago, it has apparently taken the browser makers 8 days to issue an update while in the interim there were rogue signed certs out in the wild)
Turns out the IP address is being misreported as from Iran, so i'm wondering if the same thing happen in this case to point the finger at them
It is, at best, evidence, not proof. Reasonably strong evidence, mind you.
"The attacker was well prepared and knew in advance what he was to try to achieve. He seemed to have a list of targets that he knew he wanted to obtain certificates for, was able quickly to generate the CSRs for these certificates and submit the orders to our system so that the certificates would be produced and made available to him."
This makes me think that this could've been prepared anywhere in the world and was made from an Iranian IP address to make it look like it originated in Iran.
If they were that prepared why not use a host in a different country?
Even if the certificate labeling is copied, the actual cryptographic values will change. (If they were readily reproducible, the cryptography itself would be useless.)
So... notify the user when those values change from previous sessions, or at least when the fingerprint changes. This still assumes the ability to establish the legitimate values during those previous sessions or via other means. And it appears that trusting the original browser installation is not adequate. (E.g. dozens of "built-in" certs, some from who knows where. Or now, apparently, attempted forgery of Mozilla certificates.)
Of course, I guess most users will refuse to deal with such details, anyway. Until it hurts enough...