Re: [cryptography] Misuses/abuses of Sony's compromised root certificate?

2014-12-17 Thread Ryan Carboni
Pretty sure it's an internal root certificate to the Sony corporation. On Wed, Dec 17, 2014 at 1:19 PM, Erwann Abalea wrote: > > > 2014-12-17 21:41 GMT+01:00 Jeffrey Walton : >> >> Has anyone come across any reports of abuse due to Sony's compromised >> root? I believe its named "Sony Corp. CA 2

Re: [cryptography] Misuses/abuses of Sony's compromised root certificate?

2014-12-17 Thread Erwann Abalea
2014-12-17 21:41 GMT+01:00 Jeffrey Walton : > > Has anyone come across any reports of abuse due to Sony's compromised > root? I believe its named "Sony Corp. CA 2 Root"? > > I did not find it in the Windows 8.1 certificate store. Are any of the > browsers carrying it around? > Since Vista, you'll

Re: [cryptography] Misuses/abuses of Sony's compromised root certificate?

2014-12-17 Thread Warren Kumari
Well, yes and no https://securelist.com/blog/security-policies/68073/destover-malware-now-digitally-signed-by-sony-certificates/ This particular incident may have been a "joke", but there are rumors (on closed lists) of it being seen in the wild... W On Wed, Dec 17, 2014 at 3:41 PM, Jeffre

[cryptography] Misuses/abuses of Sony's compromised root certificate?

2014-12-17 Thread Jeffrey Walton
Has anyone come across any reports of abuse due to Sony's compromised root? I believe its named "Sony Corp. CA 2 Root"? I did not find it in the Windows 8.1 certificate store. Are any of the browsers carrying it around? ___ cryptography mailing list cryp