Slashdot Mirror


Microsoft Certificate Was Used To Sign Flame Malware

wiredmikey writes "Microsoft disclosed that 'unauthorized digital certificates derived from a Microsoft Certificate Authority' were used to sign components of the recently discovered Flame malware. 'We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft,' Microsoft Security Response Center's Jonathan Ness wrote in a blog post. Microsoft is also warning that the same techniques could be leveraged by less sophisticated attackers to conduct more widespread attacks. In response to the discovery, Microsoft released a security advisory detailing steps that organizations should take in order block software signed by the unauthorized certificates, and also released an update to automatically protect customers. Also as part of its response effort, Microsoft said its Terminal Server Licensing Service no longer issues certificates that allow code to be signed."

1 of 194 comments (clear)

  1. Re:UEFI by afidel · · Score: 0, Troll

    You are an idiot, the Windows 8 Ready program requires manufacturers to make adding additional secure boot keys available to the end user. Secure Boot isn't some conspiracy to get rid of Linux, it's an attempt to try to get rid of physical access == owned. Paranoid Linux lovers have turned it into a conspiracy because MS == evil in their eyes, whereas the real evils (Chinese government for one) are given a pass even though the attempt is to get rid of things like rootkits installed at customs.

    --
    There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.