Jump to content

Trustico: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
DGG (talk | contribs)
Added {{merge to}} tag to article (TW)
m link typos
Line 1: Line 1:
{{merge to|Certificate revocation list.|discuss=Talk:Certificate revocation list.#Proposed merge with Trustico|date=March 2018}}
{{merge to|Certificate revocation list|discuss=Talk:Certificate revocation list#Proposed merge with Trustico|date=March 2018}}
{{Current related}}
{{Current related}}
{{Infobox company
{{Infobox company

Revision as of 08:03, 3 March 2018

Trustico
Company typePrivate company
IndustryInternet security, Public key infrastructure
Headquarters,

Trustico is a certificate reseller.

It became notable in March 2018, after its CEO transferred the private keys for 23,000 HTTPS certificates via email (not a secure protocol) to an executive at DigiCert.[2][3][4][1][5] The fact that these private keys had been stored by Trustico suggested that Trustico had been violating the baseline requirements for certificate authorities.[2]

This was followed by the disclosure of a critical security flaw - a publicly-accessible root shell - in the Trustico website, after which the website was taken offline.[6][7]

See also

References

  1. ^ a b c "23,000 HTTPS certs will be axed in next 24 hours after private keys leak".
  2. ^ a b "23,000 HTTPS certificates axed after CEO emails private keys".
  3. ^ Whittaker, Zack. "Trustico compromises own customers' HTTPS private keys in spat with partner".
  4. ^ "23,000 Digital Certificates Revoked in DigiCert-Trustico Spat - SecurityWeek.Com". www.securityweek.com.
  5. ^ "How not to run a CA - Hacker News". news.ycombinator.com.
  6. ^ "Trustico website goes dark after someone drops critical flaw on Twitter".
  7. ^ "HTTPS cert flingers Trustico, SSL Direct go TITSUP after website security blunder blabbed".