DigiNotar dies from certificate hack caper

"Unlikely many are going to shed tears" over Dutch company's demise, says security researcher

The Dutch company that was hacked earlier this summer by certificate thieves has gone bust and shut down, its U.S.-based owner said Tuesday.

DigiNotar filed for bankruptcy in a Netherland court on Monday, and its assets will be liquidated by a court-appointed trustee, said Vasco Data Security International, the Chicago company that purchased DigiNotar last January for $13.1 million.

"Effective as of the beginning of business today, the Trustee has taken over the management of DigiNotar's business activities," Vasco said in a statement on Tuesday.

In late August, DigiNotar admitted that hackers had illegally generated numerous SSL (secure socket layer) certificates, including one for google.com that was later found to have been used to spy on some 300,000 Iranians through their Gmail accounts.

DigiNotar confirmed that it had first discovered the intrusion on July 19, but had not disclosed the breach to browser makers, the Dutch government -- which used DigiNotar certificates to validate the identities of many of its websites -- or other customers until more than a month later.

An investigation sponsored by the Dutch government revealed that the hacker or hackers first compromised DigiNotar's servers in mid-June and made off with more than 500 certificates.

After DigiNotar went public, all five of the major browser makers -- Apple, Google, Microsoft, Mozilla and Opera -- issued updates that barred users from reaching sites secured with DigiNotar-issued certificates.

DigiNotar's filing for bankruptcy was not unexpected.

On Sept. 15, Vasco filed a statement with the U.S. Securities and Exchange Commission (SEC) that noted the company's investment in DigiNotar had been "materially impaired," and added that it was "not able to determine the amount of impairment loss Vasco may incur or estimate the amount of future cash expenditures that the Company may incur in connection with the impairment."

Vasco credited the loss to a Sept. 14 decision by the Dutch Independent Post and Telecommunications Authority (OPTA) to terminate DigiNotar as a certificate authority (CA), preventing it from issuing any further certificates.

But the browser makers' moves to block, then bar, DigiNotar certificates also played a part, said a security expert.

"Ultimately, the power is in the hands of the browser makers to trust any CA," said Andrew Storms, director of security operations at nCircle Security. "Going by that logic, the browsers then have the same power to create the demise of a CA."

Microsoft declined to comment on the death of DigiNotar, and neither Mozilla or Google responded to a request for comment.

Vasco purchased DigiNotar in January for $13.1 million, and in its most recent quarterly filing with the SEC, tallied the Dutch company's "goodwill" and "intangible assets" at nearly $12.8 million. In its Tuesday statement, Vasco said it was still working on putting a number to DigiNotar's vanishing act, but voiced confidence that some of DigiNotar's intellectual property rights would still be valuable.

Vasco also distanced its own products and services from the now-dead Dutch firm.

"The incident at DigiNotar has no impact on Vasco's core authentication technology," argued T. Kendall Hunt, Vasco's CEO and chairman.

Jan Valcke, president and chief operating officer of Vasco, added that the company would steer clear of the certificate business. "We do not plan to re-enter the certificate authority business in the near future," said Valcke in the same statement.

Vasco's stock has taken a beating since the company announced the intrusion, with the share price down 31.5% since the close of the market on Aug. 29. As recently as July 11, Vasco's shares traded at $13.82.

"It's unlikely that many people are going to shed many tears over the demise of DigiNotar," said Graham Cluley, senior technology consultant at security firm Sophos, in a Tuesday blog. "The firm lost all trust when it was discovered that it had known that it had suffered a security breach weeks before coming clean about the problem."

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His e-mail address is gkeizer@computerworld.com.

See more articles by Gregg Keizer.

Read more about security in Computerworld's Security Topic Center.

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Cybercrime and HackingapplicationsGooglesecuritybrowserssoftwareMalware and Vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld (US)
Show Comments

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?