Apple Removes DigiNotar Certificates From Safari
Apple has finally released a fix for the certificate trust issue caused by the attack on DigiNotar, more than a week after the fraudulent certificates were identified and other browser vendors moved to revoke trust in them. However, the company did not update the mobile version of Safari to remove the certificates in iOS.
While Microsoft, Mozilla and Google had been communicating with users about the issue and pushing out new versions and updates to eliminate the compromised certificate authorities from their browsers, Apple had been mum about the attack and hadn't given any indication of when it might issue an update for Safari. On Friday the company published a security advisory for Mac OS X users, saying that it was removing DigiNotar's certificates from its trust list.
"Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted," the advisory said.
Apple is the last of the major browser vendors to make the move to revoke trust in DigiNotar's root certificates from its software. The update applies to Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.1, and Lion Server v10.7.1.
It's unclear whether there's a new version of iOS in the works to remove the certificates from iPhones, iPads and iPod Touches, as well.
Recommended Reads
Commenting on this Article is closed.
Today's Most Popular
- Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest
- Dear Jailbreaker, Apple Wants to Have a Word with You
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- White House Security Czar Howard Schmidt Retiring
Most Commented Stories
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




Comments
I guess Apple's not the least bit concerned about security of the 50 million+ iPhone users out there...
Oh one whole week, the horror. Silly Apple bashing.
Oh and Google may have patched Chrome they have not patched Android.
This isn't a theoretical attack that might happen 10 years in the future. The attacker has valid certs for more than 500 domains, and even though tha CA revoked them, that doesn't fix the problem. The browser vendor needs to revoke trust for them, as well.