Advertisements
//
you're reading...
Communication & Technology

Google no longer recognises digital security certificates issued by Chinese government


Google has said it will no longer recognise internet security certificates issued by the official China Internet Network Information Centre.

Google has said it will no longer recognise internet security certificates issued by the official China Internet Network Information Centre.

Search giant Google will no longer recognise security certificates issued by the official China Internet Network Information Centre (CNNIC) following what experts called a “major breach of public trust and confidence”.

CNNIC, which is responsible for internet affairs under the Ministry of Industry and Information Technology, responded to Google’s announcement with a defence of its practices, calling the move “unacceptable”.

Last month, CNNIC issued security certificates for a number of domains, including Google’s, without their permission. Security certificates are akin to a website or online service’s fingerprint, and tell a browser whether it can be trusted. By issuing unapproved certificates, CNNIC risked compromising the encryption protocols used to protect users of email services and other secure websites.

“CNNIC is included in all major root stores and so the misissued certificates would be trusted by almost all browsers and operating systems,” Google said in a statement.

Chinese officials told Google they had contracted Cairo-based MCS Holdings to issue the certificates. MCS said it would only issue certificates for domains it had registered.

“However, rather than keep the private key in a suitable [hardware security module], MCS installed it in a man-in-the-middle proxy. These devices intercept secure connections by masquerading as the intended destination and are sometimes used by companies to intercept their employees’ secure traffic for monitoring or legal reasons,” Google said.

Tom Lowenthal, a security and surveillance expert at the Committee to Protect Journalists, said the Chinese move marked a “major breach of public trust and confidence.” “The deliberate breach had the potential to seriously endanger vulnerable users, such as journalists communicating with sources,” he wrote.

On Wednesday, Google said that “as a result of a joint investigation of the events surrounding this incident by Google and CNNIC”, it would no longer recognise certificates issued by the Chinese authority.

Websites and businesses using CNNIC certificates may now be flagged as dangerous on Google’s Chrome browser, potentially scaring off customers.

Google said it did not believe any other certificates had been affected aside from those issued by MCS, and praised CNNIC for taking steps to improve security.

“[We] welcome them to reapply once suitable technical and procedural controls are in place,” it said.

In a response posted online on Wednesday, CNNIC said Google’s decision was “unacceptable and unintelligible” and called on the US-based company to consider user rights and interests.

“For the users that CNNIC has already issued the certificates to, we guarantee that your lawful rights and interests will not be affected,” the agency said.

Google’s move comes as US President Barack Obama issued an executive order declaring cybersecurity a “national emergency”, in the wake of a concerted attack on the open-source code repository GitHub.

Source: SCMP – Google drops support for Chinese internet security certificates after trust breach (paywalled)

 

Advertisements

About Sky In Company

I am Genevieve Cheung, originally from Hong Kong. After completing secondary studies, I moved to Australia where I completed a degree in Bachelor of Business Management at the VUT in Melbourne. After graduation I moved to Italy where I have been living for more than twenty years. My vast cultural background and extensive linguistic knowledge (speak and write fluent English, Mandarin/Cantonese Chinese and Italian), allow me to join our company- SKY IN COMPANY (HK/ITALY). We provide main services such as web-site translations from Italian/ English to Chinese/English, and SEO services for the Chinese search engine "Baidu". Our offices, based in Hong Kong and Italy, have a young and dynamic team with collaborators around the world. Sono Genevieve Cheung, originaria di Hong Kong; dopo aver completato gli studi secondari, mi sono trasferita in Australia, dove ho conseguito una Laurea in Bachelor of Business Management presso la VUT di Melbourne. Dopo la Laurea mi sono trasferita in Italia, dove vivo ormai da più di venti anni. Il mio background culturale e la vasta conoscenza linguistica (parlo e scrivo correntemente l’inglese, il cinese mandarino e l’italiano), mi consentono di partecipare in quest’attività di traduzione in Italiano/English/Cinese. La principale attività della nostra ditta – SKY IN COMPANY (HK), consiste nella traduzione in lingua cinese di siti web italiani, nonché di servizi di tipo SEO rivolti al motore di ricerca cinese “Baidu”. La nostra ditta principale, con base in Hong Kong, dispone di un team giovane e dinamico con collaboratori in tutto il mondo. WWW.SKYINCOMPANY.COM skyinhk74@yahoo.com.hk HONG KONG OFFICE: Flat b 15/F, Block 7 Yee Mei Court, South Horizon, Ap Lei Chau, Hong Kong Island Hong Kong Tel: ++852 92235260 ITALY OFFICE: Via Metastasio 27 Firenze 50124 Italy Tel: ++39-347 1429011

Discussion

Trackbacks/Pingbacks

  1. Pingback: Is China’s new ‘internet plus’ ambition all about new smartphones? | China Daily Mail - April 30, 2015

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Advertisements

Type 407 Training Visas

Get An Australian Diploma

Learn How To Sell Real Estate To Chinese Buyers

Sell Your Real Estate To Chinese Investors

China Daily Mail

China Daily Mail is not affiliated in any way with The China Daily or the government of the People's Republic of China.

Enter your email address to receive an email each time an article is published, or join our RSS feed. 100% FREE.

Want to write for China Daily Mail?

Read "Contributor Guidelines" above to join our team of 68 contributors. Write news or opinion about issues in China, or post photos and video. Promote your own site.

Recent Posts

China Daily Mail Stories Have Been Featured In:

%d bloggers like this: