<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>isssource.com</title>
	<atom:link href="http://www.isssource.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.isssource.com</link>
	<description></description>
	<lastBuildDate>Wed, 22 Feb 2012 23:45:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hunting Down Clues in Refinery Fires</title>
		<link>http://www.isssource.com/hunting-down-clues-in-refinery-fires/</link>
		<comments>http://www.isssource.com/hunting-down-clues-in-refinery-fires/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 23:19:29 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[BP]]></category>
		<category><![CDATA[Cherry Point]]></category>
		<category><![CDATA[crude oil]]></category>
		<category><![CDATA[Egypt]]></category>
		<category><![CDATA[floor collapsed]]></category>
		<category><![CDATA[four workers killed]]></category>
		<category><![CDATA[leaky flange connection]]></category>
		<category><![CDATA[lubricating oil]]></category>
		<category><![CDATA[refinery]]></category>
		<category><![CDATA[serious burns]]></category>
		<category><![CDATA[Suez]]></category>
		<category><![CDATA[WA]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8079</guid>
		<description><![CDATA[Refinery fires are taking center stage as a leaky flange connection may be the cause of one blaze at BP&#8217;s <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/hunting-down-clues-in-refinery-fires/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>Refinery fires are taking center stage as a leaky flange connection may be the cause of one blaze at BP&#8217;s Cherry Point, WA, refinery, while another explosion that killed four workers in Egypt is still under investigation.</p>
<p>In the Cherry Point fire, information filed with the Coast Guard&#8217;s National Response Center is very preliminary and the cause remains under investigation, said BP spokesman Scott Dean.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/firms-cited-for-toxic-chemical-releases/">Firms Cited for Toxic Chemical Releases</a><br />
<a href="http://www.isssource.com/refinery-suffers-penalties-sentences/">Refinery Suffers Penalties, Sentences</a><br />
<a href="http://www.isssource.com/osha-chemical-emphasis-program-starts/">Chemical Emphasis Program Fires Up</a><br />
<a href="http://www.isssource.com/wa-refineries-need-to-clean-up-air/">WA Refineries Need to Clean Up Air</a>
</p></blockquote>
<p>It remains unclear how long the refinery would be out of service as a result of the Friday fire. The company is trying to supply customers from existing stocks or other sources.</p>
<p>The refinery can process 230,000 barrels of crude oil a day. It produces 20 percent of Washington&#8217;s gasoline and the majority of aviation fuel for the Vancouver, British Columbia, Sea-Tac and Portland airports.</p>
<p>Meanwhile, the director of an oil refinery says four of his Egyptian workers died as they tried to put out a huge fire that erupted at the plant&#8217;s complex in the port city of Suez. </p>
<p>Reda Abdel-Samad said the floor on which the men were standing collapsed as the fire raged in the lubricating oil section at the refinery. </p>
<p>Five other workers suffered serious burns, he said. Abdel-Samad says the fire raged for at least two hours before firefighters managed to put it out. </p>
<p>Investigators are looking to determine the cause of the blast.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/hunting-down-clues-in-refinery-fires/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>African Frontier: Shell Buys Cove Energy</title>
		<link>http://www.isssource.com/african-frontier-shell-buys-cove-energy/</link>
		<comments>http://www.isssource.com/african-frontier-shell-buys-cove-energy/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 23:06:37 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Africa]]></category>
		<category><![CDATA[Andarko]]></category>
		<category><![CDATA[Bharat Petroleum]]></category>
		<category><![CDATA[Cove Energy]]></category>
		<category><![CDATA[Eni]]></category>
		<category><![CDATA[Kenya]]></category>
		<category><![CDATA[liquefied natural gas]]></category>
		<category><![CDATA[LNG]]></category>
		<category><![CDATA[Mitsui]]></category>
		<category><![CDATA[Mozambique]]></category>
		<category><![CDATA[natural gas]]></category>
		<category><![CDATA[recoverable reserves]]></category>
		<category><![CDATA[Rovuma]]></category>
		<category><![CDATA[Rovuma Offshore Area 1]]></category>
		<category><![CDATA[Royal Dutch Shell]]></category>
		<category><![CDATA[Statoil]]></category>
		<category><![CDATA[Tanzania]]></category>
		<category><![CDATA[Videocon]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8076</guid>
		<description><![CDATA[Safety and security are major initiatives for energy companies, but refiners will have to step it up a notch as <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/african-frontier-shell-buys-cove-energy/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>Safety and security are major initiatives for energy companies, but refiners will have to step it up a notch as Africa is becoming an oil and gas hotbed of activity. </p>
<p>Making the latest move into Africa, Royal Dutch Shell Plc, will pay $1.6 billion for Mozambique-based focused Cove Energy.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/canadian-utility-deals-for-u-s-utility/">Canadian Utility Deals for U.S. Utility</a><br />
<a href="http://www.isssource.com/fracking-future-apache-deals-for-driller/">Fracking Future: Apache Deals for Driller</a><br />
<a href="http://www.isssource.com/fracking-foreign-firms-fund-pacts/">Fracking: Foreign Firms Fund Pacts</a><br />
<a href="http://www.isssource.com/abb-dealing-buys-ups-provider/">ABB Dealing: Buys UPS Provider</a>
</p></blockquote>
<p>Cove&#8217;s main asset is an 8.5 percent stake in the Rovuma Offshore Area 1, in Mozambique, where operator Anadarko said recoverable reserves could top 30 trillion cubic feet of natural gas.</p>
<p>The project partners plan to build plants to freeze the gas into liquefied natural gas (LNG) and ship it to Asian markets.</p>
<p>&#8220;East Africa is a major prospective hydrocarbon province, which has seen a significant increase in exploration activity in recent years,&#8221; Shell said in its offer document. </p>
<p>&#8220;Shell already has interests in Tanzania, and the acquisition of Cove would mark Shell&#8217;s entry into exciting new hydrocarbon provinces in Kenya and Mozambique, with significant potential for new LNG from recent gas discoveries offshore Mozambique, and further complementary exploration positions in East Africa.&#8221;</p>
<p>Neighboring the Rovuma find, Italy&#8217;s Eni made its own major gas finds while, north of the maritime border, Norway&#8217;s Statoil has made a find in Tanzanian waters.</p>
<p>On Tuesday, the Tanzanian government said British gas and oil firm BG Group planned to step up its investment on the east African coastline fast becoming a major gas hub with a $500 million investment this year.</p>
<p>In addition to Anadarko, Japan&#8217;s Mitsui and Indian groups Bharat Petroleum and Videocon each own 10 percent stakes in the Rovuma license. The values of these interests could now be more valuable.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/african-frontier-shell-buys-cove-energy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Details on NFS Acid Leak</title>
		<link>http://www.isssource.com/details-on-nfs-acid-leak/</link>
		<comments>http://www.isssource.com/details-on-nfs-acid-leak/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 22:43:54 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[300 gallons]]></category>
		<category><![CDATA[800 gallons]]></category>
		<category><![CDATA[dike]]></category>
		<category><![CDATA[Erwin]]></category>
		<category><![CDATA[NFS]]></category>
		<category><![CDATA[NRC]]></category>
		<category><![CDATA[Nuclear Fuel Services]]></category>
		<category><![CDATA[Nuclear Regulatory  Commission]]></category>
		<category><![CDATA[outdoor chemical storage]]></category>
		<category><![CDATA[safe shutdown]]></category>
		<category><![CDATA[TDEC]]></category>
		<category><![CDATA[Tennessee Department of Environment & Conservation]]></category>
		<category><![CDATA[TN]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8073</guid>
		<description><![CDATA[Up to 800 gallons of nitric acid may have leaked Nuclear Fuel Services (NFS) Erwin, TN, facility Jan. 9 Tennessee <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/details-on-nfs-acid-leak/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>Up to 800 gallons of nitric acid may have leaked Nuclear Fuel Services (NFS) Erwin, TN, facility Jan. 9 Tennessee Department of Environment &#038; Conservation (TDEC) officials said.</p>
<p>The initial report on the accident was &#8220;that approximately 800 gallons spilled. However, there was also water in the containment area, so we cannot determine exactly how much,&#8221; said TDEC spokeswoman Meg Lockhart. </p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/refinery-upsets-rage-for-second-day/">Refinery Upsets Rage for Second Day</a><br />
<a href="http://www.isssource.com/another-release-at-raccoon-refinery/">Another Release at ‘Raccoon’ Refinery</a><br />
<a href="http://www.isssource.com/raccoon-tests-refinery-safety-system/">Raccoon Tests Refinery Safety System</a><br />
<a href="http://www.isssource.com/epa-leak-breaches-water-standards/">EPA: Leak Breaches Water Standards</a>
</p></blockquote>
<p>The Nuclear Regulatory Commission (NRC) report said that NFS reported &#8220;approximately 300 gallons of nitric acid had spilled.&#8221;</p>
<p>Around noon Jan. 9, a nitric acid leak occurred in an outdoor chemical storage area at NFS. The nitric acid ended up contained by a dike designed for such a purpose, officials said.</p>
<p>Following the incident, facility operations went into a “safe shutdown,” in which operations in certain areas temporarily halted and everyone followed NFS procedure to ensure these areas were in stable condition. </p>
<p>As a precaution, NFS employees working in areas near the leak went to another NFS facility, and two employee went to NFS medical staff due to possible exposure to nitric acid vapor. They ended up released. </p>
<p>No injuries were reported as a result of the incident.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/details-on-nfs-acid-leak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker Scopes Royal Navy, The Fed</title>
		<link>http://www.isssource.com/hacker-scopes-royal-navy-the-fed/</link>
		<comments>http://www.isssource.com/hacker-scopes-royal-navy-the-fed/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 22:24:50 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Arizona University]]></category>
		<category><![CDATA[Chinese schools]]></category>
		<category><![CDATA[cross-site scripting vulnerability]]></category>
		<category><![CDATA[German hacker]]></category>
		<category><![CDATA[Hong Kong]]></category>
		<category><![CDATA[OpChina]]></category>
		<category><![CDATA[Pastebin]]></category>
		<category><![CDATA[proof of concepts]]></category>
		<category><![CDATA[Royal Navy]]></category>
		<category><![CDATA[SQL injection vulnerability]]></category>
		<category><![CDATA[Stanford University]]></category>
		<category><![CDATA[U.S. Federal Reserve]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8070</guid>
		<description><![CDATA[A German hacker breached the official website of the Royal Navy and found holes in the U.S. Federal Reserve after <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/hacker-scopes-royal-navy-the-fed/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>A German hacker breached the official website of the Royal Navy and found holes in the U.S. Federal Reserve after finding an SQL injection vulnerability.</p>
<p>“The admins have been warned immediately before of this post. The vulnerable ‘parameter’ has been obscured to prevent damages from others,” the hacker wrote on Pastebin.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/amnesty-for-ca-violations/">Amnesty for CA Violations</a><br />
<a href="http://www.isssource.com/unintended-man-in-the-middle/">Unintended Man in the Middle</a><br />
<a href="http://www.isssource.com/cyber-report-bad-guys-winning/">Cyber Report: Bad Guys Winning</a><br />
<a href="http://www.isssource.com/security-best-practices-will-cut-downtime/">Security Best Practices will Cut Downtime</a>
</p></blockquote>
<p>This is not the first time the Royal Navy’s website suffered a breach. A few years back, Romanian hacker TinKode also broke in, but authorities busted him last month.</p>
<p><em>D35m0nd142</em> also found a vulnerability on the official website of the U.S. Federal Reserve. In this case, he found 47 blind SQL injection flaws on the site’s pages.</p>
<p>Since university websites are among his specialties, the hacker took a peek at the security measures implemented by Arizona University, Stanford University, and an education institution in Hong Kong. From the U.S. universities he leaked some data to prove they are weak, but the Chinese school’s site ended up defaced.</p>
<p>This wasn’t the only defacement that targeted major Chinese sites. Thirteen Chinese government sites ended up defaced as part of an operation called OpChina. </p>
<p>Another hack in Asia targeted the official website of Iran’s president. On this site, he identified a cross-site scripting (XSS) vulnerability, a type of weakness that allows an attacker to execute arbitrary code.</p>
<p>In most of the cases, the site’s administrators got the news before <em>D35m0nd142</em> published his proof-of-concepts or screenshots to prove he really did gain access.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/hacker-scopes-royal-navy-the-fed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Food Maker Faces Machine Safety Fines</title>
		<link>http://www.isssource.com/food-maker-faces-machine-safety-fines/</link>
		<comments>http://www.isssource.com/food-maker-faces-machine-safety-fines/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 21:42:25 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Bridgford Foods Corp.]]></category>
		<category><![CDATA[energy sources]]></category>
		<category><![CDATA[lockout/tagout procedures]]></category>
		<category><![CDATA[machine guarding]]></category>
		<category><![CDATA[Occupational Safety and Health Administration]]></category>
		<category><![CDATA[OSHA]]></category>
		<category><![CDATA[Severe Violators Enforcement Program]]></category>
		<category><![CDATA[six serious]]></category>
		<category><![CDATA[two repeat safety violations]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8068</guid>
		<description><![CDATA[Anaheim, CA-based Bridgford Foods Corp. is facing $174,500 in fines for six serious and two repeat safety violations at one <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/food-maker-faces-machine-safety-fines/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>Anaheim, CA-based Bridgford Foods Corp. is facing $174,500 in fines for six serious and two repeat safety violations at one of its food manufacturing facilities in Dallas, said Occupational Safety and Health Administration (OSHA) officials.</p>
<p>An investigation started Aug. 23, at the company&#8217;s Chancellor Row location as part of OSHA’s Severe Violators Enforcement Program, which mandates follow-up inspections of recalcitrant employers that endangered workers by committing willful, repeat, or failure-to-abate violations.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/barge-maker-faces-osha-safety-fines/">Barge Maker Faces OSHA Safety Fines</a><br />
<a href="http://www.isssource.com/biodiesel-maker-faces-safety-fines/">Biodiesel Maker Faces Safety Fines</a><br />
<a href="http://www.isssource.com/safety-alert-manufacturers-fined-for-violations/">Safety Alert: Manufacturers Fined for Violations</a><br />
<a href="http://www.isssource.com/manufacturer-faces-safety-fines-2/">Manufacturer Faces Safety Fines</a>
</p></blockquote>
<p>&#8220;Bridgford Foods has a history of putting its employees at risk of serious injury,&#8221; said John Hermanson, OSHA&#8217;s regional administrator in Dallas. &#8220;The company needs to adhere to OSHA&#8217;s standards for controlling hazardous energy and machine guarding to prevent the loss of limb and life.&#8221;</p>
<p>The serious violations include failing to provide required machine guarding to prevent workers from coming into contact with rotating parts on drill presses, implement energy control procedures for machinery with more than one energy source, ensure that employees have training on the use of energy control procedures, and prevent slip and &#8220;struck-by&#8221; hazards by ensuring walkways are kept clean and dry.</p>
<p>The repeat violations involve failing to ensure lockout/tagout procedures of energy sources occurred by an authorized employee and the authorized employee affixed a personal lock or tag to the group lockout device. OSHA cited the company for similar violations in February 2008 with penalties of $8,000, in September 2008 with penalties of $33,900, and in January 2010 with penalties of $106,000.</p>
<p>Additionally, OSHA cited the company&#8217;s facility on South Good Latimer Expressway in Dallas in October 2011 for 27 safety and health violations with penalties totaling $422,600.</p>
<p>Bridgford Foods manufactures frozen bread dough, biscuits, cinnamon roll doughs, sandwiches, beef jerky, and snack and deli foods.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/food-maker-faces-machine-safety-fines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDoS Tool Heads to Android</title>
		<link>http://www.isssource.com/ddos-tool-heads-to-android/</link>
		<comments>http://www.isssource.com/ddos-tool-heads-to-android/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 21:27:54 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Anonymous Argentina]]></category>
		<category><![CDATA[cause]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hactivists]]></category>
		<category><![CDATA[LOIC]]></category>
		<category><![CDATA[low orbit ion cannon]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[potentially unwanted program]]></category>
		<category><![CDATA[PUP]]></category>
		<category><![CDATA[WebLOIC]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8066</guid>
		<description><![CDATA[The Low Orbit Ion Cannon (LOIC) is popular among hackers that want to take down a certain website and now <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/ddos-tool-heads-to-android/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>The Low Orbit Ion Cannon (LOIC) is popular among hackers that want to take down a certain website and now there is a version designed for Android users.</p>
<p>The tool first appeared via Anonymous Argentina as the hacktivists urged their supporters to download the application to aid their cause, McAfee researchers said.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/mobile-malware-skyrocketing/">Mobile Malware Skyrocketing</a><br />
<a href="http://www.isssource.com/hackers-find-cell-phone-location/">Hackers Find Cell Phone Location</a><br />
<a href="http://www.isssource.com/apple-deals-with-app-privacy-issues/">Apple Deals with App Privacy Issues</a><br />
<a href="http://www.isssource.com/apple-supplier-hit-by-hack/">Apple Supplier Hit by Hack</a>
</p></blockquote>
<p>The developers didn’t start this WebLOIC for Android from the ground up. They simply ported the web application using a free online service that creates Android apps from a URL or a piece of HTML code.</p>
<p>Created to aid Anonymous in OpArgentina, the LOIC for Android went out in a hurry; they didn’t even resize the page to fit the screen of a smartphone. </p>
<p>Researchers to determine they programmed it to send 1,000 HTTP requests with one of the parameters being the message “We are LEGION.” </p>
<p>McAfee identified this tool as Android/DIYDoS and cataloged it as being a potentially unwanted program (PUP). </p>
<p>“Because the application’s purpose is simply to display any website on an Android system, we classify this hack tool a potentially unwanted program,” McAfee Labs Malware Researcher Carlos Castillo said.</p>
<p>Another reason why this tool is a PUP is because of prior reports where the hacktivists tried to dupe unsuspecting Internet users into clicking on links that led to a version of web LOIC that automatically sent large numbers of packets toward a designated target.</p>
<p>DOS tools such as LOIC have become popular not only among hackers, but also among regular users who support their causes. </p>
<p>The best example for this is the massive attacks that took place following the Megaupload closure. At the time, reports revealed more than 5,000 individuals used these automated tools to launch attacks against the FBI, RIAA, the U.S. Department of Justice and many others.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/ddos-tool-heads-to-android/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amnesty for CA Violations</title>
		<link>http://www.isssource.com/amnesty-for-ca-violations/</link>
		<comments>http://www.isssource.com/amnesty-for-ca-violations/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 21:00:41 +0000</pubDate>
		<dc:creator>gHale</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[amnesty]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[domain name]]></category>
		<category><![CDATA[hardware security module]]></category>
		<category><![CDATA[HSM]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[reprieve]]></category>
		<category><![CDATA[root certificates]]></category>
		<category><![CDATA[SSL traffic management]]></category>
		<category><![CDATA[sub-CA keys]]></category>
		<category><![CDATA[Trustwave]]></category>

		<guid isPermaLink="false">http://www.isssource.com/?p=8064</guid>
		<description><![CDATA[Mozilla wants all certificate authorities (CAs) to revoke subordinate CA certificates used for corporate SSL traffic management, offering a reprieve <br /><a style="color:red;text-decoration:underline;" href="http://www.isssource.com/amnesty-for-ca-violations/">Read More</a>]]></description>
			<content:encoded><![CDATA[<p>Mozilla wants all certificate authorities (CAs) to revoke subordinate CA certificates used for corporate SSL traffic management, offering a reprieve to any CAs that breached Mozilla&#8217;s conditions for having their root certificates ship with its products.</p>
<p>The request comes after <a href="http://www.isssource.com/unintended-man-in-the-middle/">Trustwave issued a sub-CA certificate</a> to a private company for use in a data loss prevention system.</p>
<blockquote><p>
<strong>RELATED STORIES</strong><br />
<a href="http://www.isssource.com/unintended-man-in-the-middle/">Unintended Man in the Middle</a><br />
<a href="http://www.isssource.com/advantechs-new-version-of-webaccess/">Advantech’s New Version of WebAccess</a><br />
<a href="http://www.isssource.com/cyber-report-bad-guys-winning/">Cyber Report: Bad Guys Winning</a><br />
<a href="http://www.isssource.com/security-best-practices-will-cut-downtime/">Security Best Practices will Cut Downtime</a>
</p></blockquote>
<p>Sub-CA keys can sign SSL certificates for any domain name on the Internet, which makes them very dangerous if they fall in the wrong hands.</p>
<p>Even though Trustwave said the sub-CA key in question was in a hardware security module (HSM), making it irretrievable, the fact that such a powerful certificate was issued to a private company that wasn&#8217;t a certificate authority, represents a violation of Mozilla&#8217;s policy for CAs.</p>
<p>Certificate authorities voluntarily adhere to Mozilla&#8217;s CA Certificate Policy in order to have their root keys included by default in Firefox, Thunderbird and other Mozilla products.</p>
<p>&#8220;Participation in Mozilla&#8217;s root program is at our sole discretion, and we will take whatever steps are necessary to keep our users safe, up to and including the removal of root certificates that mis-issue, as well as any roots that cross-sign them,&#8221; said Johnathan Nightingale, senior director of Firefox Engineering at Mozilla. </p>
<p>Because there is reason to believe that multiple CAs engage in this type of behavior, Mozilla has decided to offer everyone a one-time chance to come clean about it without risking repercussions instead of making an example out of Trustwave, which would likely discourage similar disclosures.</p>
<p>&#8220;We believe that security is best served when browsers and CAs can work together; we hope that frank communication and clear expectations can resolve these issues before any such action is required,&#8221; Nightingale said.</p>
<p>Mozilla made its amnesty offer in an email to all CAs on Friday, asking them to revoke sub-CA certificates used for SSL man-in-the-middle interception or traffic management and to destroy the corresponding HSMs.</p>
<p>&#8220;We have requested the serial numbers of those certificates and fingerprints of their signing roots so that we, and other relying parties, can detect and distrust these subCA certificates if encountered,&#8221; Nightingale said.</p>
<p>CAs have until April 27 to comply with these requests. If they find those certificates after that date, the issuing CAs will face punishments including the removal of their root keys from Mozilla&#8217;s products.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.isssource.com/amnesty-for-ca-violations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 1/5 queries in 0.001 seconds using disk
Object Caching 817/817 objects using disk

Served from: www.isssource.com @ 2012-02-22 23:06:09 -->
