Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
[Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  8 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Eddy Nigg  
View profile  
 More options Dec 21 2008, 7:09 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Mon, 22 Dec 2008 02:09:28 +0200
Local: Sun, Dec 21 2008 7:09 pm
Subject: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
Has anybody an idea how to prevent those spam and scam attempts? I
already contacted Godaddy with an abuse complaint. What else?

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Dec 21 2008, 7:49 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Mon, 22 Dec 2008 02:49:59 +0200
Local: Sun, Dec 21 2008 7:49 pm
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
On 12/22/2008 02:09 AM, Eddy Nigg:

> Has anybody an idea how to prevent those spam and scam attempts? I
> already contacted Godaddy with an abuse complaint. What else?

Apparently this site is connected to Comodo. I went all the way and paid
for a certificate in order to find out who is responsible for this scam.
I'm contacting the reps from Comodo, contacted Paypal which they also
use for payment processing, Entrust which issued their site certificate,
Godaddy which sold the domain.

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gen Kanai  
View profile  
 More options Dec 21 2008, 9:15 pm
Newsgroups: mozilla.dev.tech.crypto
From: Gen Kanai <g...@mozilla.com>
Date: Mon, 22 Dec 2008 11:15:39 +0900
Local: Sun, Dec 21 2008 9:15 pm
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]

On Dec 22, 2008, at 9:49 AM, Eddy Nigg wrote:

> On 12/22/2008 02:09 AM, Eddy Nigg:
>> Has anybody an idea how to prevent those spam and scam attempts? I
>> already contacted Godaddy with an abuse complaint. What else?

> Apparently this site is connected to Comodo. I went all the way and  
> paid for a certificate in order to find out who is responsible for  
> this scam. I'm contacting the reps from Comodo, contacted Paypal  
> which they also use for payment processing, Entrust which issued  
> their site certificate, Godaddy which sold the domain.

Eddy,

Can you provide us a little more background here as to what you just  
experienced?

Thank you in advance,

Gen


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Dec 21 2008, 9:43 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Mon, 22 Dec 2008 04:43:53 +0200
Local: Sun, Dec 21 2008 9:43 pm
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
On 12/22/2008 04:15 AM, Gen Kanai:

I received today the email which I forwarded to the list. Apparently
they operate a robot scanning for secured sites and send a "reminder"
message prior to expiration of the certificate, pretending and
resembling our own messages which we send out to our own legitimate
users and customers.

The email is clearly an attempt to trick our customers and that of
others believing that they have to renew their certificate (which I
received exactly 10 days before expiration of the installed certificate)
and by clicking at the link. The name certstart.com resembles that of
our own sites cert.startcom.org and startssl.com.

Once using the link, the site lists the domain name and pretended
further to renew the SSL certificate for domain startcom.org.

I tried to find out who is behind this scam, but nowhere is the CA
listed. The site itself is secured by an Equifax certificate. So I went
all the way through, registered * and ordered one of their certs for our
domain, paid via Paypal and received a shiny certificate for 45 US$ from
Comodo. I retained all evidences of the emails, screen shots, Paypal
payments, certificates, etc.

I contacted all parties involved including my contact at Comodo. I also
had contact with the operator of this site himself and requested
immediate cessation of all activities including the web site itself.

* During "Renewal" the site requests "New username", further giving the
impression as if one already had previously a username.

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kyle Hamilton  
View profile  
 More options Dec 21 2008, 10:05 pm
Newsgroups: mozilla.dev.tech.crypto
From: "Kyle Hamilton" <aerow...@gmail.com>
Date: Sun, 21 Dec 2008 19:05:23 -0800
Local: Sun, Dec 21 2008 10:05 pm
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]

Why does it matter?  We've already seen that the former CEO of the
Mozilla Corporation won't remove anything from the cert store, even if
there are valid complaints against the CA's business or trust.

-Kyle H


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Dec 21 2008, 10:16 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Mon, 22 Dec 2008 05:16:16 +0200
Local: Sun, Dec 21 2008 10:16 pm
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
On 12/22/2008 05:05 AM, Kyle Hamilton:

Not sure if this is a reason to disable a root, but it's certainly
illegal business practice. Hopefully we can settle this with Comodo
directly in appropriate manner.

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ian G  
View profile  
 More options Dec 22 2008, 4:11 am
Newsgroups: mozilla.dev.tech.crypto
From: Ian G <i...@iang.org>
Date: Mon, 22 Dec 2008 10:11:23 +0100
Local: Mon, Dec 22 2008 4:11 am
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
On 22/12/08 04:16, Eddy Nigg wrote:

> Not sure if this is a reason to disable a root, but it's certainly
> illegal business practice. Hopefully we can settle this with Comodo
> directly in appropriate manner.

Seems like the business is in Denmark, and claims Danish law and courts.
  Which law are you claiming is breached?  Just curious...

iang


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Dec 22 2008, 8:08 am
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Mon, 22 Dec 2008 15:08:22 +0200
Local: Mon, Dec 22 2008 8:08 am
Subject: Re: [Fwd: Reminder - SSL Certificate for *.startcom.org expires in 10 Days]
On 12/22/2008 11:11 AM, Ian G:

> On 22/12/08 04:16, Eddy Nigg wrote:
>> Not sure if this is a reason to disable a root, but it's certainly
>> illegal business practice. Hopefully we can settle this with Comodo
>> directly in appropriate manner.

> Seems like the business is in Denmark, and claims Danish law and courts.
> Which law are you claiming is breached? Just curious...

Unfortunately I can't comment any further on this matter what legal
issues concerns...

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google