ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Digital signatures may be prone to scams

Will Knight ZDNet.co.uk

Published: 09 Dec 1999 15:13 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The document digitally signed by the Secretary for the Department of Trade and Industry Wednesday can be easily fooled, or "spoofed", according to British security and software development firm Skygate.

BT responds, however, that the trick is of limited application and points out that it doesn't really affect Trustwise's security.

On Thursday Skygate posted a Web page claiming to show how the verification of a signature can be forged using simple HTML and JavaScript. On the page, Skygate argued that a user who is not overly cautious can be fooled into thinking that any signature has been authenticated by BT's Trustwise service. In actual fact the spoofing method transports them to a different BT Trustwise page that did originally authenticate a signature.

Skygate says a simple way to avoid this sting is to disable JavaScript in a browsers preferences.

As of Thursday afternoon, however, the page had been taken down, leaving only a note with the explanation that "this page has been withdrawn following discussions with BT."

Skygate Director Pete Chown sees the spoofing method as a potentially serious flaw in BT's security plans. He says, "There is the possibility that someone could set up a fake site for, say, paying your phone bills, and capture people's credit card details. This could be particularly serious if this becomes a public service. BT should make sure that their pages really authenticate a signature instead of just throwing HTML back at you."

Neil Barrett, security specialist at Information Risk Management, believes however that for the security-conscious user this shouldn't be a particular threat. "It's like a spoofed email. If you look at the guts of the page and really test it, you will see that it's fake. If you actually go to the Trustwise site and ask whether the page is recognised it won't verify it."

Barrett sees this example as further evidence of the need to make people aware of the security risks that do exist online. He adds, "It's a flaw in the degree of trust you put in it. If there is one thing wrong with e-commerce it is that the public is being swayed into thinking that everything is secure."

According to Barrett, there is another very simple way in which the Trustwise verification system could be unscrupulously exploited. "Another way is to register another very similar name. The system is obviously not clever enough to do name mapping." This means that by misspelling or adding an initial to a name it might be possible to fool someone into thinking the digital signature belongs to an entirely different individual or organisation.

Skygate's Trustwise criticism comes just a day after the technology's public endorsement by DTI secretary Stephen Byers.

A BT spokesman plays down the significance of the stunt saying, "It's not a breach of security, they haven't got into the Trustwise site. Also, with the real system you can verify a whole site and you can't do that with this. We are in discussions with the people who have done this and are working on ways to stop it happening anymore. It's an inconvenience rather than anything else."

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
57 out of 105 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Web developer - Expanding Consultancy - Blue Chip Financial projects

Skills for this role will include; proven experience in ASP.NET/VB.NET Javascript, HTML SQL Server 2000. These will include; website production ...

HTML, XHTML, JAVASCRIPT and CSS UI Development Media

HTML, XHTML, JAVASCRIPT and CSS UI Development Media Huxley Associates media client based in the Centre of London are looking to add a UI developer ...

Technical Architect - C# .Net, SQL Server - London

Essential Skills C# .Net JavaScript SQL Server My SQL HTML SOAP FTP Web Services Social Networking This company is a house-hold name as a result of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments