How Fraudsters Obtain EV Certificates for Scams

330 views
•
February 28, 2020
by
RSAC Cybersecurity
YouTube video player
How Fraudsters Obtain EV Certificates for Scams

TL;DR

Fraudsters can exploit weaknesses in certificate authorities’ identity-validation processes to obtain EV certificates for institutions that do not exist, including fictitious banks and retail websites. Research into this activity argues that cybersecurity decisions and policy reforms should rely on rigorous evidence about offenders, enablers, targets, guardians, and the wider cybercrime ecosystem.

Transcript

Thank you so much. Uh, and thank you all for attending this session. I know it's, uh, early morning Friday, so I appreciate-- I, I, I, um, specifically and, and, and very much appreciate the fact that, uh, you guys are here and, um, thrilled to share the findings we, uh, have from, from this really interesting operation we had last year, um, in the... Read More

Key Insights

  • EV certificate fraud is enabled by weaknesses in the identity-validation procedures used by certificate authorities in the United States and other countries, allowing criminals to seek trusted certificates for organizations that do not genuinely exist.
  • At least one international organized crime group is believed to have exploited the flawed validation process to obtain EV certificates associated with fictitious institutions, including nonexistent banks and retail websites.
  • Identity validation for certificates is comparable to passport issuance because both systems depend on an authority examining submitted evidence, checking its authenticity, and confirming that the applicant is genuinely connected to the claimed identity.
  • Trust in an EV certificate depends on the certificate authority’s verification process, so a certificate issued from inadequate or false documentation undermines confidence in both the represented organization and the validating authority.
  • Evidence-based cybersecurity is an approach that bases the adoption of security tools and policies on rigorous scientific evidence instead of decision-makers’ personal experience or their political, financial, and social backgrounds.
  • Cybersecurity research is incomplete when it concentrates only on technical mechanisms because understanding online crime also requires attention to human behavior, interactions, and the ecosystem in which offenders and defenders operate.
  • The cybercrime ecosystem contains four key groups for empirical study: offenders, enablers who support criminal operations, targets exposed to cybercrime, and guardians such as organizational security officers and law enforcement agencies.
  • Rigorous cybersecurity evidence can come from field experiments, surveys and analyses of security-system logs, and systematic observation. These methods can identify threats and vulnerabilities, improve target education, guide policy development, and strengthen guardians’ efforts.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How do fraudsters obtain EV certificates for fake organizations?

Fraudsters can obtain EV certificates by exploiting weaknesses in the identity-validation processes used by certificate authorities. The research indicates that at least one international organized crime group used such flaws to secure certificates for institutions that did not exist, including fictitious banks and retail websites. The presented excerpt identifies the validation failure as the central mechanism but does not provide the exact operational steps or documents used.

Q: Why is EV certificate validation compared with passport issuance?

The comparison shows that both systems rely on a trusted authority to confirm an applicant’s identity before issuing a credential. A passport application requires a completed form, proof of citizenship, proof of identity, photographs, fees, and official verification. Likewise, an EV certificate is only trustworthy if the certificate authority rigorously authenticates the organization requesting it. Weak verification damages confidence in the resulting credential.

Q: What was the main finding about fraudulent EV certificates?

The main finding was that a flaw existed in how certificate authorities in the United States and other countries validated identity. Researchers believed that at least one international organized crime group exploited this process and obtained EV certificates for nonexistent institutions. The examples given included fictitious banks and retail websites, demonstrating that apparently validated online identities could be created for organizations lacking a genuine existence.

Q: Why do fraudulent SSL/TLS certificates create a security problem?

Fraudulent certificates create a security problem because users depend on certificate authorities to verify that websites, servers, and applications represent the identities they claim. If criminals can receive EV certificates for nonexistent institutions, the validation process no longer provides dependable assurance. The description also states that cybercriminals use SSL/TLS certificates in attacks and that a marketplace for such certificates exists on the dark web.

Q: What is evidence-based cybersecurity?

Evidence-based cybersecurity is an approach that bases decisions about tools and policies on rigorous scientific evidence. It seeks to move beyond choices shaped by personal experience or decision-makers’ political, financial, and social backgrounds. Its purpose is to provide better information about what works and what does not, helping organizations, researchers, and public authorities make more conscious security decisions.

Q: Which actors should cybercrime researchers study?

Cybercrime researchers should study four key groups: offenders, enablers, targets, and guardians. Offenders conduct criminal activity, while enablers support their operations by creating malicious software or building darknet markets that facilitate illegal sales. Targets are those exposed to attacks. Guardians include chief information security officers, other organizational defenders, and law enforcement agencies operating within the cybersecurity environment.

Q: Which research methods support evidence-based cybersecurity?

The proposed approach uses three principal research designs: field experiments, survey research, and observation. Survey research is defined broadly enough to include analysis of logs from antivirus products and intrusion detection or prevention systems, not merely questionnaires. Observation must be thorough and rigorous. Together, these methods help researchers determine what works, identify threats and vulnerabilities, and evaluate protection levels.

Q: How can cybersecurity research improve policy and defense?

Cybersecurity research can improve policy and defense by producing rigorous empirical evidence about threats, vulnerabilities, criminal behavior, and protective measures. That evidence can help educate cybercrime targets more effectively, guide policy development, and direct the work of guardians who secure cyberspace. The certificate-fraud findings were significant enough that the FBI and Congress were considering changes to Internet identity-validation processes.

Summary & Key Takeaways

  • Researchers at Georgia State investigated darknet activity involving SSL/TLS certificates and identified a serious weakness in online identity validation. The central finding is that at least one international organized crime group appeared able to exploit certificate-authority procedures and obtain EV certificates for nonexistent institutions, including fictitious banks and retail websites.

  • The passport analogy illustrates why certificate validation matters. Governments require applications, citizenship evidence, identity documents, photographs, fees, and official verification before issuing passports. EV certificates similarly depend on trustworthy identity checks. If weak evidence can satisfy those checks, users cannot reliably trust the institution or the authority that validated it.

  • The research advocates evidence-based cybersecurity that evaluates policies and security tools through rigorous scientific evidence instead of personal experience or political, financial, and social influences. It recommends studying offenders, enablers, targets, and guardians through field experiments, survey-based analysis of security data, and systematic observation to guide education, policy, and defensive efforts.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚