TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Opera breached, has code cert stolen, possibly spreads malware

172 pointsby JoeCoo7almost 12 years ago

8 comments

josteinkalmost 12 years ago
Ow. That&#x27;s really, really bad.<p>Opera is already a pretty small actor so stuff like this probably hurts them more than the bigger guys. This incident will probably show in the bottom-line later on.<p>Hope they get their things sorted out, and I really hope they learn enough to avoid having anything like this happening in the future. Things like this are never OK if there is a second time around.
评论 #5951577 未加载
评论 #5951360 未加载
pestaaalmost 12 years ago
The article claims the official story is unclear, but I disagree. As a potential customer, I&#x27;ve learnt everything I need to know to protect myself from vulnerabilities. (Though the inner hacker would like to hear how their infrastructure was compromised and whether it can have any effect on related services, such as Fastmail.)<p>Opera also states the security breach has been handled on their end, so I see nothing wrong with the announcement&#x27;s title either.<p>It would be unfortunate if the situation got out of hand, with recent fundamental changes to their browser, Opera now needs 100% focus to stay competitive.
评论 #5952266 未加载
jacobralmost 12 years ago
Official announcement: <a href="http://my.opera.com/securitygroup/blog/2013/06/26/opera-infrastructure-attack" rel="nofollow">http:&#x2F;&#x2F;my.opera.com&#x2F;securitygroup&#x2F;blog&#x2F;2013&#x2F;06&#x2F;26&#x2F;opera-infr...</a>
perlgeekalmost 12 years ago
There&#x27;s another possibility: Maybe opera has an internal service that accepts software uploads and automatically signs them. That way an attacker might have spread malware without having stolen the certificate.
hmottestadalmost 12 years ago
&quot;...may automatically have received and installed the malicious software...&quot;<p>That is nice. Automatic installation of malware. It&#x27;s the way to go :)
评论 #5951836 未加载
评论 #5952423 未加载
ernesthalmost 12 years ago
So should I trust the update that apt-get shows me? There is a 12.16.1760 in the deb.opera.com repository while the opera main page gives a download for version 12.15!
评论 #5951238 未加载
评论 #5951244 未加载
stock_toasteralmost 12 years ago
I wonder if this impacted Fastmail as well... ;_;
评论 #5956445 未加载
counterpointeralmost 12 years ago
The signing keys are the weakest link in the security infrastructure and are essentially the keys to the kingdom. We have seen this happen repeatedly, I think it&#x27;s time for all companies to build a lot of safeguards around the use of their private signing keys, like making employees input it manually everytime, or even split it across multiple employees. For Opera at least, I don&#x27;t think they do releases that frequently.