Explore the dark web's SSL/TLS certificate marketplace and its impact on cybersecurity in this 53-minute RSA Conference talk. Delve into new research findings on the prevalence and value of encryption certificates, including their availability, packaging, pricing, and purchasing processes. Gain insights into how cybercriminals exploit these certificates for attacks, and understand the established marketplace enabling such activities. Examine evidence-based approaches, cybercrime ecosystems, and experiments conducted to uncover these threats. Learn about the specific vulnerabilities of EV (Extended Validation) certificates and the methods fraudsters use to obtain them. Discover the intricate details of certificate authorities, the value of different certificate types, and the step-by-step process cybercriminals follow to acquire fraudulent certificates. Suitable for those with a general understanding of encryption's role in security and privacy, and the use of SSL/TLS certificates.
The Modus Operandi of EV Certificates Fraudsters - Findings from the Field