About this tag
The tag 'spoofed certificates' covers discussions about fraudulent digital certificates issued by compromised certificate authorities. A key example is the DigiNotar breach, where spoofed certificates for domains like *.microsoft.com and *.windowsupdate.com were discovered. Microsoft responded by revoking trust in DigiNotar and releasing updates to protect users. The tag highlights how spoofed certificates can be used in man-in-the-middle attacks, the importance of certificate revocation, and the steps Microsoft takes to safeguard Windows users through updates and multiple verification methods for Windows Update content.
  1. News

    More on Microsoft’s response to the DigiNotar compromise

    Microsoft’s investigation into the scope and impact of the DigiNotar compromise has continued over the holiday weekend. We’ve now confirmed that spoofed certificates for *.microsoft.com and *.windowsupdate.com are among those issued by the Dutch firm. Users of Vista and later...