Reports: Syrian Government Using Man-in-the-Middle Attacks to Compromise Citizens’ Facebook Accounts

This article is over 13 years old and may contain outdated information

Recommended Videos

Reports are issuing from Syrian bloggers that the government-run Syrian Telecom Ministry is compromising the security of citizens’ Facebook accounts. In what appears to be a man-in-the-middle attack against the HTTPS version of Facebook, logging in triggers a browser warning like the one above, saying that the certificate is invalid not to be trusted.

The certificate on the left, issued to “Facebook, Inc.” is not real; the DigiCert one is. The EFF says that it’s a sign of the relative unsophistication of the alleged government attack that it raises a warning at all: However, there are plenty of people who don’t pay attention to browser warnings, especially if they’re attempting to log into a trusted site like Facebook. Logging in anyway would give the attackers behind the phony certificate “access to and control of their Facebook account,” so this is serious business.

(EFF via Boing Boing)


The Mary Sue is supported by our audience. When you purchase through links on our site, we may earn a small affiliate commission. Learn more about our Affiliate Policy
Author