Not wishing to be picky ;-) but it wasn't actually "stolen" as it was
never Microsoft's in the first place. Verisign were stupid enough to
issue two certificates to an individual claiming to be from Microsoft,
without checking - needless to say, they weren't.

Anyone relatively savvy should be OK, as trust is on a
certificate-by-certificate basis, not based on a common name - thus,
even though code signed with the official MS certificates may be
trusted by default, an encounter with one of the fake certifcates will
prompt for confirmation of usage.

Basically - *DON'T* trust any certificate claiming to belong to MS
issued on January 29 or 30, 2001.

For more details:

MS Security Bulletin 01-017

MS Knowledge Base article Q293818: "Erroneous VeriSign-Issued Digital
Certificates Pose Spoofing Hazard"

Russ' post on the subject to NTBugTraq

For those interested in the more technical details of the problem,
there's a thread on BugTraq ( and follow
the links to BugTraq, archive, or simply cheat and go to
[apologies if that wrapped...])

Adam D. Barratt

