360 responds to the security lobster private key leak incident

robot
Abstract generation in progress

Recently, it was reported that 360’s AI product, 360 Safe Lobster, which is under 360 Company, had serious security oversights at the time of release: the product installer package directly bundled and embedded *.myclaw.360.cn wildcard domain SSL private keys and certificates, raising major concerns among the industry and users about information security.

360 Company told First Financial that it has revoked the certificates involved immediately, and that the certificates are now invalid, so ordinary users will not be affected. 360 Company revealed that this issue was caused by a mistake in the release process, which led to the website certificate for an internal domain being accidentally packaged into the installer. After the problem was discovered, the company immediately took emergency measures and completed the revocation of the certificates involved, blocking—at the technical level—the possibility that an attacker could use the private key to forge servers and hijack traffic. (First Financial)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin