The Latest in IT Security

Posts Tagged ‘certificates’

Today we saw the discovery of another rogue SSL certificate – this time for *.google.com. The certificate itself was issued five weeks ago. This will allow an attacker to sniff the traffic to virtually all of Google’s services even with HTTPS enabled. Right now, there’s an unconfirmed report this attack is happening in Iran. Frankly, […]

Read more ...

Update: Mozilla have announced out of an abundance of caution that they are releasing new versions of Firefox, Firefox Mobile and Thunderbird to revoke the trust of DigiNotar’s root certificate for signing certificates. I presume this is because DigiNotar has not explained how the Google certificate was signed and to prevent further abuse. This could […]

Read more ...

I had the pleasure of attending Moxie Marlinspike’s DEFCON talk “SSL And The Future Of Authenticity.” Marlinspike is a great presenter and he doesn’t just point out the problems with what we are doing now, but proposes solutions, often with working proof-of-concept code. Marlinspike didn’t disappoint and began the talk with a funny story, rather […]

Read more ...


Categories

WEDNESDAY, MARCH 12, 2025
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments