The Latest in IT Security

Posts Tagged ‘ssl certificate’

Today we saw the discovery of another rogue SSL certificate – this time for *.google.com. The certificate itself was issued five weeks ago. This will allow an attacker to sniff the traffic to virtually all of Google’s services even with HTTPS enabled. Right now, there’s an unconfirmed report this attack is happening in Iran. Frankly, […]

Read more ...

Diginotar is a Dutch Certificate Authority. They sell SSL certificates. Somehow, somebody managed to get a rogue SSL certificate from them on July 10th, 2011. This certificate was issued for domain name .google.com. What can you do with such a certificate? Well, you can impersonate Google — assuming you can first reroute Internet traffic for […]

Read more ...

I had the pleasure of attending Moxie Marlinspike’s DEFCON talk “SSL And The Future Of Authenticity.” Marlinspike is a great presenter and he doesn’t just point out the problems with what we are doing now, but proposes solutions, often with working proof-of-concept code. Marlinspike didn’t disappoint and began the talk with a funny story, rather […]

Read more ...


Categories

SATURDAY, JUNE 07, 2025
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments