Chinese Certificate Authority ‘mistakenly’ gave out SSL Certs for GitHub Domains

A Chinese certificate authority (CA) appeared to be making a significant security blunder by handing out duplicate SSL certificates for a base domain if someone just has control over its any subdomain.

The certificate authority, named WoSign, issued … Continue reading Chinese Certificate Authority ‘mistakenly’ gave out SSL Certs for GitHub Domains

What is Certificate Transparency? How It helps Detect Fake SSL Certificates

Do you know there is a huge encryption backdoor still exists on the Internet that most people don’t know about?

I am talking about the traditional Digital Certificate Management System… the weakest link, which is completely based on trust, and it has already been broken several times.

To ensure the confidentiality and integrity of their personal data, billions of Internet users blindly

Continue reading What is Certificate Transparency? How It helps Detect Fake SSL Certificates

Suckfly: Revealing the secret life of your code signing certificates

A China-based APT group has an insatiable appetite for stolen code-signing certificates.Read More Continue reading Suckfly: Revealing the secret life of your code signing certificates