It’s easy to fake Extended Validation certificates, research shows

What does the happy green lock at the top of your browser mean? Maybe not what you think. Extended Validation certificates — the files that tell your browser to show the lock — are supposed to make crystal clear who owns a website, in order to stymie cyberattacks and phishing. Instead, EV certificates are dangerously easy to fake, according to experts like U.S.-based researcher Ian Carroll. The certificates are meant to prove legal ownership of HTTPS websites so that you are certain, for instance, that Google owns the website you’re visiting. Browsers like Chrome and Firefox show a green bar with the company name to signify security. The iOS version of Safari even replaces URLs entirely with the EV certificate. The problem, Carroll explained in a recent blog post, is that it’s easy to incorporate under the same name as big-time companies and therefore imitate their EV certificate. Carroll did exactly that by incorporating […]

The post It’s easy to fake Extended Validation certificates, research shows appeared first on Cyberscoop.

Continue reading It’s easy to fake Extended Validation certificates, research shows

Apple protects its Wi-Fi enabled devices from KRACK attack

Apple has released security updates for its many popular products, and has finally plugged the recently unveiled WPA2 flaws that allow attackers to extract sensitive information from Wi-Fi traffic. Fixes for preventing a KRACK attack being leveraged against users have been included in the updates for all of Apple’s Wi-Fi enabled devices: Macs, iPhones and iPads, Apple Watch and Apple TV. Other plugged flaws of note A glut of vulnerabilities in WebKit, Apple’s layout engine … More Continue reading Apple protects its Wi-Fi enabled devices from KRACK attack

Apple’s new tracking protection is “sabotage”, claims ad industry

The ad industry is not happy with Apple’s latest move to limit how we get tracked around the web. Continue reading Apple’s new tracking protection is “sabotage”, claims ad industry

Every Major Advertising Group Is Blasting Apple for Blocking Cookies in the Safari Browser

The biggest advertising organizations say Apple will “sabotage” the current economic model of the internet with plans to integrate cookie-blocking technology into the new version of Safari. Marty Swant, reporting for AdWeek: Six trade groups — the Int… Continue reading Every Major Advertising Group Is Blasting Apple for Blocking Cookies in the Safari Browser

Microsoft Won’t Fix Security Bypass Vulnerability in Edge

Microsoft is opting to stand pat and not fix a content security bypass vulnerability in its Edge browser, something researchers warn could potentially lead to the disclosure of confidential information. Continue reading Microsoft Won’t Fix Security Bypass Vulnerability in Edge