IoT Device Attacks, FCC Fines Mobile Carriers, Let’s Encrypt Certificate Bug

In episode 111 for March 9th 2020: A new report shows that attacks on Internet of Things devices are on the rise, the FCC fines major mobile carriers for selling users’ location data, and details on what happens when 3 million HTTPS certificates … Continue reading IoT Device Attacks, FCC Fines Mobile Carriers, Let’s Encrypt Certificate Bug

Still Why No HTTPS?

Presently sponsored by: Varonis. Free Video Course: 7 Hidden Office 365 Security Settings You Can Only Unlock with PowerShell

Back in July last year, Scott Helme and I shipped a little pet project that tracked the world’s largest websites not implementing HTTPS by default. We called it Why No HTTPS? and it gave people a way to see the largest websites not taking transport layer security seriously. We also

Continue reading Still Why No HTTPS?

HSTS From Top to Bottom or GTFO

Presently sponsored by: Varonis. Free Video Course: 7 Hidden Office 365 Security Settings You Can Only Unlock with PowerShell

We’re pretty much at a “secure by default” internet these days, at least that’s the assumption with most websites, particularly so in the financial sector. About 80% of all web pages are loaded over an HTTPS connection, browsers are increasingly naggy when anything isn’t HTTPS and it’s never been cheaper

Continue reading HSTS From Top to Bottom or GTFO

Posted in SSL

Choosing the right HTTPS certificate for your WordPress website

In our previous post WordPress HTTPS, SSL and TLS – a guide for website administrators, we explained what HTTPS and all the other technical terms are, and how it works. In this article, we discuss HTTPS certificates, the different ways you may ac… Continue reading Choosing the right HTTPS certificate for your WordPress website

Visibility: Do You Know What’s In Your Network?

Although you may be protected by the most advanced firewall technology, your existing security mechanisms may fail to see into encrypted SSL/TLS traffic.
The post Visibility: Do You Know What’s In Your Network? appeared first on Radware Blog.
T… Continue reading Visibility: Do You Know What’s In Your Network?

WordPress HTTPS, SSL & TLS – A Guide For Website Administrators

When you visit a website, your browser (also known as a client) sends a HTTP request to a web server. Once the web server sends an HTTP response, the browser can then render the page to your screen. However, HTTP traffic has a problem; it is a plaintex… Continue reading WordPress HTTPS, SSL & TLS – A Guide For Website Administrators

Extended Validation Certificates are (Really, Really) Dead

Presently sponsored by: strongDM-see why Splunk’s CISO says “strongDM enables you to see what happens, replay & analyze incidents. You can’t get that anywhere else”

Almost one year ago now, I declared extended validation certificates dead. The entity name had just been removed from Safari on iOS, it was about to be removed from Safari on Mojave and there were indications that Chrome would remove it from the desktop in the future (they already weren’t

Continue reading Extended Validation Certificates are (Really, Really) Dead

The probability that an EV SSL certificate is associated with a bad domain is 0.013%

In 2018, phishing attacks were attempted 482.5 million times, more than doubling the number of incidents in 2017. New research conducted by the Georgia Institute of Technology Cyber Forensics Innovation (CyFI) Laboratory confirms that a website with a … Continue reading The probability that an EV SSL certificate is associated with a bad domain is 0.013%