Extended Validation Certificates are Dead

Presently sponsored by: Build scalable, reliable and secure cloud native applications with Tech Fabric

That’s it – I’m calling it – extended validation certificates are dead. Sure, you can still buy them (and there are companies out there that would just love to sell them to you!), but their usefulness has now descended from “barely there” to “as good as non-existent&…

Continue reading Extended Validation Certificates are Dead

Adopt TLS 1.3 – Kill Two Birds with One Stone

Transport Layer Security (TLS) version 1.3 provides significant business benefits by making applications more secure, improving performance and reducing latency for the client. Changes in how handshake between client and server is designed has decreas… Continue reading Adopt TLS 1.3 – Kill Two Birds with One Stone

Final Nail in the Coffin of HTTP: Chrome 68 and SSL/TLS Implementation

Google released Chrome version 68 in late July 2018, marking the start of a new era for secure web browsing. From version 68 onwards, all websites using HTTP will be marked as Not Secure on Chrome browsers. Starting with Chrome 69, we will no longer se… Continue reading Final Nail in the Coffin of HTTP: Chrome 68 and SSL/TLS Implementation

Why No HTTPS? Questions Answered, New Data, Path Forward

Presently sponsored by: Build scalable, reliable and secure cloud native applications with Tech Fabric

So that little project Scott Helme and I took on – WhyNoHTTPS.com – seems to have garnered quite a bit of attention. We had about 81k visitors drop by on the first day and for the most part, the feedback has been overwhelming positive. Most people have said it’s…

Continue reading Why No HTTPS? Questions Answered, New Data, Path Forward

Why No HTTPS? Here’s the World’s Largest Websites Not Redirecting Insecure Requests to HTTPS

Presently sponsored by: Matchlight by Terbium Labs: Know when your exact data appears on the dark web. Schedule a meeting during Black Hat to learn more!

As of today, Google begins shipping Chrome 68 which flags all sites served over the HTTP scheme as being “not secure”. This is because the connection is, well, not secure so it seems like a fairly reasonable thing to say! We’ve known this has been coming for a…

Continue reading Why No HTTPS? Here’s the World’s Largest Websites Not Redirecting Insecure Requests to HTTPS

Here’s Why Your Static Website Needs HTTPS

Presently sponsored by: Netsparker – a scalable and dead accurate web application security solution. Scan thousands of web applications within just hours.

It was Jan last year that I suggested HTTPS adoption had passed the “tipping point”, that is it had passed the moment of critical mass and as I said at the time, “will very shortly become the norm”. Since that time, the percentage of web pages

Continue reading Here’s Why Your Static Website Needs HTTPS

HTTPS Is Easy!

Presently sponsored by: More IoT devices mean more security challenges. DigiCert EVP of Emerging Markets discusses why manufacturers shouldn’t take this lightly.

HTTPS is easy! In fact, it’s so easy I decided to create 4 short videos around 5 minutes each to show people how to enable HTTPS on their site and get all traffic redirecting securely, optimise their HTTPS configuration to get it rating higher than most banks, fix any insecure…

Continue reading HTTPS Is Easy!

Posted in SSL

The Executive Guide to Demystify Cybersecurity

WHAT DO BANKS AND CYBERSECURITY HAVE IN COMMON? EVERYTHING The world we live in can be a dangerous place, both physically and digitally. Our growing reliance on the Internet, technology and digitalization only makes our dependence on technology more p… Continue reading The Executive Guide to Demystify Cybersecurity