There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…
We have seen recently that Google detected that publicly trusted TLS/(SSL) certificates had been created for Google domains without having been requested by Google themselves. T…
Looking Back at 2013 Protocol Attacks The year started with a couple of SSL/TLS protocol attacks: [Lucky Thirteen][1] and [RC4 attack][2]. Lucky Thirteen allows the decryption o…
After the CASC’s [previous][1] letter addressing ICANN’s proposal to delegate nearly 2000 new gTLDs for use on the public Internet, ICANN identified and initiated an extensive s…
We have previously reviewed [implementation of SHA 2][1], but with [Bruce Schneier stating the need to migrate away from SHA 1][2] and the [SHA 1 deprecation policy from Microso…
We have recently discussed the benefits of code signing in two posts: [Securing Software Distribution with Digital Signatures][1] and [Improving Code Signing][2]. These posts co…
Internet Surveillance The big news at [IETF 88 in Vancouver][1] was the technical plenary on [Hardening the Internet][2] which discussed the issue of pervasive surveillance. Per…
Certification Authorities (CAs) are trusted third parties that authenticate customers before issuing SSL certificates to secure their servers. Exactly how do CAs authenticate th…
Previously, we discussed how code signing certificates play a key role in the trust framework by proving the authenticity of software. As mentioned, code signing certificates ac…
Have you ever wondered why your web server certificate has a “chain” of other certificates associated with it? The main reason is so that browsers can tell if your certificate w…

