Through 2017 and into 2018, we have seen the use of HTTPS grow substantially. Last Fall Google announced the following status: Over 68% of Chrome traffic on both Android and Win…
Looking Back at 2017 2017 saw the end of SHA 1 in public trust SSL/TLS certificates and the start of Certification Authority Authorization (CAA) allowing domain owners to author…
On October 17th, a group of Czech researchers announced they had found a way to factor the moduli of many RSA public keys generated by hardware produced by Infineon Technologies…
Twenty years ago, paying your phone or electric bill involved receiving it in the mail, writing a check and mailing it back to the company. Today, that has largely been replaced…
The media is full of stories about how phishing sites are moving rapidly to encryption using anonymous, free DV certificates they use to imitate login pages for popular sites, s…
[Google just announced][1] they will not be enforcing certificate transparency (CT) logging for all new TLS certificates until April 2018. In a previous [blog post][2], we advis…
Things are certainly heating up at the CA/Browser with exciting proposals surrounding inclusion of the Wi Fi Alliance (WFA) as a subjectAltName otherName, new validation methods…
Looking Back at 2016 Fortunately, 2016 was not a year full of SSL/TLS vulnerabilities. Although some researchers did prove old cryptography algorithms should be put out to pastu…
This is a good time to offer a reminder that the CASC has a great tool for secure server testing, the [SSL Server Test][1]. The tool grades your server installation and reviews …
The CASC’s Minimum Requirements for Code Signing Certificates enables a common vetting process for all CAs San Francisco –December 8, 2016 – the Certificate Authority Security C…


