The four letters, “http”, are known to technical and non technical users alike as the beginning of any web address. These have been ubiquitous for many years. But things are abo…
You may have heard in the news that the Chinese Certificate Authority, WoSign, was caught backdating SHA 1 certificates to make it look like they were issued before the December…
The policy change goes into effect October 2017 A recent Google announcement stated that all publicly trusted SSL/TLS certificates issued in October 2017 or later will be expect…
I wrote about the [next version of the HTTP protocol][1] 18 months ago. Since then, HTTP/2 has gained significant traction, but not without generating some controversy along the…
The Long Life Certificate – Why It Doesn’t Exist Why is certificate expiration even necessary? Wouldn’t it be better if I could just buy a certificate with a long life before ex…
There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…
Always On SSL should be deployed to prevent the “Not secure” warning Website owners who do not secure their website with an SSL/TLS certificate will have to rethink their online…
Details surrounding the [SWEET32: Birthday attacks on 64 bit block ciphers in TLS and OpenVPN][1] can be found in the paper released by Karthikeyan Bhargavan and Gaëtan Leurent …
Google is making [security icon changes][1] in the Chrome status bar. The changes are based on a [research paper][2] prepared by members of Google and University of California, …
It is time for an update on the Baseline Requirements for Code Signing. First the bad news, the new standard was not approved by the CA/Browser Forum due to philosophical differ…
