It might be hard to believe, but the SSL/TLS Ecosystem is nearly 20 years old. It’s time to take stock and see how we’re doing with regards to TLS certificates. In this article,…
In previous blog [posts][1] we have discussed the differences among the various types of SSL/TLS certificates available. In this blog post we introduce you to a new [infographic…
A team of researchers has announced a vulnerability with [SSL 2.0][1] called D ecrypting R SA with O bsolete and W eakened e N cryption; otherwise known as [DROWN][2]. SSL 2.0 i…
It’s tax filing season again, and you need to be aware of scams that tried to steal your sensitive information or even your tax refund. During 2015 the IRS blocked over 4.3 mill…
Part 1 of this blog post discussed browser security indicators and how to avoid getting warnings about mixed content on your website. (Mixed content leaves a door open that allo…
Over the past several years there has been increased discussion about deprecating HTTP and making HTTPS the default protocol for the World Wide Web. (HTTP stands for “HyperText …
On January 1, 2016, the public trust certification authorities (CAs) will stop issuing SHA 1 signed SSL/TLS certificates. What will happen? Will all websites using SHA 1 fail? N…
Looking Back at 2015 A number of new tactics proved 2015 was no exception to an active year defending against ever increasing security issues. Vendors found new and creative way…
You may have heard that the CA/Browser Forum is getting ready to approve Baseline Requirements for Code Signing certificates. But why is this important? Let’s back up and get so…
While some face to face meetings can be rather mundane and boring, that can’t be said about October’s CA/B Forum meeting in Istanbul, Turkey. Guest speaker Andrea Servida from t…
