Through 2017 and into 2018, we have seen the use of HTTPS grow substantially. Last Fall Google announced the following status: Over 68% of Chrome traffic on both Android and Win…
PKI Consortium blog
Posts by tag HSTS
Always On SSL should be deployed to prevent the “Not secure” warning Website owners who do not secure their website with an SSL/TLS certificate will have to rethink their online…
Part 1 of this blog post discussed browser security indicators and how to avoid getting warnings about mixed content on your website. (Mixed content leaves a door open that allo…
Over the past several years there has been increased discussion about deprecating HTTP and making HTTPS the default protocol for the World Wide Web. (HTTP stands for “HyperText …
Since we last [wrote about SSL/TLS performance][1], there has been a lot of activity in the IETF HTTP Working Group, resulting in the February announcement that the next version…
TLS is quickly becoming a de facto requirement for every website due to increased concerns about spying and Google’s recent move to use HTTPS as a factor in search engine rankin…
Is your website secure? One thing to consider is securing your website with [HTTP Strict Transport Security (HSTS)][1]. Implementation of HSTS is an extension of the [Always On …
Looking Back at 2013 Protocol Attacks The year started with a couple of SSL/TLS protocol attacks: [Lucky Thirteen][1] and [RC4 attack][2]. Lucky Thirteen allows the decryption o…
Internet Surveillance The big news at [IETF 88 in Vancouver][1] was the technical plenary on [Hardening the Internet][2] which discussed the issue of pervasive surveillance. Per…
At RSA last week a few of us participated in panel discussions that focused on SSL/TLS. During the panel that I moderated on Friday, one theme we addressed was secure server con…
