There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…
PKI Consortium blog
Posts by tag OpenSSL
A team of researchers has announced a vulnerability with [SSL 2.0][1] called D ecrypting R SA with O bsolete and W eakened e N cryption; otherwise known as [DROWN][2]. SSL 2.0 i…
Looking Back at 2015 A number of new tactics proved 2015 was no exception to an active year defending against ever increasing security issues. Vendors found new and creative way…
OpenSSL has announced a high severity vulnerability, CVE 2015 1793 which will require an upgrade to some OpenSSL installations. The vulnerability was discovered by Google person…
Recently, we read about lots of SSL/TLS related vulnerabilities found in mobile apps, which should come as no surprise. We were warned about this back in 2012 (see [these][1] [s…
Looking Back at 2014 End of 1024 Bit Security In 2014, the SSL industry moved to issuing a minimum security of 2048 bit RSA certificates. Keys smaller than 2048 are no longer al…
In October 2014, [Google announced POODLE][1], an SSL 3.0 protocol attack. To bring you up to speed, the [SSL/TLS protocol][2] is the most important and popular security protoco…
Recent revelations from Edward Snowden about pervasive government surveillance have led to many questions about the safety of communications using the SSL/TLS protocol. Such com…
On April 7, 2014, a vulnerability in the OpenSSL cryptographic library was announced to the Internet community. Aptly labeled as the Heartbleed bug, this vulnerability affects O…
There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…
