The purpose of this article The purpose of this article is to demonstrate why I believe browser based UI for website identity can make the web safer for everyone. I explain in g…
PKI Consortium blog
Posts by tag Vulnerability
Over the years misconceptions about CAs and the SSL infrastructure have arisen. Below is a list of common myths related to SSL and CAs. Myth 1: CAs are not regulated Fact: CAs a…
Short validity period certificates are becoming ever more common to reduce the scope of data compromised if a server vulnerability is uncovered, such as [HeartBleed][1]. Good se…
Last month marked the release of Firefox 66, the newest iteration of the ever popular web browser. The update adds a number of interesting new features, including improvements t…
Looking Back at 2018 2018 was an active year for SSL/TLS. We saw the SSL/TLS certificate validity period drop to 825 days and the mass deployment of Certificate Transparency (CT…
Last month saw the final adoption, after 4 years of work, of TLS version 1.3 by the Internet Engineering Task Force (IETF). This latest iteration of the protocol for secure comm…
Through 2017 and into 2018, we have seen the use of HTTPS grow substantially. Last Fall Google announced the following status: Over 68% of Chrome traffic on both Android and Win…
Looking Back at 2017 2017 saw the end of SHA 1 in public trust SSL/TLS certificates and the start of Certification Authority Authorization (CAA) allowing domain owners to author…
Looking Back at 2016 Fortunately, 2016 was not a year full of SSL/TLS vulnerabilities. Although some researchers did prove old cryptography algorithms should be put out to pastu…
This is a good time to offer a reminder that the CASC has a great tool for secure server testing, the [SSL Server Test][1]. The tool grades your server installation and reviews …

