The group that manages the Payment Card Industry Data Security Standard quietly announced in February that an imminent update was coming to its payment card and application requ…
PKI Consortium blog
Posts by tag Vulnerability
Since we last [wrote about SSL/TLS performance][1], there has been a lot of activity in the IETF HTTP Working Group, resulting in the February announcement that the next version…
FREAK is a new man in the middle (MITM) vulnerability discovered by a [group of cryptographers at INRIA, Microsoft Research and IMDEA][1]. FREAK stands for “Factoring RSA EXPORT…
Lenovo is [selling computers][1] that contain the Superfish application which “supplements” the user’s SSL sessions to enable their adware application to deliver content transpa…
In accordance with the [CA/Browser Forum Baseline Requirements][1], effective April 1, 2015, Certificate Authorities (CAs) will no longer be able to issue SSL Certificates with …
Looking Back at 2014 End of 1024 Bit Security In 2014, the SSL industry moved to issuing a minimum security of 2048 bit RSA certificates. Keys smaller than 2048 are no longer al…
The [POODLE attack on SSL 3.0][1] has now been extended to some implementations of TLS. POODLE for TLS can be tracked through [CVE 2014 8730][2]. POODLE is not a flaw with the c…
The holidays are approaching as quickly as a sleigh pulled by magic reindeer, and every year it seems like the shopping season starts earlier and earlier. In many places, Christ…
In October 2014, [Google announced POODLE][1], an SSL 3.0 protocol attack. To bring you up to speed, the [SSL/TLS protocol][2] is the most important and popular security protoco…
Code signing certificates are used to sign software objects to authenticate that they originated from a verified source, allowing developers to avoid warnings commonly displayed…
