On April 7, 2014, a vulnerability in the OpenSSL cryptographic library was announced to the Internet community. Aptly labeled as the Heartbleed bug, this vulnerability affects O…
PKI Consortium blog
Posts by tag Vulnerability
Last year, Edward Snowden, an American computer specialist working as a contractor for the National Security Agency (“NSA”), shocked web users around the world by publicizing do…
CA Security Council (CASC) members Trend Micro, Go Daddy, and Symantec participated in a discussion panel at the 2014 RSA Conference in San Francisco on February 24 entitled “Ne…
After the news broke that [40 million credit card numbers were stolen from Target][1] in a data breach of epic proportions, many of their customers went to work checking their a…
We have seen recently that Google detected that publicly trusted TLS/(SSL) certificates had been created for Google domains without having been requested by Google themselves. T…
After the CASC’s [previous][1] letter addressing ICANN’s proposal to delegate nearly 2000 new gTLDs for use on the public Internet, ICANN identified and initiated an extensive s…
Internet Surveillance The big news at [IETF 88 in Vancouver][1] was the technical plenary on [Hardening the Internet][2] which discussed the issue of pervasive surveillance. Per…
If you are reading this post you are probably already familiar with the use of digital certificates and SSL even if you may not be familiar with the history. Before exploring th…
In a previous post titled [Getting the Most Out of SSL Part 2][1] , we touched on the recommendation that Web servers be configured to prefer Transport Layer Security (TLS) vers…
The September 5th joint article by the New York Times and Guardian newspapers on NSA’s and GCHQ’s efforts to circumvent encryption implementation have left many people speculati…

