Automating Internal Certificate Issuance With ACME-based Certificate Authority
Lessons learned from running Let's Encrypt Boulder certificate authority software in the company.
Posted
#Articles
Lessons learned from running Let's Encrypt Boulder certificate authority software in the company.
Posted
#Articles
Let's Encrypt recapitulated the last year in the operation of their ACME based certification authority, and summarized the challenges that they will work on in 2019. They intend to deploy multi-perspective validation, checking multiple distinct Autonomous Systems for domain validation, preventing potential BGP hijacks. They also plan to run own Certificate Transparency (CT) log.
Posted
#Weekly-News
A Comcast security flaws exposed more than 26 millions of customers’ personal information. Basically, an attacker could spoof IP address using 'X-forwarded-for' header on a Comcast login page and reveal the customer’s location.
Posted
#Weekly-News
Electron applications designed to run on Windows that register themselves as the default handler for a protocol, like Skype, Slack and others, are vulnerable to the remote code execution vulnerability.
Posted
#Weekly-News
New research has found a flaw in a group messaging part of a Signal protocol used by Signal, WhatsApp and Threema. It’s hardly exploitable, but the server (attacker) could be, in some theoretical scenario, able to silently join an encrypted group chat.
Posted
#Weekly-News