TLS

Apple Harshes Cumulative Mellow: Enforces Unilateral TLS Certificate 13 Month Time Limit In Safari Web Browser

Is it possible this is just an effort at redirection? Maybe (OK, it's a thin argument I'll admit, but stick…

10 months ago

Forgot to Renew Your TLS Certificate, Microsoft?

Microsoft Teams went dark for seven hours yesterday. It turns out the Teams team forgot to renew a TLS certificate.

11 months ago

Update Your Browser to Support TLS 1.2 and WPA2-Enterprise

Organizations should be aware of an important update to TLS. TLS 1.2 is the most recent update that builds on…

11 months ago

Sniffing Decrypted TLS Traffic with Security Onion

Wouldn't it be awesome to have a NIDS like Snort, Suricata or Zeek inspect HTTP requests leaving your network inside…

11 months ago

Sharing a PCAP with Decrypted HTTPS

Modern malware and botnet C2 protocols use TLS encryption in order to blend in with 'normal' web traffic, sometimes even…

11 months ago

Installing a Fake Internet with INetSim and PolarProxy

This is a tutorial on how to set up an environment for dynamic malware analysis, which can be used to…

1 year ago

The NSA HSTS Security Feature Mystery

I recently stumbled across an NSA Cyber Advisory titled Managing Risk from Transport Layer Security Inspection (U/OO/212028-19) after first learning…

1 year ago

The NSA Warns of TLS Inspection

The NSA has released a security advisory warning of the dangers of TLS inspection: Transport Layer Security Inspection (TLSI), also…

1 year ago

New Reductor Nation-State Malware Compromises TLS

Kaspersky has a detailed blog post about a new piece of sophisticated malware that it's calling Reductor. The malware is…

1 year ago

Choosing the right HTTPS certificate for your WordPress website

In our previous post WordPress HTTPS, SSL and TLS – a guide for website administrators, we explained what HTTPS and…

1 year ago