Security News > 2019 > March > Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
2019-03-13 18:12
64 bits of cert ID on the wall, 64 bits of ID. Take the top bit down, don't pass it around, 63 bits of cert ID on the wall... A bunfight over a controversial UAE mobile security company led to the discovery that millions of TLS security certificates have been improperly issued – thanks to a dodgy default configuration in popular certificate authority (CA) certificate-wrangling software.…
News URL
http://go.theregister.com/feed/www.theregister.co.uk/2019/03/13/tls_cert_revoke_ejbca_config/
Related news
- Open source maintainers: Key to software health and security (source)
- T-Mobile US fined $31.5M for network security breaches between 2021 and 2023 (source)
- WeChat devs introduced security flaws when they modded TLS, say researchers (source)
- Osmedeus: Open-source workflow engine for offensive security (source)
- Am I Isolated: Open-source container security benchmark (source)
- ScubaGear: Open-source tool to assess Microsoft 365 configurations for security gaps (source)
- Debunking myths about open-source security (source)
- AxoSyslog: Open-source scalable security data processor (source)