Security News

Dozens of .gov HTTPS certs expire, websites offline, FBI on ice, IT security slows... Yup, it's day 20 of Trump's govt shutdown
2019-01-11 02:02

Hackers may be rubbing their hands with glee The IT impact of the ongoing partial US federal government shutdown has begun to show up in the form of degraded computer security. According to...

Great, you've moved your website or app to HTTPS. How do you test it? Here's a tool to make local TLS certs painless
2019-01-09 08:04

Breathe easier knowing you've tested your software properly A Google cyrptoboffin is close to releasing a tool that will hopefully make all of us more secure online.…

Mozilla Testing DNS-over-HTTPS in Firefox
2018-11-30 21:28

Mozilla is moving forward with yet another project designed to provide users with increased security: it is now testing DNS-over-HTTPS (DoH) in Firefox stable. read more

Oh my chord! Sennheiser hits bum note with major HTTPS certificate cock-up
2018-11-29 01:11

Audiophiles could get played like a fiddle, have their web traffic snooped by son-of-a-pitch scammers Headphone maker Sennheiser is facing the music after being caught compromising the security of...

HTTP/3: Come for the speed, stay for the security
2018-11-14 12:52

Key personnel at the Internet Engineering Task Force (IETF) have suggested basing the next version of a core web protocol on Google technology.

'The inmates have taken over the asylum': DNS godfather blasts DNS over HTTPS adoption
2018-10-23 09:59

Can those who need lookup privacy afford architectural purism? The Internet Engineering Task Force (IETF) has formally adopted DNS-over-HTTPS as a standard, and reignited a debate over whether...

You like HTTPS. We like HTTPS. Except when a quirk of TLS can smash someone's web privacy
2018-10-19 07:04

Never-closed browsers and persistent session tickets make tracking a doddle Analysis Transport Layer Security underpins much of the modern internet. It is the foundation of secure connections to...

HTTPS crypto-shame: TV Licensing website pulled offline
2018-09-06 12:16

Telly taxpayers' info sent in the clear The UK's TV Licensing agency has taken its website offline "as a precaution" after being blasted for running transactional pages that were not sent over HTTPS.…

How to nab a HTTPS cert for a stranger's website: Step one, shatter those DNS queries...
2018-09-06 10:01

Domain validation systems fooled by boffins Updated Researchers in Germany have discovered how to obtain HTTPS security certificates for web domains they don't own – even if the certs are...

Take a pinch of autofill, mix in HTTP, and bake on a Wi-Fi admin page: Quirky way to swipe a victim's router password
2018-09-06 05:02

If they fall for this social-engineering trick, of course Vid Beware using your web browser's autofill feature to log into your broadband router via Wi-Fi. If the login attempt is sent over...