Security News

DHS Orders Federal Agencies to Use DMARC, HTTPS
2017-10-17 08:13

The U.S. Department of Homeland Security (DHS) has issued a binding operational directive requiring all federal agencies to start using web and email security technologies such as HTTPS, DMARC and...

Google to enforce HTTPS on TLDs it controls
2017-10-04 19:21

In its sustained quest to bring encryption to all existing Web sites, Google has announced that it will start enforcing HTTPS for the 45 Top-Level Domains it operates. How will it do that? You may...

Optionsbleed bug makes Apache HTTP Server leak data from memory
2017-09-20 20:16

On Monday, security researcher Hanno Böck detailed a memory-leaking vulnerability in Apache HTTP Server that’s similar to the infamous OpenSSL Heartbleed bug uncovered in April 2014. Unlike...

What’s Triggers HTTPS Chrome Browser Warnings?
2017-09-20 18:20

Researchers combed through 2,000 Chrome error reports to better classify HTTPS error warnings.

Google Reminding Admins HTTP Pages Will Be Marked ‘Not Secure’ in October (Threatpost)
2017-08-29 19:12

Google began sending out notices to site owners this month who haven't yet migrated from HTTP to HTTPS warning them that in October their sites will be marked "NOT SECURE."

HTTPS Certificate Revocation is broken, and it’s time for some new tools (ArsTechnica)
2017-07-03 12:00

Certificate Transparency and OCSP Must-Staple can't get here fast enough.

Making HTTPS phishing sites easier to spot (Help Net Security)
2017-06-28 18:31

For years, we taught users that a website’s URL that includes https at its very beginning is a relatively good indicator of whether they can safely input sensitive information into it. Most users...

Google Blacklists Sites Using Logins Over HTTP: Report (Security Week)
2017-05-30 13:30

In what appears to be yet another effort to encourage site owners to adopt HTTPS, Google is marking newly registered sites that serve login pages or password input fields over HTTP as unsafe,...

Rash Of Phishing Attacks Use HTTPS To Con Victims (Threatpost)
2017-05-26 12:00

Phishing sites are deploying freely available TLS certificates in order to dupe victims into thinking they're visiting a safe site.