Security News

Chrome browser has a New Year’s resolution: HTTPS by default
2021-01-05 14:56

HTTPS, as you probably know, stands for secure HTTP, and it's a cryptographic process - a cybersecurity dance, if you like - that your browser performs with a web server when it connects, improving privacy and security by agreeing to encrypt the data that goes back and forth. Why is HTTP still the default choice of your browser if you type an URL into the address bar and don't explicitly put https:// at the start?

Oblivious DNS-over-HTTPS
2020-12-08 21:02

This new protocol, called Oblivious DNS-over-HTTPS, hides the websites you visit from your ISP. Here's how it works: ODoH wraps a layer of encryption around the DNS query and passes it through a proxy server, which acts as a go-between the internet user and the website they want to visit. Because the DNS query is encrypted, the proxy can't see what's inside, but acts as a shield to prevent the DNS resolver from seeing who sent the query to begin with.

Mozilla Boosts Security in Firefox With HTTPS-Only Mode
2020-11-19 04:27

"In light of the very high availability of HTTPS, we believe that it is time to let our users choose to always use HTTPS. That's why we have created HTTPS-Only Mode, which ensures that Firefox doesn't make any insecure connections without your permission," Mozilla says. Once HTTPS-Only Mode has been enabled, Firefox will attempt to always establish a fully secure connection to the visited website, and even if the user clicks on an HTTP link or manually enters it, the browser will still use HTTPS instead. The new feature can be enabled from the "Preferences" menu, in the "Privacy & Security" section.

Firefox 83 boosts security with HTTPS-Only mode, zero-day fix
2020-11-17 10:37

Mozilla Firefox 83 was released today with a new feature called 'HTTPS-Only Mode' that secures your browsing sessions by rewriting URLs to secure HTTPS versions. Windows, Mac, and Linux desktop users can upgrade to Firefox 83 by going to Options -> Help -> About Firefox.

Apple's privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps
2020-11-17 07:51

Now Apple has stressed that this app security check does not send anyone's Apple IDs nor device identifiers over the 'net, though it did log people's public IP addresses. "To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs," Apple said.

Researcher Discovers New HTTP Request Smuggling Attack Variants
2020-08-06 13:14

A researcher has detailed several new variants of an attack named HTTP request smuggling, and he has proposed some new defenses against such attacks. HTTP request smuggling, also known as HTTP desyncing, has been known since 2005, but Amit Klein, VP of security research at SafeBreach, believes the method has not been fully analyzed, which is why he has decided to conduct a research project focusing on this attack technique.

Researcher Demonstrates 4 New Variants of HTTP Request Smuggling Attack
2020-08-05 11:57

A new research has identified four new variants of HTTP request smuggling attacks that work against various commercial off-the-shelf web servers and HTTP proxy servers. Amit Klein, VP of Security Research at SafeBreach who presented the findings today at the Black Hat security conference, said that the attacks highlight how web servers and HTTP proxy servers are still susceptible to HTTP request smuggling even after 15 years since they were first documented.

New Attack Leverages HTTP/2 for Effective Remote Timing Side-Channel Leaks
2020-07-31 03:10

Since measuring the time taken to execute cryptographic algorithms is crucial to carrying out a timing attack and consequently leak information, the jitter on the network path from the attacker to the server can make it impractical to successfully exploit timing side-channels that rely on a small difference in execution time. The new method, called Timeless Timing Attacks by researchers from DistriNet Research Group and New York University Abu Dhabi, instead leverages multiplexing of network protocols and concurrent execution by applications, thus making the attacks immune to network conditions.

Digicert will shovel some 50,000 EV HTTPS certificates into the furnace this Saturday after audit bungle
2020-07-10 00:29

A notice emitted by the certificate biz explained that a number of its intermediate certificate authorities had issued EV certs to customers despite not being included in DigiCert's WebTrust audits - which goes against the rules for EV certs. "Although there is no security threat, the EV Guidelines require that we revoke EV certificates signed by the affected ICAs by July 11, 2020 at 12pm MDT.".

Remember when we warned in February Apple will crack down on long-life HTTPS certs? It's happening: Chrome, Firefox ready to join in, too
2020-06-30 03:57

From September 1, Apple software, from Safari to macOS to iOS, will reject new HTTPS and other SSL/TLS certificates that are valid for more than 398 days, plus or minus some caveats. "Connections to TLS servers violating these new requirements will fail," Apple warned in its official note.