Security News

Huawei enterprise comms kit has a TLS crypto bug
2018-07-04 06:01

You don't want insecure kit from a vendor the Pentagon hates, do you? Huawei has rolled patches to various enterprise and broadcast products to fix a cryptography bug.…

New Phishing Scam Reels in Netflix Users to TLS-Certified Sites
2018-06-20 19:43

Researchers are warning of a new Netflix phishing scam that leads to sites with valid TLS certificates.

PayPal reminds users: TLS 1.2 and HTTP/1.1 are longer optional
2018-06-20 03:52

Insecure connections will break after June 30th. And it's acquired Hyperwallet, too PayPal has reminded merchants that they must support TLS 1.2 and HTTP/1.1 by June 30.…

It's time for TLS 1.0 and 1.1 to die (die, die)
2018-06-19 01:18

IETF floats formal deprecation suggestion, even for failback As TLS 1.3 inches towards publication into the Internet Engineering Task Force's RFC series, it's a surprise to realise that there are...

Google Turns TLS on By Default on Android P
2018-04-13 16:52

Applications targeting the next version of Android (Android P) are required to use encrypted connections by default, Google said on Thursday. read more

Hurrah! TLS 1.3 is here. Now to implement it and put it into software
2018-04-01 00:00

Which won't be terrifyingly hard: it's pretty good at making old kit like the way it moves The ink has dried, so to speak, on TLS 1.3, so it's time for work developing software to implement the...

IETF Approves TLS 1.3
2018-03-26 05:39

The Internet Engineering Task Force (IETF) last week announced the approval of version 1.3 of the Transport Layer Security (TLS) traffic encryption protocol. The Internet standards organization...

Darknet Vendors Sell Counterfeit TLS Certificates
2018-02-26 11:47

Pro Tip: Change TLS Certificates Regularly For Better Data SecurityCertificate Authorities continue to be tricked into issuing bogus TLS certificates. A study by Recorded Future found that there...

TLS-Abusing Covert Data Channel Bypasses Network Defenses
2018-02-06 19:37

Researchers from Fidelis Cybersecurity have discovered a new method of abusing the X.509 public key certificates standard for covert channel data exchange following initial system compromise.  read more

Covert Data Channel in TLS Dodges Network Perimeter Protection
2018-02-05 19:26

Researchers have found a new covert data exchange technique that abuses the TLS protocol that can circumvent traditional network perimeter protections.