PolarSSL Library Vulnerable to Remote Code Execution

PolarSSL Library Vulnerable to Remote Code Execution

Future release includes patch, workaround already available

POODLE Attack Also Affects Some TLS Implementations

POODLE Attack Also Affects Some TLS Implementations

Admins can check if the flaw impacts their servers

Chrome 39 Disables SSLv3 Fallback, Awards $41,500 / €33,000 in Bounties

Chrome 39 Disables SSLv3 Fallback, Awards $41,500 / €33,000 in Bounties

Double-free glitch in Flash and use-after-free vulnerability in Blink lead receive the highest rewards

Free Google Tool Shows Network Security Issues

Free Google Tool Shows Network Security Issues

It uses deep packet inspection to detect vulnerable traffic

Chrome 39 Will Have SSL 3.0 Disabled by Default, Chrome 40 Removes It Completely

Chrome 39 Will Have SSL 3.0 Disabled by Default, Chrome 40 Removes It Completely

TLS 1.0 to be the minimum version for encrypted connections

New OpenSSL Fixes Four Security Glitches, POODLE Not the Biggest Concern

New OpenSSL Fixes Four Security Glitches, POODLE Not the Biggest Concern

Two denial-of-service risks have been mitigated

Popular Android Apps Vulnerable to Man-in-the-Middle Attacks

Popular Android Apps Vulnerable to Man-in-the-Middle Attacks

Issues related to trust managers, certificate verification and ignored SSL errors

SSL Blacklist Reveals Certificates Used by Cybercriminals

SSL Blacklist Reveals Certificates Used by Cybercriminals

SHA1 fingerprints for bad certificates amassed in a single database

National Informatics Centre in India Compromised

National Informatics Centre in India Compromised

Investigation does not reveal full extent of the breach

Fake Google Digital Certificates Issued by National Informatics Centre in India

Fake Google Digital Certificates Issued by National Informatics Centre in India

Authorities are investigating the cause that led to the incident

BoringSSL, an OpenSSL Fork for Google Products

BoringSSL, an OpenSSL Fork for Google Products

Change prompted by large set of patches for Chrome and Android

  • Web Blog
  • By Lucian Parfeni
  • November 14th, 2013
Google Lists All Known TLS Cipher Vulnerabilities to Help You Pick the Best

Google Lists All Known TLS Cipher Vulnerabilities to Help You Pick the Best

With the NSA actively trying to break internet encription, every little bit of info helps

Experts Explain the Risks Posed by the Lucky 13 Attack

Experts Explain the Risks Posed by the Lucky 13 Attack

Venafi and GlobalSign representatives share some insight on the matter

Lucky 13: Researchers Find Vulnerabilities in TLS and DTLS Protocols

Lucky 13: Researchers Find Vulnerabilities in TLS and DTLS Protocols

Nadhem AlFardan and Kenny Paterson have published a detailed paper on the attack method

Researchers Demonstrate CRIME Attack Against TLS Protocol [Video]

Researchers Demonstrate CRIME Attack Against TLS Protocol [Video]

The experts who presented the BEAST attack return with a new discovery

Browser Vendors Prepare for SSL Attacks

Browser Vendors Prepare for SSL Attacks

The implementation of the newer protocols turns out to be difficult

  • Security
  • By Eduard Kovacs
  • September 20th, 2011
SSL Encryption Turns Out to Be Highly Vulnerable

SSL Encryption Turns Out to Be Highly Vulnerable

Account credentials can be decrypted in 10 minutes

 
Want more? Browse: