HandonComputer (1)
The Return Of Bleichenbacher's Oracle Threat (ROBOT) attack takes advantage of an old vulnerability discovered by Daniel Bleichenbacher in 1998. We have previously seen the Bleichenbacher attack in 2016 when it was used in the DROWN attack on SSL 2.0. The use of a ROBOT attack fully breaks the conf...
AgencyLabSmile
Originally, there were just seven generic top level domains (gTLDs) and a couple hundred country code TLDs (ccTLDs). In 2012, ICANN announced the application for nearly 2000 new gTLDs. Within these applications were requests for about 500 Brand TLDs. Brand TLD The 2012 gTLD application program, al...
Public Key Pinning was great idea at first. Google used static public keys to protect their websites. In doing so, the keys were embedded in Chrome and were useful in helping users find the DigiNotar attack in 2011, and in a mistaken certification authority (CA) certificate issued by TURKTRUST in 20...
Chrome currently issues a "Not secure" browser warning for pages accepting password and/or credit card data that are not protected by HTTPS. The release of Chrome 62 due in October 2017 extends the "Not secure" warning to include any non-HTTPS page that accepts data from website visitors. In additio...
The Evolution of Identity in the Connected World You may think you know who you are. But the truth is, your identity is becoming richer and more complex. You’ve likely used an employee badge to enter a building, a driver’s license to rent a car, a loyalty card to accumulate points and a username an...