One stolen laptop. One disgruntled employee. Oftentimes, this is all it takes for an enterprise security breach to begin. Although the cybercrimes that most frequently make headlines are the ones carried out by fearsome hackers in distant lands, the truth is that all too often security episodes sta...
When authorities try to suppress malware authors, those criminals either return to the drawing board to develop a more advanced approach or just their arsenal of technology they haven't even needed to deploy yet. This is a system that certainly favors the criminal, and security experts are finding ...
Over the last few years, we’ve witnessed publicly trusted SSL certificates issued to domain names that were not authorized. These miss-issuances are typically caused by attackers or simply a mistake by a certification authority (CA). Miss-issuance has been detected in a brute-force manner. Typicall...
OCSP Must-Staple
This post was originally published by on the CA Security Council blog. With the announcement of the Heartbleed bug and the resulting need to revoke large numbers of SSL certificates, the topic of certificate revocation has, once again, come to the fore. There have been many issues with how revocat...