* Posts by thijs

5 publicly visible posts • joined 21 Oct 2015

Apple and some Linux distros are open to Bluetooth attack

thijs

How often to you think those adapters will receive security fixes then?

FREE wildcard HTTPS certs from Let's Encrypt for every Reg reader*

thijs

They already do and will reject a request if the domain has a CAA record that does not list LetsEncrypt.

SSL's DROWN not as bad as Heartbleed, still a security ship wreck

thijs

Re: Is TLS vulnerable or not?

If your server supports SSLv2, also connections over TLSv1.2 are at risk. An evesdropper can collect encrypted streams sent over TLSv1.2. He can then use the DROWN attack with crafted packets to get a session key. That session key can be used to decrypt one of the encrypted TLSv1.2 streams.

Cobweb 'fesses up to failure to renew SSL certificate

thijs

Re: Bypass expired SSL

Expired certificates are not secure for two reasons:

- Certificates that reach their expiry date are routinely purged from certificate revocation lists, therefore you cannot know whether it was revoked;

- Users are trained to click away certificate warnings if people keep claiming that this ok to do.

Let's Encrypt announces browser integration

thijs

Re: Still no DANE?

https://www.imperialviolet.org/2015/01/17/notdane.html