Most SSL Sites Poorly Configured

Saturday, July 31st, 2010

The good news about SSL-based websites: Most are running strong encryption. The bad news: More than 60 percent aren't properly configured.Researcher Ivan Ristic, who is director of engineering, Web application firewall, and SSL at Qualys, revealed findings here yesterday from a study he conducted of some 120 million registered domain ...

WPA2 security hole discovered

Monday, July 26th, 2010

Security experts at AirTight Networks have discovered a hole in the WPA2 Wi-Fi security protocol. The security hole was named as Hole 196 after the number of the relevant page in the IEEE 802.11 (2007) standard document:. Right at the bottom of this page, the IEEE introduces the keys used ...

Jungle Disk Not Backing Up EFS Encrypted Files

Friday, November 20th, 2009

I've been using SyncToy to back up data to an external USB drive and then using Jungle Disk to back up the data to Amazon S3.  With the newest version of SyncToy (2.1) they fixed a bug for EFS and now files retain their encryption when copied to an NTFS ...

Researcher busts into Twitter via SSL reneg hole

Saturday, November 14th, 2009

A Swiss grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the secure sockets layer protocol.The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. ...

Scramble on to fix flaw in SSL security protocol

Thursday, November 5th, 2009

Software makers around the world are scrambling to fix a serious bug in the technology used to transfer information securely on the Internet.The flaw lies in the SSL protocol, best known as the technology used for secure browsing on Web sites beginning with HTTPS, and lets attackers intercept secure SSL ...