Symantec Gets Good Vibes From Virtualized Browser

Wednesday, January 14th, 2009

Security vendor Symantec is using new virtual machine technology to protect Web surfers from online attack. Called Vibes, the software bounces between three different virtual machine sessions, depending on what the user is doing on the Web. When Vibes spots the SSL (Secure Sockets Layer) protocol used for secure Web transactions, ...

Foxmarks Uses Vulnerable MD5 Certificates

Tuesday, January 13th, 2009

I decided to try the ever popular Firefox plugin called Foxmarks that lets you sync and back up your bookmarks and passwords across multiple computers.  I didn't feel comfortable using the password sync quite yet because it will take me a while to trust a 3rd party with that kind ...

Google adds HTTPS-only browsing to Chrome

Friday, January 9th, 2009

Google has quietly released a pre-beta version of Google Chrome 2.0 with a new HTTPS-only browsing mode. The new feature lets users add “force-https to your Google Chrome shortcut” to only load Web sites with valid security certificates.   “Sites with SSL certificate errors will not load,” the company explained. The newest Chrome ...

MetaSploit Now Scans For MD5-signed SSL Certificates

Sunday, January 4th, 2009

Efrain Torres just committed an improvement to the Metasploit source tree that allows the framework to be used as a SSL certificate scanner. This provides a simple way to identify SSL certificates in use that were signed with the MD5 algorithm and need to re-issued. To use the new module, ...

SSL Blacklist – Firefox Plugin Detects Bad Certificates

Friday, January 2nd, 2009

This Firefox plugin was first created back during the Debian/OpenSSL scare about 6 months ago where the key pairs that were generated from an affected machine were easily guessable. Marton Anka created this plugin to help users find these bad certificates: On 12/31/2008, Marton updated this plugin to detect the ...