Get a Pentest and security assessment of your IT network.

News

When Certificate Authority Business Models and Vendor Certificate Policies Clash

Trustwaves certificate was used to sign certificates for websites not owned by its corporate customer. Trustwave sold certificate knowing that it would be used to perform active man-in-the-middle interception of HTTPS traffic. Mozilla Foundation is taking these statements and the issue openly and seriously seriously. Researcher Christopher Soghoian quickly weighed in on the topic and suggested the only power that the browser vendors can wield is to revoke or not revoke the Trustwave certificates. But other researchers argue that the voluntary disclosure and policy change should weigh into the decision to the decision.”]

Source: https://securelist.com/when-certificate-authority-business-models-and-vendor-certificate-policies-clash/32245/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Shamoon Malware, cyber espionage tool, cyber weapon or