Despite Chrome’s pending “mark of shame,” 3 major news sites aren’t HTTPS

Fox News is one of three top news websites that are not encrypting content. In February, Emily Schechter, the Chrome Security Product Manager at Google, announced in a blog post that beginning with the release of Chrome version 68, “Chrome will mark all HTTP sites as ‘not secure’.” This means that Chrome users will see […]

Rash of Fortnite cheaters infected by malware that breaks HTTPS encryption

Enlarge (credit: Rainway) Tens of thousands of Fortnite players have been infected by malware that hijacks encrypted Web sessions so it can inject fraudulent ads into every website a user visits, an executive with a game-streaming service said Monday. Rainway CEO Andrew Sampson said in a blog post that company engineers first detected the mass […]

23,000 HTTPS certificates axed after CEO emails private keys

Enlarge (credit: unrequited life) A major dust-up on an Internet discussion forum is touching off troubling questions about the security of some browser-trusted HTTPS certificates when it revealed the CEO of a certificate reseller emailed a partner the sensitive private keys for 23,000 TLS certificates. The email was sent on Tuesday by the CEO of […]

HTTPS Certificate Revocation is broken, and it’s time for some new tools

Enlarge / Damn computer hackers, always trying to steal all my stuff. (credit: Getty Images / C.J. Burton) This article was originally published on Scott Helme’s blog and is reprinted here with his permission. We have a little problem on the web right now and I can only see it becoming a larger concern as […]

Google takes Symantec to the woodshed for mis-issuing 30,000 HTTPS certs

Enlarge (credit: Nyttend) In a severe rebuke of one of the biggest suppliers of HTTPS credentials, Google Chrome developers announced plans to drastically restrict transport layer security certificates sold by Symantec-owned issuers following the discovery they have issued more than 30,000 certificates. Effective immediately, Chrome plans to stop recognizing the extended validation status of all […]

Newly discovered flaw undermines HTTPS connections for almost 1,000 sites

Enlarge Encrypted connections established by at least 949 of the top 1 million websites are leaking potentially sensitive data because of a recently discovered software vulnerability in appliances that stabilize and secure Internet traffic, a security researcher said Thursday. The bug resides in a wide range of firewalls and load balancers marketed under the F5 […]