why not · @tasket
25 followers · 237 posts · Server infosec.exchange

Time to Remove Some Untrustworthy Certificate Authorities From Browser and OS

soylentnews.org/article.pl?sid

#certificates #certificateauthorities #tls #infosec

Last updated 3 years ago

aegilops :github::microsoft: · @aegilops
46 followers · 172 posts · Server fosstodon.org

A caveat to what I said - there *are* rogue Certificate Authorities out there:

washingtonpost.com/technology/

That's not to say rogue CAs are a threat to every system or user equally. As the article points out, they will probably be used sparingly to get at high value targets.

Anyway, take care to audit which CAs you trust in your browsers and other applications.

If you have a very specialised server application it doesn't need to trust 100-odd CAs!

#certificateauthorities #trust #tls

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online