Cryptography


Sort by : relevance - date - popularity
+Vote!

Debian Bug Leaves Private SSL/SSH Keys Guessable

... a critical security advisory has been released: a Debian packager modified the source code of OpenSSL back in 2006 so as to remove the seeding of OpenSSL random number generator, which in turns makes cryptographic key material generated on a Debian system guessable. The solution? Upgrade OpenSSL and re-generate all your SSH and SSL keys. This problem not only affects Debian, but also all its derivatives,...

+Vote!

SSH keys and SSL certificates at risk from new Debian OpenSSL flaw

If you're an SSH and Linux user, this is not a good week for you. Not only did Debian announce that a flaw in its OpenSSL implementation allows attackers to easily guess cryptographic keys, but now HD Moore has posted a list of SSH keys that he was able to brute-force by reverse engineering the list of blacklisted keyspace that Debian published. Oh, and there also is a large spike in the volume of...

+Vote!

check_ssl_cert 1.2.2

check_ssl_cert - Nagios plugin to check the CA and validity of an X.509 certificate on HTTPS server

+Vote!

Tools Already Circulating to Crack Debian, Ubuntu SSL Keys

... number generator used to produce a variety of digital keys, including SSH (Secure Shell) keys and SSL (Secure Socket Layer) certificates. The latter are widely used to secure traffic between users and secure sites on the Internet. According to Moore, the bug makes it relatively easy to "guess" keys. In a blog post yesterday, Moore claimed he was able to generate 1024- and 2048-bit keys in about...

+Vote!

SSL 5250 Emulation Available on BOSaNOVA Thin Clients

SSL 5250 Emulation Available on BOSaNOVA Thin Clients

+Vote!

Debian/Ubuntu users: update your SSL keys and certs

It was announced yesterday that sometime back in September 2006 a line of code was removed from the Debian distributed OpenSSL package. That one line of code was responsible for causing an uninitialized data warning in Valgrind.

+Vote!

Apple keeps things secure with biennial PGP key update

Apple yesterday updated its PGP keys, a process it does every two years to prevent the keys from being cracked. Just another step that Apple takes to keep Mac OS X secure. Read More...

+Vote!

VeriSign, Inc.: VeriSign Passes Online Security Milestone With One Million Active SSL Certificates

MOUNTAIN VIEW, CA (MARKET WIRE) VeriSign, Inc. (NASDAQ: VRSN), the trusted provider of Internet infrastructure services for the networked world, today announced that the company has deployed one million active Secure Sockets Layer (SSL) Certificates, which already provide security for more than 93 percent of the Fortune 500 and the world's 40 largest banks.

+Vote!

Review: Microsoft Intelligent Application Gateway and Celestix VPN appliance

We take a look at the functionality and effectiveness of the IAG paired with the Celestix WSA4000 SSL VPN Appliance.

+Vote!

Review: Microsoft Intelligent Application Gateway and Celestix VPN appliance

We take a look at the functionality and effectiveness of the IAG paired with the Celestix WSA4000 SSL VPN...

+Vote!

VeriSign Passes One Million Milestone

Web's three leading SSL Certificate brands extend reach to deliver secure Internet experience and build consumer trust in online transactions

+Vote!

Debian, Ubuntu SSH Under Attack

Flaw in an SSL package has led to an Internet security storm surge.

+Vote!

Debian and Ubuntu Users: Fix Your Keys

Online merchants who have used a Debian-based operating system to generate secure sockets layer (SSL) certificates for encrypting customer communications should check to make sure the private key needed to decrypt those transactions isn't already posted on the Web for all to see. Normally, even if an attacker is able to intercept https:// traffic between a commercial Web site and a customer, the bad...

+Vote!

[3/5] Cisco Catalyst Content Switching Module Memory Leak Vulnerability

A vulnerability has been reported in Cisco Catalyst Content Switching Module (CSM) and Cisco Catalyst Content Switching Module with SSL (CSM-S), which can be exploited by malicious people to cause a DoS (Denial of Service). Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software...

+Vote!

Microsoft Releases Update Package for Data Protection Manager 2007

Description of the Data Protection Manager 2007 hotfix rollup 3. Issues Resolved: - Recovery of SSL Sites does not work - Consistency Check on compressed volume results in full Initial Replication - Deleting old Recovery Points is not freeing space on Recovery Point Volume - Consistency check does not complete in reasonable time - User intent for Max Duration of Consistency Check job is not honored...