tls

  1. ChatGPT

    Quantum Computing and Cybersecurity: Microsoft’s Post-Quantum Cryptography Advancements

    The world of cybersecurity is perpetually on alert, facing an unending procession of new threats that demand fresh defensive measures. However, a new frontier has started to crystallize on the horizon—one that many researchers and technology leaders now call the next great battle in...
  2. ChatGPT

    Quantum-Resistant Cryptography in Windows 11: Preparing for the Quantum Computing Era

    The world of cybersecurity is undergoing a tectonic shift as the relentless march of quantum computing edges ever closer to practical realization. For decades, the bedrock of digital security—cryptography—has relied on mathematical problems that are infeasible for classical computers to solve...
  3. ChatGPT

    Microsoft Enhances Security: Deprecation of Weak RSA Certificates in TLS

    In the realm of online security, consistent advancements are essential to enhance the protection of digital interactions and safeguard sensitive information. An integral aspect of this security landscape involves Transport Layer Security (TLS) server authentication. Recently, Microsoft announced...
  4. News

    Use the LdapEnforceChannelBinding registry entry to make LDAP authentication over SSL/TLS more secure

    Describes the LdapEnforceChannelBinding registry setting that is used to enable the fix decribed in CVE-2017-8563 Continue reading...
  5. S

    Windows 10 Your web browser is not using a secure enough connection

    Hi, I have suddenly started getting issues with websites (eg a failure to connect to Sage Pay from a shopping site) - Chrome and Edge browsers. I believe I am up to date with Windows 10 updates and Chrome is right up to date version, just reinstalled to be sure. eg -I tried accessing PC World...
  6. Y

    Server 2008 R2 has trouble with Discord/Denuvo/Other stuff

    Hello! This is gonna be an odd post in this section, considering that my problems are unrelated to server usage altogether, but maybe someone can help me out here. I got a copy of Windows Server 2008 R2 from the Dreamspark program years ago by attending college. I decided I wanted to use this...
  7. News

    TA17-075A: HTTPS Interception Weakens TLS Security

    Original release date: March 16, 2017 Systems Affected All systems behind a hypertext transfer protocol secure (HTTPS) interception product are potentially affected. Overview Many organizations use HTTPS interception products for several purposes, including detecting malware that uses HTTPS...
  8. News

    SHA-1 Collisions Research

    Today, a group of eight researchers from across the security industry released a research report on SHA-1 that demonstrates for the first time, a “hash collision” for the full SHA-1 hash algorithm (called “SHAttered”). This is a significant step toward understanding this type of security issue...
  9. News

    Enabling IIS Manager and Web Deploy after disabling SSL3 and TLS 1.0

    Link Removed
  10. News

    RC4 is now deprecated in Microsoft Edge and Internet Explorer 11

    In September 2015, Microsoft announced the end-of-support for the RC4 cipher in Microsoft Edge and Internet Explorer 11 in 2016, as there is consensus across the industry that RC4 is no longer cryptographically secure. Today, we are releasing KB3151631 with the August 9, 2016 cumulative updates...
  11. Neemobeer

    Windows Security Hardening (SCHANNEL)

    I created this reg file to disable SSLv2, v3 and TLS 1.0 as well as disabling weak encryption cipher suites.
  12. News

    3155527 - Update to Cipher Suites for FalseStart - Version: 1.0

    Revision Note: V1.0 (May 10, 2016): Advisory published. Summary: FalseStart allows the TLS client to send application data before receiving and verifying the server Finished message. This allows an attacker to launch a man-in-the-middle (MiTM) attack to force the TLS client to encrypt the first...
  13. News

    Description of the security update for Schannel: April 12, 2016

    Continue reading...
  14. News

    3155527 - Update to Cipher Suites for FalseStart - Version: 1.0

    Revision Note: V1.0 (May 10, 2016): Advisory published. Summary: FalseStart allows the TLS client to send application data before receiving and verifying the server Finished message. This allows an attacker to launch a man-in-the-middle (MiTM) attack to force the TLS client to encrypt the first...
  15. P

    Windows Server Monitoring

    I hope I don't come across as horibly spammy on my third post here but I would like to share some info on a project that I've been working on. I know when it comes to free monitoring solutions we're all basically stuck with Nagios or some sort of Linux based product that is typically ugly and...
  16. News

    3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0

    Revision Note: V1.0 (January 12, 2016): Advisory published. Summary: Microsoft is announcing the availability of an update to improve interoperability between Schannel-based TLS clients and 3rd-party TLS servers that enable RFC5077-based resumption and that send the NewSessionTicket message in...
  17. News

    3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0

    Revision Note: V1.0 (December 8, 2015): Advisory published. Summary: Microsoft is aware of an SSL/TLS digital certificate for *.xboxlive.com for which the private keys were inadvertently disclosed. The certificate could be used in attempts to perform man-in-the-middle attacks. It cannot be used...
  18. News

    3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0

    Revision Note: V1.0 (December 8, 2015): Advisory published. Summary: Microsoft is aware of an SSL/TLS digital certificate for *.xboxlive.com for which the private keys were inadvertently disclosed. The certificate could be used in attempts to perform man-in-the-middle attacks. It cannot be used...
  19. News

    Ending support for the RC4 cipher in Microsoft Edge and Internet Explorer 11

    Today, Microsoft is announcing the end-of-support of the RC4 cipher in Microsoft Edge and Internet Explorer 11. Starting in early 2016, the RC4 cipher will be disabled by-default and will not be used during TLS fallback negotiations. There is consensus across the industry that RC4 is no longer...
  20. News

    HTTP Strict Transport Security comes to Internet Explorer 11 on Windows 8.1 and Windows 7

    In February, we Link Removed the first preview of HTTP Strict Transport Security in Internet Explorer 11 in the Windows 10 Insider Preview. The HTTP Strict Transport Security (HSTS) policy protects against variants of man-in-the-middle attacks that can strip TLS out of communications with a...
Back
Top