Showing posts with label SSL. Show all posts
Showing posts with label SSL. Show all posts

Thursday, 2 February 2012

VeriSign - TOP SSL Provider was Hacked Several Times in 2010

Verisign, One of the leading security providers for half of the website in world has now some seriouse security breach issues from hackers.

Though there is no official statement on the hack. Verisign has been hacked several times made off with data.

Reuters reported the news today and information was made public. Verisign offers several top level domains including .com, .net, and .gov. actual breach was happen in 2010 though it was not revealead yet by the gaint security firm.

According to Computer World, “Prior to August 2010, VeriSign was the world’s largest SSL (secure socket layer) certificate issuing authority. In May of that year, Symantec announced it would acquire VeriSign’s authentication business, including SSL certificate generation, for $1.2 billion. The acquisition was finalized Aug. 9, 2010.”

In reply to the news, Verisign says that the company did “not believe these attacks breached servers that support our Domain Name System Network.” However, since the details of the breach have not been disclosed, this is cold comfort.

Thursday, 8 December 2011

SSL Certificate Expiration Reminders by Google

In Google Webmaster Central blog recently an interesting post about "SEO Advice for Hosting companies" was found. What it discusses about is common hosting related issues Google spots, including ways for hosting providers recognize, diagnose, and fix these issues.
  • Blocking of Googlebot crawling
  • Availability issues
  • Invalid SSL certificates
  • Wildcard DNS
  • Misconfigured virtual hosting
  • Content duplication through hosting-specific URLs
  • Soft error pages
  • Content modification and frames
  • Spam and malware
SSL Certificates
Though one interesting point is about Invalid SSL Certificates. For SSL certificates to be valid for your website, they need to match the name of the site. Common problems include expired SSL certificates and servers misconfigured such that all websites on that server use the same certificate. Most web browsers will try warn users in these situations, and Google tries to alert webmasters of this issue by sending a message via Webmaster Tools. The fix for these problems is to make sure to use SSL certificates that are valid for all your website’s domains and subdomains your users will interact with.