Symantec Thawte RapidSSL GeoTrust
Ebay Best Buy DiscountASP.NET Amazon

Windows Live ID adopts Extended Validation (EV) SSL Certificates.

Windows Live ID is very committed to the safety of its users. To further protect the users against phishing, Windows Live ID has adopted (Extended Validation) EV SSL Certificates.

EV SSL certificates require a company to undergo an extensive vetting process and provide users additional assurance about the identity and authenticity of web sites they visit. Thus when a user visits Live ID in IE7, the address bar will turn green and the identity of the company that owns the website – in this instance ‘Microsoft Corporation [US]’ – is displayed. You can get more information on EV certificates here.

Users of sites (such as Hotmail, Spaces, and Microsoft partner sites) that use Live ID authentication can now enjoy the additional protection and verified identity provided by EV SSL. Remember that in order to enjoy the additional assurance provided by EV SSL, users will have to use a newer browser that supports EV SSL, such as Internet Explorer 7. Windows Live ID is the first large scale authentication service to adopt EV certificates; our over 380 million users can now enjoy the additional protection offered by EV over 1.2 billion times a day when they login.

Mozilla Firefox and Google Chrome Updated for Security Flaws

It's a big week for browser updates, as both Mozilla and Google are updating their respective Web browsers for multiple security flaws.

The Mozilla Firefox 3.6.11 update addresses at least nine security flaws, five of which are rated as being critical by Mozilla. Among the critical flaws are memory safety hazard issues, as well as a memory corruption issue that could potentially enable an attacker to run arbitrary code.
Additionally there is a critical fix for a use-after-free memory error, which could enable attackers to make unauthorized use of allocated memory.

"Security researcher Sergey Glazunov reported that it was possible to access the 'locationbar' property of a window object after it had been closed," Mozilla's security advisory states. "Since the closed window's memory could have been subsequently reused by the system, it was possible that an attempt to access the 'locationbar' property could result in the execution of attacker-controlled memory."


Mozilla also credits HP TippingPoint's Zero Day Initiative with the discovery of a JavaScript dangling pointer vulnerability, which could also lead to an attacker taking control of user memory.

"When 'window.__lookupGetter' is called with no arguments, the code assumes the top JavaScript stack value is a property name," Mozilla's advisory states. "Since there were no arguments passed into the function, the top value could represent uninitialized memory or a pointer to a previously freed JavaScript object. Under such circumstances the value is passed to another subroutine, which calls through the dangling pointer, potentially executing attacker-controlled memory."

Firefox 3.6.11 also provides fixes for a number of interesting vulnerabilities, including one related to how Firefox handles the nearly extinct Gopher (define)server system. The Gopher vulnerability could have led to a Cross Site Scripting (XSS) attack.

There is also a fix for an SSL wildcard flaw that Mozilla notes is unlikely to ever occur, since a certificate authority isn't likely to grant the wildcard certificate.

"Security researcher Richard Moore reported that when an SSL certificate was created with a common name containing a wildcard, followed by a partial IP address, a valid SSL connection could be established with a server whose IP address matched the wildcard range by browsing directly to the IP address," Mozilla stated in its advisory.

The issue of SSL wildcards was a topic that was first raised at theBlack Hat 2009 security conference. Famed security researcher reported that the major browser vendors all had SSL wildcard flaws that could potentially be exploited. Mozilla patched the specific flaws highlighted by Kaminsky in August of 2009 with the Firefox 3.5.2 release.

Chrome 7

Google is also joining the Web browser update parade this week with the release of Chrome 7.0.517.41 for its stable channel. The release marks the first stable Chrome 7.x release for Google, after having been in its development channel for the last three months.

With Chrome 7.0.517.41, Google is providing at least 11 security fixes, five of which are labeled as having high impact and one listed as critical. The critical flaw is a browser crash issue related to the form autofill capability.

As was the case with Firefox, memory corruption issues are part of the Chrome fix list. Google has credited researcher Simon Schaak with reporting memory corruption issues with animated GIF images in Chrome.

Chrome 7.0.517.41 also provides a high impact fix for a possible URL spoofing issue that could have occurred when the page is unloaded.

ClickSSL provides (VeriSign) Site Seal "Trusted" Service.

Now internet surfing is a actual accepted process, but anytime anticipation about its authority and credibility? As millions of website owners are there accountability of these sites are awful needed, and to accomplish that VeriSign Trust Seal has been introduced. Actually the VeriSign Internet Trust Basis was advised to barometer the levels of trust humans abode on the Internet. See if you fit one of the trust basis profiles: Am I agreement too majorly trust in the Internet, or too little? Now How to acquaint if a website is secured or not. With so abounding sites on the Web, it’s harder to apperceive which are safe to trust, and which to avoid.

Now VeriSign trust is there to actuate whether the website is secure or not and for that you allegation to analysis out assertive factors. If you’re application a high-security, Extended Validation Secure Sockets Layer (EV SSL) enabled Web browser
, analysis to see if the abode bar has became green. Look for the VeriSign trust™ seal and bang on it to verify that the seal is authentic. Ensure that the URL in your address bar begins with HTTPS, not HTTP. That added “s” is important, as it stands for “SECURE”.

Now you may ask why Trust Is Essential in agreement of your website's credibility. You will appear beyond altered Causes that and some of them are Stand out from the antagonism in search results; Build trust in your Web site; Reduce the risk of getting blocked by search engines and browsers; Show customers your identity has been verified; Display the #1 trust mark on the Internet, and so on. Also begin that VeriSign adds adds trust enhancement to its SSL. New security features, which cover circadian malware scanning and the company's Seal-in-Search technology, can advice now website operators to ensure that users of their sites can browse them and accomplish online transactions without fear of security breaches.

"In the face of added busy attacks and fraud schemes, web sites require solutions that do added than data encryption," as said by vice president of product marketing at VeriSign. "By enhancing our SSL Certificate services with new features that instill trust at every step of the online experience—at no additional charge to our customers—we're delivering a more robust and value-driven solution. In the process, we're redefining what web sites should expect from online security."

As the brand desired by major banks and retailers, the VeriSign seal cab build assurance for higher transitions on all types of Web sites now.

ClickSSL is VeriSign Platinum Partner company and authorized to resell and renew all RapidSSL, GeoTrust, Thawte and VeriSign SSL certificates. SSL certificate will be issued by VeriSign itself and you will save more money and maintenance cost. Even you have purchase SSL from other resellers or direct from VeriSign then also you can renew it with ClickSSL.com.

Symantec Launches New Logo with VeriSign Check

Symantec Corporation, known for its software security products, recently released its new design company logo.

The previous logo was created in 2000, and since then Symantec has widened its portfolio and recently acquired the VeriSign (News - Alert) check mark for $1.28 billion along with VeriSign’s security business, which includes the (Secure Sockets Layer) SSL Certificate Services, the Public Key Infrastructure (PKI) Services, the VeriSign Trust Services and the VeriSign Identity Protection (VIP) Authentication Service.

The VeriSign check mark is the most recognized symbol, associated with trust, particularly in websites. When consumers see the logo, they know they are accessing a safe site or that their shopping will be safe, encouraging them to purchase more online.

The new logo with a circle and checkmark will represent the unified resources and will enhance Symantec’s (News - Alert) recognition in the industry and market segments. Symantec provides industry solutions including security from threats and information thefts, data loss, data protection, manage PC systems, antivirus, anti-malware, anti-spam, backup and recovery of data, systems and email, security management, storage management, Endpoint security and management, virtualization management, and web security among others, to businesses of all sizes. It is more popular under the Norton suite of security products.

Symantec, said, "We believe in today's connected world that the Symantec check mark will stand for confidence, the same way the Nike swoosh stands for fitness. The new logo signals Symantec's vision to bring together identity and device security, information protection, context and relevance and the benefits from leveraging the cloud - all critical enablers of confidence in a connected world."

VeriSign added, "This transaction allows VeriSign to focus on the growing Internet infrastructure services business, where we expect to build on our expertise and record of success as the longtime operator of the .com and .net domain infrastructures. We believe Symantec's leading position as the premier end-to-end security provider will enable them to better serve our authentication customers and accelerate market growth."

GeoTrust Further Beats Go Daddy in Race for SSL Industry Contribution between Lead Websites

The internet's most visited sites continue to rely on GeoTrust, Inc., according to the latest "Alexa Netcraft Index," a monthly measure of Secure Sockets Layer (SSL) certificate used around the world.

GeoTrust, a leading SSL Certificate authority (CA), secured 20.6 percent of unique domains among the 1 million most visited sites whose SSL usage is tracked by Netcraft. The VeriSign brand followed with 17.9 percent of all unique domains, and Go Daddy again was third, with a 15.6 percent share.

The Alexa Netcraft Index is produced by cross-referencing data from Netcraft's September SSL Survey and the Alexa Top 1 Million Domains list. The analysis found nearly 170,000 unique domains on the Alexa 1 Million where Netcraft found SSL certificates. Of that total, 34,792 are protected by GeoTrust(R) SSL certificates, 30,220 by VeriSign SSL certificates, and 26,433 by Go Daddy.

The latest results show GeoTrust's continual lead in the high-volume, low-cost SSL market remains unchallenged. In this particular market segment, low prices drive purchase decisions among SSL customers whose primary concern is to encrypt data transferred to and from their sites. On the flipside, the VeriSign brand leads the premium SSL certificate and online trust category, where customers demand full business authentication, seal-in-search, daily malware scans, and other enhanced services in addition to encryption.

"Every time they renew their SSL certificates, the most popular sites on the internet vote for the brand they trust most," said Jeff Barto, senior product marketing manager for GeoTrust. "Year in and year out, again and again, they return to place their trust in GeoTrust. For sites large and small, investing in GeoTrust SSL certificates has obviously proven to be a successful way to build trust with an increasingly wary public. Just ask the Web sites that matter most."

Prepared by Catapult Data Services, the Alexa Netcraft Index obtains an accurate picture of SSL certificate usage across the Web sites that matter most by cross-referencing the Netcraft SSL Survey with the Alexa 1 Million list. The Netcraft SSL survey tallies all publicly facing SSL certificates on the internet, including "parked" certificates on unused or infrequently visited Web sites. The Alexa 1 Million is a well-known site traffic measurement service that ranks the 1 million most visited sites in order of popularity.

With SSL certificates issued in more than 150 countries around the world, GeoTrust offers world-class SSL certificates with fast delivery at a cost-effective price. Enabling up to 256-bit SSL encryption, they include a range of GeoTrust(R) True Site seals based on the desired level of identity verification.

GeoTrust's SSL solutions present a wide range of cost-effective options, including standard or Extended Validation (EV) SSL certificates, support of up to 256-bit SSL encryption, static or dynamic GeoTrust True Site seals, and warranty protection ranging from $10,000. In addition, GeoTrust offers multi-domain support in the Subject Alternative Names (SANs) field for greater flexibility to work with products like Microsoft Exchange Server 2007 and Microsoft Office Communications Server 2007.

About GeoTrust A wholly owned subsidiary of Symantec, Corp.

(SYMC 15.39, +0.22, +1.45%) , GeoTrust is the world's largest low-cost digital certificate provider. More than 100,000 customers in over 150 countries trust GeoTrust to secure online transactions and conduct business over the internet. GeoTrust's range of digital certificate and trust products enable organizations of all sizes to maximize the security of their digital transactions cost-effectively.

Symantec is a global leader in providing security; storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored.

Apple releases Security Update 2010-005 for Mac OS X



Apple today released a security update for Mac OS X. Security Update 2010-005 weights 84 MB and it available through Software Update. Apple fixes the following with the update:

ATS:

CVE-ID: CVE-2010-1808: Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.4, Mac OS X Server v10.6.4.

Impact: Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.

Symantec closes Verisign security deal

INSECURITY OUTFIT Symantec has closed its $1.28 billion acquisition of Verisign's identity and authentication business.

Now that it has bought Verisign, Symantec is close to doing some serious work in SSL Certificates, Public Key Infrastructure and other online trust and identity technologies.


However it should make a real killing flogging SSL certificates along with its security products, which will mean that customers will have a one stop shop for Internet security. This is particularly important for online transaction services.

Enrique Salem, president and CEO of Symantec said that enterprises and consumers expect simple and secure access to information from any device, protection from identity fraud, and online experiences that are user-friendly and hassle-free.

He said that the combination of Symantec's leading security solutions with Verisign's security products, services and recognition as the most trusted brand online puts Symantec in a strong position.

Symantec plans to integrate Verisign technologies with its array of endpoint security and data loss prevention products.

Symantec might weave Verisign SSL technology into its products like Critical System Protection and Protection Suite for Servers to bolster the security of customers' web servers and increase trust levels during financial and other sensitive transactions.

Symantec said it plans to incorporate Verisign technologies into its data loss prevention products to ensure that only authorised users can access certain types of information.

Symantec has been buying up companies like a mad thing this year, taking some key names like PGP and Guardianedge into its stable.

Credit: Original Source

Chrome extension forces secure Google searches


Google SSL Web Search adds encrypted Google search to Chrome's list of search engines.

Google now offers an extension for Chrome that automates the process of adding the secure Google search site as a search engine to the Chrome 6.x branch. Google SSL Web Search is an extension, still in beta, that works with Chrome 6.0.419.0 and later on Windows and Linux computers.

SSL Secures Website seal

This columnist absolution provides affluence of advice about defended your website allowance and account of SSL Certificates to assure your eCommerce website.

CLICKSSL.COM currently offers a chargeless Defended Website Allowance to all SSL Certificates Customers, which helps them to brainwash web visitors on the secures technology they apply to assure adjoin phishing attacks and eavesdropping. secures Website Allowance acutely shows that the affairs performed on the website are deeply encrypted by arch SSL technology. When aggregation bang on SSL website seal, it displays website secures information.

If you accept installed accurate amount SSL (Organization Absolute SSL Certificate) again you can appearance Accurate Website Seal. This shows organizations data such as area name, business name, abode and etc. This way you can accord your website visitors visible, real-time affirmation that the website is accurate and protected.

Visitors like alone user affable and arresting things to see on website. Now if you accept installed SSL Certificates on website and you do not affectation SSL secures Website Allowance again some visitors may jump out from your website. SSL secures Website is a cast image, abnormally for online arcade barrow websites.

You should be acquainted of SSL secures Website Allowance use and misuse. Following are few abetment on abusage of SSL secures Website Seal.

Who should affectation SSL secures Website Allowance on website?

1. If you accept installed absolute SSL Certificates on your website, again alone you can use SSL secures Website Seal.

Who should not affectation SSL secures Website Allowance on website?

1. If your website is not installed SSL Certificates and you affectation SSL Website allowance again it is diddle.

2. If you accept purchased SSL Certificates but did not install on website and you affectation Website Allowance again it is diddle.

3. If you accept already installed SSL Certificates but SSL Certificates authority is asleep and you affectation SSL secures website allowance again it is diddle.

4. If you accept SSL purchased for one of your aggregation website and you affectation SSL secures Website Allowance on all aggregation website, again it is diddle.

5. You can affectation SSL secures Website Allowance on SSL Certificates installed website.

Warning:

SSL secures Website Allowance abusage is diddle and anyone (SSL Provider /Reseller / Issuer / Customer / Visitor) can affirmation for this diddle. As they can accept that either you abundance claimed advice like Credit Card amount and protect code, username, password, credential information.

For added advice on the new website allowance service, amuse visit: ClickSSL.com

Attacking the edges of defended Internet traffic

Researchers accept baldheaded new means that abyss can spy on Internet users even if they're application defended admission to banks, online retailers or added acute Web sites.

The attacks approved at the Black Hat appointment actuality appearance how bent hackers can detect about the edges of encrypted Internet cartage to aces up clues about what their targets are up to.

It's like borer a blast chat and audition deadened choir that adumbration at the accent of the conversation.

The botheration lies in the way Web browsers handle Defended Sockets Layer, or SSL, encryption technology, according to Robert Hansen and Josh Sokol, who batten to a arranged allowance of several hundred aegis experts.


Encryption forms a affectionate of adit amid a browser and a website's servers. It scrambles abstracts so it's awkward to prying eyes.

SSL Certificate is broadly acclimated on sites trafficking in acute information, such as acclaim agenda numbers, and its attendance is apparent as a padlock in the browser's abode bar.

SSL is a broadly attacked technology, but the admission by Hansen and Sokol wasn't to breach it. They capital to see instead what they could apprentice from what are about the breadcrumbs from people's defended Internet surfing that browsers leave abaft and that accomplished hackers can follow.

Their attacks would crop all sorts of information. It could be almost minor, such as browser settings or the amount of Web pages visited. It could be absolutely substantial, including whether anyone is accessible to accepting the "cookies" that abundance usernames and passwords misappropriated by hackers to log into defended sites.

Hansen said all above browsers are afflicted by at atomic some of the issues.

"This credibility to a beyond botheration” we charge to amend how we do cyber banking commerce," he said in an account afore the conference, an anniversary acquisition adherent to advertisement the latest computer-security vulnerabilities.

For the boilerplate Internet user, the analysis reinforces the accent of accepting accurate on accessible Wi-Fi networks, area an antagonist could bulb himself in a position to attending at your traffic. For the attacks to work, the antagonist accept to aboriginal accept admission to the victim's network.

Hansen and Sokol categorical two dozen problems they found. They accustomed attacks application those weaknesses would be harder to cull off.

The vulnerabilities appear out of the actuality humans can cream the Internet with assorted tabs accessible in their browsers at the aforementioned time, and that apart cartage in one tab can affect defended cartage in addition tab, said Hansen, arch authoritative of consulting close SecTheory. Sokol is a aegis administrator at National Instruments Corp.

Their allocution isn't the aboriginal time advisers accept looked at means to abrade defended Internet cartage for clues about what's accident abaft the blind of encryption. It does aggrandize on absolute analysis in key ways, though.

"Nobody's accepting afraid with this tomorrow, but it's avant-garde research," said Jon Miller, an SSL able who wasn't complex in the research.

Miller, administrator of Accuvant Labs, accepted Hansen and Sokol for demography a altered admission to advancing SSL.

"Everybody's animadversion on the foreground door, and this is, 'let's yield a attending at the windows,'" he said. "I never would accept anticipation about accomplishing something like this in a actor years. I would accept anticipation it would be a decay of time. It's accurate because it's a little different."

Another accepted allocution at Black Hat anxious a new advance affecting potentially millions of home routers. The advance could be acclimated to barrage the kinds of attacks declared by Hansen and Sokol.

Researcher Craig Heffner advised 30 altered types of home routers from companies including Actiontec Electronics Inc. and Cisco Systems Inc.'s Linksys and begin that added than bisected of them were accessible to his attack.

He tricked Web browsers that use those routers into absolution him admission authoritative airheaded that alone the routers' owners should be able to see. Heffner said the vulnerability is in the browsers and illustrates a beyond aegis botheration involving how browsers actuate that the sites they appointment are trustworthy.

The admonition is he has to aboriginal ambush anyone into visiting a awful site, and it helps if the victim hasn't afflicted the router's absence password.

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites