Symantec Thawte RapidSSL GeoTrust
Ebay Best Buy DiscountASP.NET Amazon

Apple releases Security Update 2010-005 for Mac OS X



Apple today released a security update for Mac OS X. Security Update 2010-005 weights 84 MB and it available through Software Update. Apple fixes the following with the update:

ATS:

CVE-ID: CVE-2010-1808: Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.4, Mac OS X Server v10.6.4.

Impact: Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.

Symantec closes Verisign security deal

INSECURITY OUTFIT Symantec has closed its $1.28 billion acquisition of Verisign's identity and authentication business.

Now that it has bought Verisign, Symantec is close to doing some serious work in SSL Certificates, Public Key Infrastructure and other online trust and identity technologies.


However it should make a real killing flogging SSL certificates along with its security products, which will mean that customers will have a one stop shop for Internet security. This is particularly important for online transaction services.

Enrique Salem, president and CEO of Symantec said that enterprises and consumers expect simple and secure access to information from any device, protection from identity fraud, and online experiences that are user-friendly and hassle-free.

He said that the combination of Symantec's leading security solutions with Verisign's security products, services and recognition as the most trusted brand online puts Symantec in a strong position.

Symantec plans to integrate Verisign technologies with its array of endpoint security and data loss prevention products.

Symantec might weave Verisign SSL technology into its products like Critical System Protection and Protection Suite for Servers to bolster the security of customers' web servers and increase trust levels during financial and other sensitive transactions.

Symantec said it plans to incorporate Verisign technologies into its data loss prevention products to ensure that only authorised users can access certain types of information.

Symantec has been buying up companies like a mad thing this year, taking some key names like PGP and Guardianedge into its stable.

Credit: Original Source

Chrome extension forces secure Google searches


Google SSL Web Search adds encrypted Google search to Chrome's list of search engines.

Google now offers an extension for Chrome that automates the process of adding the secure Google search site as a search engine to the Chrome 6.x branch. Google SSL Web Search is an extension, still in beta, that works with Chrome 6.0.419.0 and later on Windows and Linux computers.

SSL Secures Website seal

This columnist absolution provides affluence of advice about defended your website allowance and account of SSL Certificates to assure your eCommerce website.

CLICKSSL.COM currently offers a chargeless Defended Website Allowance to all SSL Certificates Customers, which helps them to brainwash web visitors on the secures technology they apply to assure adjoin phishing attacks and eavesdropping. secures Website Allowance acutely shows that the affairs performed on the website are deeply encrypted by arch SSL technology. When aggregation bang on SSL website seal, it displays website secures information.

If you accept installed accurate amount SSL (Organization Absolute SSL Certificate) again you can appearance Accurate Website Seal. This shows organizations data such as area name, business name, abode and etc. This way you can accord your website visitors visible, real-time affirmation that the website is accurate and protected.

Visitors like alone user affable and arresting things to see on website. Now if you accept installed SSL Certificates on website and you do not affectation SSL secures Website Allowance again some visitors may jump out from your website. SSL secures Website is a cast image, abnormally for online arcade barrow websites.

You should be acquainted of SSL secures Website Allowance use and misuse. Following are few abetment on abusage of SSL secures Website Seal.

Who should affectation SSL secures Website Allowance on website?

1. If you accept installed absolute SSL Certificates on your website, again alone you can use SSL secures Website Seal.

Who should not affectation SSL secures Website Allowance on website?

1. If your website is not installed SSL Certificates and you affectation SSL Website allowance again it is diddle.

2. If you accept purchased SSL Certificates but did not install on website and you affectation Website Allowance again it is diddle.

3. If you accept already installed SSL Certificates but SSL Certificates authority is asleep and you affectation SSL secures website allowance again it is diddle.

4. If you accept SSL purchased for one of your aggregation website and you affectation SSL secures Website Allowance on all aggregation website, again it is diddle.

5. You can affectation SSL secures Website Allowance on SSL Certificates installed website.

Warning:

SSL secures Website Allowance abusage is diddle and anyone (SSL Provider /Reseller / Issuer / Customer / Visitor) can affirmation for this diddle. As they can accept that either you abundance claimed advice like Credit Card amount and protect code, username, password, credential information.

For added advice on the new website allowance service, amuse visit: ClickSSL.com

Attacking the edges of defended Internet traffic

Researchers accept baldheaded new means that abyss can spy on Internet users even if they're application defended admission to banks, online retailers or added acute Web sites.

The attacks approved at the Black Hat appointment actuality appearance how bent hackers can detect about the edges of encrypted Internet cartage to aces up clues about what their targets are up to.

It's like borer a blast chat and audition deadened choir that adumbration at the accent of the conversation.

The botheration lies in the way Web browsers handle Defended Sockets Layer, or SSL, encryption technology, according to Robert Hansen and Josh Sokol, who batten to a arranged allowance of several hundred aegis experts.


Encryption forms a affectionate of adit amid a browser and a website's servers. It scrambles abstracts so it's awkward to prying eyes.

SSL Certificate is broadly acclimated on sites trafficking in acute information, such as acclaim agenda numbers, and its attendance is apparent as a padlock in the browser's abode bar.

SSL is a broadly attacked technology, but the admission by Hansen and Sokol wasn't to breach it. They capital to see instead what they could apprentice from what are about the breadcrumbs from people's defended Internet surfing that browsers leave abaft and that accomplished hackers can follow.

Their attacks would crop all sorts of information. It could be almost minor, such as browser settings or the amount of Web pages visited. It could be absolutely substantial, including whether anyone is accessible to accepting the "cookies" that abundance usernames and passwords misappropriated by hackers to log into defended sites.

Hansen said all above browsers are afflicted by at atomic some of the issues.

"This credibility to a beyond botheration” we charge to amend how we do cyber banking commerce," he said in an account afore the conference, an anniversary acquisition adherent to advertisement the latest computer-security vulnerabilities.

For the boilerplate Internet user, the analysis reinforces the accent of accepting accurate on accessible Wi-Fi networks, area an antagonist could bulb himself in a position to attending at your traffic. For the attacks to work, the antagonist accept to aboriginal accept admission to the victim's network.

Hansen and Sokol categorical two dozen problems they found. They accustomed attacks application those weaknesses would be harder to cull off.

The vulnerabilities appear out of the actuality humans can cream the Internet with assorted tabs accessible in their browsers at the aforementioned time, and that apart cartage in one tab can affect defended cartage in addition tab, said Hansen, arch authoritative of consulting close SecTheory. Sokol is a aegis administrator at National Instruments Corp.

Their allocution isn't the aboriginal time advisers accept looked at means to abrade defended Internet cartage for clues about what's accident abaft the blind of encryption. It does aggrandize on absolute analysis in key ways, though.

"Nobody's accepting afraid with this tomorrow, but it's avant-garde research," said Jon Miller, an SSL able who wasn't complex in the research.

Miller, administrator of Accuvant Labs, accepted Hansen and Sokol for demography a altered admission to advancing SSL.

"Everybody's animadversion on the foreground door, and this is, 'let's yield a attending at the windows,'" he said. "I never would accept anticipation about accomplishing something like this in a actor years. I would accept anticipation it would be a decay of time. It's accurate because it's a little different."

Another accepted allocution at Black Hat anxious a new advance affecting potentially millions of home routers. The advance could be acclimated to barrage the kinds of attacks declared by Hansen and Sokol.

Researcher Craig Heffner advised 30 altered types of home routers from companies including Actiontec Electronics Inc. and Cisco Systems Inc.'s Linksys and begin that added than bisected of them were accessible to his attack.

He tricked Web browsers that use those routers into absolution him admission authoritative airheaded that alone the routers' owners should be able to see. Heffner said the vulnerability is in the browsers and illustrates a beyond aegis botheration involving how browsers actuate that the sites they appointment are trustworthy.

The admonition is he has to aboriginal ambush anyone into visiting a awful site, and it helps if the victim hasn't afflicted the router's absence password.

Internet's 1 Million Most-Visited Domains Rely on GeoTrust SSL More Than Any Other Certificate Authority

MOUNTAIN VIEW, CA, Jul 06, 2010 (MARKETWIRE via COMTEX) -- GeoTrust, Inc., a leading certificate authority, today announced that its Secure Sockets Layer (SSL) Certificates secure more of the most-visited web sites on the Internet than any other certificate authority. The results, which were determined using Netcraft data against the Alexa Top 1 Million Domains list, highlight the popularity of GeoTrust over low-cost competitors on popular web sites.

To obtain an accurate picture of SSL Certificates usage on the most heavily-visited web sites, VeriSign, parent company of GeoTrust, commissioned Catapult Data Services to cross reference the Alexa Top 1 Million against Netcraft's June 2010 SSL Survey.
The Netcraft SSL survey is a tally of all publicly-facing SSL certificates on the Internet, including "parked" certificates on unused or infrequently-visited web sites. The Alexa Top 1 Million is a well-known site traffic measurement service that lists the million most visited sites, ranked by order of popularity.

The cross-reference revealed 33,871 unique domains protected by GeoTrust(R) SSL certificates out of approximately 136,000 of the Alexa Top 1 Million on which Netcraft found certificates. In contrast, Go Daddy, which has long claimed leadership in the low-cost SSL category, protected only 23,667 unique domains among these sites.

Although VeriSign is widely recognized as the leader in the premium SSL certificate and online trust category, its GeoTrust product competes with brands such as Go Daddy for leadership in the low-cost category, where customers are simply looking to enable encryption.

"Since this study provides an accurate depiction of SSL doing what it's intended to do -- authenticate sites and protect transactions -- the index we've commissioned reflects overwhelming preference for GeoTrust by the operators of the most visited domains on the Internet," said Jeff Barto, senior product marketing manager for GeoTrust. "Based on this data, GeoTrust clearly leads the low-cost SSL category."

With SSL certificates issued in more than 150 countries around the world, GeoTrust offers world-class SSL certificates with fast delivery at a cost-effective price. Enabling up to 256-bit SSL encryption, they include a range of GeoTrust(R) True Site seals based on the desired level of identity verification.

What Customers Are Saying

"Being an internationally based company, root ubiquity was of cardinal importance to our decision making process," said Ming Keong Kuan, director of iStyles.com, a Singapore-based fashion accessories provider for consumer electronics. "We needed to make sure that the SSL certificates would work where we are based, which is why we selected GeoTrust as our certificate authority of choice."

"The GeoTrust True Site Seal allows us to instantly communicate to existing and prospective customers that their transaction is in safe hands. Best of all, this protection comes at a price our budget can accommodate," said Scott Miller, chief executive officer of A1 Pool Parts, a Southern California-based provider of quality pool products and services.

"Reputation is key; if we want businesses to be confident in our services we need to provide them with a visual security seal from a brand name that they can easily recognize and correlate with trust," said Kurt Davey, founder and chief executive officer of Neoverve, Inc., an ecommerce service provider and Web design company.

GeoTrust's SSL solutions present a wide range of cost-effective options, including standard or Extended Validation EV SSL certificates, support of up to 256-bit SSL encryption, static or dynamic GeoTrust True Site seals, and warranty protection ranging from $10,000 to $150,000. In addition, GeoTrust offers multi-domain support in the Subject Alternative Names (SANs) field for greater flexibility to work with products like Microsoft Exchange Server 2007 and Microsoft Office Communications Server 2007. Companies can sign up today for a free 30-day trial of GeoTrust SSL certificate protection.

About GeoTrust A wholly owned subsidiary of VeriSign, Inc. (VRSN 28.15, -0.30, -1.05%), GeoTrust is the world's largest low-cost digital certificate provider. More than 100,000 customers in over 150 countries trust GeoTrust to secure online transactions and conduct business over the Internet. GeoTrust's range of digital certificate and trust products enable organizations of all sizes to maximize the security of their digital transactions cost-effectively. For more information, visit www.geotrust.com.

Statements in this announcement other than historical data and information constitute forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. These statements involve risks and uncertainties that could cause VeriSign's actual results to differ materially from those stated or implied by such forward-looking statements. The potential risks and uncertainties include, among others, the uncertainty of future revenue and profitability; potential fluctuations in quarterly operating results due to such factors as the inability of VeriSign to successfully develop and market new products and services and customer acceptance of any products or services, including those mentioned herein, increasing competition and pricing pressure from competing services offered at prices below our prices; and the uncertainty of whether VeriSign will achieve its stated objectives. More information about potential factors that could affect the company's business and financial results is included in VeriSign, Inc.'s filings with the Securities and Exchange Commission, including in the company's Annual Report on Form 10-K for the year ended December 31, 2009, Quarterly Reports on Form 10-Q and Current Reports on Form 8-K. VeriSign undertakes no obligation to update any of the forward-looking statements after the date of this press release.

Copyright2010 VeriSign, Inc. All rights reserved. VeriSign, the VeriSign logo, the Checkmark Circle, GeoTrust, and other trademarks, service marks, and designs are registered or unregistered trademarks of VeriSign, Inc., and its subsidiaries in the United States and in foreign countries. All other trademarks are property of their respective owners.

Internet's 1 Million Most-Visited Domains Rely on GeoTrust SSL More Than Any Other Certificate Authority.
Credit: GeoTrust

Most SSL Sites Poorly Configured

A variety of news stories issuing from the Black Hat security conference this week in Las Vegas describe presentations in which researchers highlight holes in web browser security, including widespread problems with the implementation of SSL Certificates.

According to a report appearing Thursday on the Forbes blogs, security researchers Robert Hansen and Josh Sokol presented a list of 24 reasons, Wednesday, why users shouldn’t trust their browser’s padlock security indicator, the image typically associated with sites secured by SSL certificates.


The presentation reportedly divided threats into mostly low- and medium-level threats, with two that Hansen considered critical. All of those threats, said the presenters, require the hacker to deploy a man-in-the-middle program on the user’s network.

The first of the critical flaws was a “cookie-passing” trick, in which the hacker visits a site before a user, receiving a valid cookie that he then passes to the user. When the legitimate user visits the site, the hacker’s cookie then becomes associated with the user, enabling the hacker to access to the user’s account.

The other critical issue was a technique through which a hacker can use an insecure tab in a user’s browser to send a request to install a plug-in once the user has opened a secure tab, making the request appear to come from the secure site.

All the slides from Hansen and Sokul’s presentation are embedded in the Forbes.com article.

SSL security and its vulnerabilities are a frequent topic at the annual Black Hat conference – which stands to reason, as it is one of the main security functions associated with ecommerce. Last year, Dan Kaminsky and Moxie Marlinspike presented vulnerabilities they had found in the issuing process for SSL certificates at the conference.

In a separate presentation at this year’s Black Hat, security researcher Ivan Ristic presented the results of a study that suggests close to 97 percent of SSL certificates are incorrectly configured, according to a report in eSecurity Planet.

Presenting the results of a study that examined 867,000 SSL certificates, Ristic said that nearly 97 percent of SSL certificates do not have the correct name on them, and don’t match the domain to which they are associated.

Of the 3 percent that matched, only one third were correctly configured – which meant, he said 2,048-bit or better encryption and the disabling of support for the SSLv2 protocol.

According to the report, Ristic speculates that the reason for the scarcity of properly-configured certificates is a lack of widespread documentation and education for the technology.

The Black Hat conference took place in Las Vegas this week, with training from July 24 to July 27, and briefings running from July 28 to July 29.

There are wide range of SSL certificates available in industry, but before purchase or renew you should look out for the best support you get from the various SSL certificates seller and reseller, you can choose RapidSSL, GeoTrust, Thawte & Verisign to secure your eCommerce website with no hassle.

Origional Source at thewhir.com

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites