Weekly Update 152

Presently sponsored by: Friends don’t let friends write user auth. Use Okta instead. Start your free trial today.

Weekly Update 152

I made it out of Vegas! That was a rather intense 8 days and if I’m honest, returning to the relative tranquillity of Oslo has been lovely (not to mention the massive uptick in coffee quality). But just as the US to Europe jet lag passes, it’s time to head back to Aus for a bit and go through the whole cycle again. And just on that, I’ve found that diet makes a hell of a difference in coping with this sort of thing:

This week it’s almost all about commercial CAs and their increasingly bizarre behaviour. It’s disappointing to see disinformation and privacy violations from any organisations, but when it’s from the ones literally controlling trust on the web it’s especially concerning. Maybe once they’re no longer able to promote EV in the way they have been that will change, but I have a feeling we’ve got a bunch more crap to endure yet. See what you think about all that in this week’s update:

Weekly Update 152
Weekly Update 152
Weekly Update 152

References

  1. Reminder: If you’re using the HIBP API to search for email addresses, get yourself onto V3 ASAP! (you’ve got 2 days until the old versions die)
  2. Chegg had 40M accounts breach with unsalted MD5 password hashes! (it was April last year, now it’s searchable in HIBP)
  3. Extended Validation Certificates are (Really, Really) Dead (I’ve been saying it for ages, but both Chrome and Firefox have really nailed it now)
  4. DigiCert is rejecting the proposal to reduce maximum certificate lifespans (uh, except for that post a few years ago when they thought it was a good idea…)
  5. Sectigo leaked the personal info of a do-gooder which resulted in him receiving a threatening letter (there’s all kinds of things gone wrong here)
  6. Big thanks to strongDM for sponsoring my blog over the last week! (see why Splunk’s CISO says “strongDM enables you to see what happens, replay & analyze incidents. You can’t get that anywhere else”)


Troy Hunt’s Blog


Are you looking for products for hacking, cybersecurity, and penetration testing? Do you need to cleanse your smartphone, PC, or website from viruses and malware? Do you need to track down a person or recover urgent information? Do you need to regain control of an account, email, or password that has been stolen from you? Interested in purchasing pre-configured devices to easily and quickly experiment with hacking techniques? Do you have specific requirements in software or hardware? We can assist you!

Contact us immediately for immediate assistance: provide us with details via email or WhatsApp about the type of support you need, and we will respond you promptly!

Fill out and submit the form below to send us an immediate support request

Write your email address here

Write here how we can help you - we provide immediate support for all your needs!

chevron_left
chevron_right