Free Post PKI Are you ready for the Symantec distrust? It's been common knowledge in the wider PKI community that Symantec, the Certificate Authority, is currently being distrusted and will soon cease to exist as a CA. My...
Free Post HSTS Bypassing HSTS or HPKP in Chrome is a badidea I saw some research published at BlackHat EU recently that detailed various ways to bypass both HSTS and HPKP in a variety of mainstream browsers. It was a novel technique...
Free Post chrome Chrome Address Spoofing PoC An address spoofing vulnerability has been disclosed in Google Chrome that not only allows a site to change the address you see in the address bar, but the certificate if...
Free Post chrome Why you shouldn't use your browser to store online passwords A recently publicised "flaw" in Chrome and Firefox could allow someone with access to your computer to view all of your online passwords in a matter of seconds. Let's look at exactly what the problem is and what can be...
Follow