The PKI Guy talks authentication with author Ivan Ristic

Q&A with Ivan Ristic, author of Bulletproof SSL and TLS and founder of Hardenize TPG: Tell us about your book, Bulletproof SSL and TLS. What are the biggest takeaways for IT security professionals? IR: Bulletproof SSL and TLS came out of my frustrations with the complexities of the TLS and PKI ecosystem and especially the lack of good […]

The PKI Guy discusses AI and security with technologist and author Charles Jennings

Q&A with Charles Jennings, author of the new book Artificial Intelligence: Rise of the Lightspeed Learners TPG: What are some misconceptions about AI? CJ:At a rudimentary level, many people conflate AIs with robots — I’ve seen major articles in both the New York Times and the New Yorker which have done so this year. AI […]

The PKI Guy talks security with Dr. Thorsten Groetker of Utimaco

Q&A with Dr. Thorsten Groetker, chief technology officer, Utimaco TPG: What are enterprises’ top security concerns? TG: Large enterprises have security concerns on many different layers; from secure single sign-on solutions for individual users to security in the cloud. Often, all those challenges must be addressed with an eye on regulatory requirements. How to maintain security in […]

Targeting the Extended Supply Chain – a Brief Review of Stuxnet

In November, 2010 Iranian president Mahmoud Ahmadinejad announced that a “cyber weapon” had been deployed against the Natanz nuclear laboratory. Indeed, some infosec pundits subsequently referred to the attack, called “Stuxnet”, as the first true cyber weapon to be used in anger. While that may be debatable, what is not in question is the design, […]

Our Advanced PKI Training Course Is Now Online

Now is the time to keep your PKI healthy – now more than ever. The key to operating and maintaining your PKI is understanding how it all works. We all know that PKIs are the foundational backbone of enterprise IT security, IoT, and industry specific security standards. Ensuring the security and integrity of your PKI […]

RPKI – The most important Internet security component you never heard of.

What do AWS, Radware, Nintendo, Google, and Facebook all have in common (other than being some of the smartest actors in internet commerce)? Over the past 18 months, they have all been impacted by outages traceable to the Border Gateway Protocol (BGP). The BGP was designed in 1994, literally on a napkin, to route data […]

Microsoft Security Advisory for ADCS exploit – ADV210003

This morning we provided details to our existing support and co-management customers on a recent notice of vulnerability to certain Microsoft ADCS configurations. The exploit involves NTLM and leveraging some ADCS PKI components. Full details can be found here: https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV210003. Summary In environments with NTLM authentication still enabled in Active Directory and when using ADCS Web […]

Microsoft January Patches and CVE-2020-0601

After two days of forewarning, Microsoft released its January 2020 collection of updates for “Patch Tuesday.” It had been leaked that there was a critical flaw in the crypt32.dll library that could represent a serious security flaw for the entire world. The crypt32.dll library provides the foundation for cryptographic operations in Windows and is often […]