#accounturi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #accounturi, aggregated by home.social.
-
@sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!
-
@sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!
-
@sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!
-
@sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!
-
@sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!
-
I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.
It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.
-
I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.
It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.
-
I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.
It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.
-
I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.
It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.
-
I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.
It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.
-
Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023
Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору
https://habr.com/ru/articles/918570/
#Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi
-
Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023
Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору
https://habr.com/ru/articles/918570/
#Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi
-
Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023
Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору
https://habr.com/ru/articles/918570/
#Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi
-
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening
-
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening
-
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening
-
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening
-
Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance. -
Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance. -
Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance. -
Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance. -
Hardened my domains #DNS / #TLS / #CAA by adding #RFC8675 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance. -
Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.
GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.
#grapheneos #privacy #security #webpki #letsencrypt #accounturi
-
Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.
GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.
#grapheneos #privacy #security #webpki #letsencrypt #accounturi
-
Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.
GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.
#grapheneos #privacy #security #webpki #letsencrypt #accounturi
-
Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.
GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.
#grapheneos #privacy #security #webpki #letsencrypt #accounturi
-
Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.
GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.
#grapheneos #privacy #security #webpki #letsencrypt #accounturi