home.social

#accounturi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #accounturi, aggregated by home.social.

fetched live
  1. @sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!

    jomo.tv/caa-records-accounturi

    #CAA #accounturi

  2. @sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!

    jomo.tv/caa-records-accounturi

    #CAA #accounturi

  3. @sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!

    jomo.tv/caa-records-accounturi

    #CAA #accounturi

  4. @sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!

    jomo.tv/caa-records-accounturi

    #CAA #accounturi

  5. @sash thanks for sharing this. I've been trying to advertise CAA with accounturi for quite some time, and this is an excellent example of why that's a good idea!

    jomo.tv/caa-records-accounturi

    #CAA #accounturi

  6. I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.

    It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.

    jomo.tv/caa-records-accounturi

    #caa #letsencrypt #accounturi #tls #acme

  7. I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.

    It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.

    jomo.tv/caa-records-accounturi

    #caa #letsencrypt #accounturi #tls #acme

  8. I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.

    It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.

    jomo.tv/caa-records-accounturi

    #caa #letsencrypt #accounturi #tls #acme

  9. I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.

    It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.

    jomo.tv/caa-records-accounturi

    #caa #letsencrypt #accounturi #tls #acme

  10. I wrote about recommendations for CAA records and how the "accounturi" feature can protect you from some attacks.

    It explains how CAA works, but also has some practical advice such as finding your account URI, working in staging/dry runs, working with or without wildcard certificates, and some others.

    jomo.tv/caa-records-accounturi

    #caa #letsencrypt #accounturi #tls #acme

  11. Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023

    Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору

    habr.com/ru/articles/918570/

    #Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi

  12. Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023

    Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору

    habr.com/ru/articles/918570/

    #Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi

  13. Дыра в щите Cloudflare: как атака на Jabber.ru вскрыла проблему, о которой молчат c 2023

    Многие помнят позапрошлогодний инцидент с Man-in-the-Middle атакой на XMPP-сервис jabber.ru . Эта история наделала много шума, но, как мне кажется, главный вывод из неё так и не был усвоен широкой аудиторией. А зря. Потому что эта атака вскрыла системную уязвимость в процессе выдачи TLS сертификатов, которая напрямую касается миллионов сайтов, особенно тех, кто доверяет свою безопасность Cloudflare. В этой статье я расскажу вам о самой уязвимости и как вы можете быть ей подвержены. В кроличью нору

    habr.com/ru/articles/918570/

    #Cloudflare #dns #caa #RFC_8657 #mitm #lets_encrypt #уязвимости #безопасность #acme #accounturi

  14. If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. pentagrid.ch/en/blog/domain-ve #hardening

  15. If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. pentagrid.ch/en/blog/domain-ve #hardening

  16. If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. pentagrid.ch/en/blog/domain-ve #hardening

  17. If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. pentagrid.ch/en/blog/domain-ve #hardening

  18. Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance.
  19. Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance.
  20. Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance.
  21. Hardened my domains #DNS / #TLS / #CAA by adding #RFC8657 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance.
  22. Hardened my domains #DNS / #TLS / #CAA by adding #RFC8675 #accounturi and #validationmethod fields. And specifying those per subdomain where necessary, further restricting certificate issuance.
  23. Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.

    GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.

    #grapheneos #privacy #security #webpki #letsencrypt #accounturi

  24. Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.

    GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.

    #grapheneos #privacy #security #webpki #letsencrypt #accounturi

  25. Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.

    GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.

    #grapheneos #privacy #security #webpki #letsencrypt #accounturi

  26. Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.

    GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.

    #grapheneos #privacy #security #webpki #letsencrypt #accounturi

  27. Normally, WebPKI certificates lack a secure issuance process and an attacker able to MITM unauthenticated HTTP(S) can obtain one.

    GrapheneOS uses the CAA accounturi feature to securely pin our Let's Encrypt account keys for each of our servers for secure certificate issuance.

    #grapheneos #privacy #security #webpki #letsencrypt #accounturi