home.social

#dane — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dane, aggregated by home.social.

  1. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  2. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  3. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  4. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  5. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  6. Viskupič chcel tiež presadiť zníženie daňového zaťaženia príjmov fyzických osôb z predaja virtuálnej meny, a to na základe tzv. časového testu.

    Tón: : veľmi negatívny
    #slovakia #gdelt #sr #sas #dane

    teraz.sk/ekonomika/parlament-o

  7. Viskupič chcel tiež presadiť zníženie daňového zaťaženia príjmov fyzických osôb z predaja virtuálnej meny, a to na základe tzv. časového testu.

    Tón: : veľmi negatívny
    #slovakia #gdelt #sr #sas #dane

    teraz.sk/ekonomika/parlament-o

  8. Viskupič chcel tiež presadiť zníženie daňového zaťaženia príjmov fyzických osôb z predaja virtuálnej meny, a to na základe tzv. časového testu.

    Tón: : veľmi negatívny
    #slovakia #gdelt #sr #sas #dane

    teraz.sk/ekonomika/parlament-o

  9. europesays.com/sk/61903/ Vstane tatranský tiger z popola? Skončí sa trestanie úspechu a Slovákov? Do parlamentu ide návrh zákona, ktorý stopne drakonické dane – Peniaze – Užitočná pravda #Business #dan #dane #Economic #Ekonomika #podnikateľ #sadzba #SK #Slovak #Slovakia #Slovenčina #Slovensko #UžitočnáPravda

  10. Rola Iranu w światowym rynku paliwowo-surowcowym

    1. Iran produkuje 4,5% światowej ropy naftowej.

    2. South Pars = największe pole gazowe na Ziemi.

    3. Iran jest siódmym producentem miedzi na świecie.

    4. 89% irańskiej ropy trafia do Chin

    5. Iran posiada kluczowe weto w Cieśninie Ormuz.

    #Iran #Chiny #Ormuz #cieśnina #paliwa #surowce #rynek #geopolityka #strategia #metale #sojusze #dostawy #handel #bezpieczeństwo #biznes #wojna #konflikt #lit #UE #ZEA #dane

  11. Rola Iranu w światowym rynku paliwowo-surowcowym

    1. Iran produkuje 4,5% światowej ropy naftowej.

    2. South Pars = największe pole gazowe na Ziemi.

    3. Iran jest siódmym producentem miedzi na świecie.

    4. 89% irańskiej ropy trafia do Chin

    5. Iran posiada kluczowe weto w Cieśninie Ormuz.

    #Iran #Chiny #Ormuz #cieśnina #paliwa #surowce #rynek #geopolityka #strategia #metale #sojusze #dostawy #handel #bezpieczeństwo #biznes #wojna #konflikt #lit #UE #ZEA #dane

  12. Surowce krytyczne i strategiczne Iranu
    Gdy debata o Iranie koncentruje się wyłącznie na ropie i gazie, umyka, że Iran jest jednym z 15 najbogatszych mineralnie krajów świata, posiadającym 68 typów minerałów o udokumentowanych rezerwach wartych ok. 27,3 bln USD.

    #Iran #surowcekrytyczne #miedź #cynk #minerały #transformacjaenergetyczna #geopolityka #dane #geologia #biznes #Chiny #Malezja #handel #gospodarka #surowce #rozwój

  13. Surowce krytyczne i strategiczne Iranu
    Gdy debata o Iranie koncentruje się wyłącznie na ropie i gazie, umyka, że Iran jest jednym z 15 najbogatszych mineralnie krajów świata, posiadającym 68 typów minerałów o udokumentowanych rezerwach wartych ok. 27,3 bln USD.

    #Iran #surowcekrytyczne #miedź #cynk #minerały #transformacjaenergetyczna #geopolityka #dane #geologia #biznes #Chiny #Malezja #handel #gospodarka #surowce #rozwój

  14. The 47-day certificate: faster treadmill, same broken foundation

    Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.

    (1/6)

    offerman.com/en/blog/the-47-da

    #TLS #PKI #LetsEncrypt #ACME #DANE #DNSSEC #InternetSecurity #rant #selfhosting

  15. The 47-day certificate: faster treadmill, same broken foundation

    Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.

    (1/6)

    offerman.com/en/blog/the-47-da

    #TLS #PKI #LetsEncrypt #ACME #DANE #DNSSEC #InternetSecurity #rant #selfhosting

  16. The 47-day certificate: faster treadmill, same broken foundation

    Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.

    (1/6)

    offerman.com/en/blog/the-47-da

    #TLS #PKI #LetsEncrypt #ACME #DANE #DNSSEC #InternetSecurity #rant #selfhosting

  17. The 47-day certificate: faster treadmill, same broken foundation

    Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.

    (1/6)

    offerman.com/en/blog/the-47-da

    #TLS #PKI #LetsEncrypt #ACME #DANE #DNSSEC #InternetSecurity #rant #selfhosting

  18. The 47-day certificate: faster treadmill, same broken foundation

    Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.

    (1/6)

    offerman.com/en/blog/the-47-da

    #TLS #PKI #LetsEncrypt #ACME #DANE #DNSSEC #InternetSecurity #rant #selfhosting

  19. 89% irańskiej ropy płynie do jednego kraju - dane eksportowe
    Iran eksportuje ropę naftową od ponad wieku — ale nigdy w historii jego eksport nie był tak skoncentrowany geograficznie jak dziś. Sankcje USA wymusiły przebudowę całego łańcucha dostaw.

    #Iran #USA #Chiny #ZEA #ropa #nafta #surowce #paliwa #dostawy #łańcuchdostaw #cieśnina #polityka #gospodarka #ekonomia #handel #eksport #geopolityka #dane

  20. 89% irańskiej ropy płynie do jednego kraju - dane eksportowe
    Iran eksportuje ropę naftową od ponad wieku — ale nigdy w historii jego eksport nie był tak skoncentrowany geograficznie jak dziś. Sankcje USA wymusiły przebudowę całego łańcucha dostaw.

    #Iran #USA #Chiny #ZEA #ropa #nafta #surowce #paliwa #dostawy #łańcuchdostaw #cieśnina #polityka #gospodarka #ekonomia #handel #eksport #geopolityka #dane

  21. Not to self you are sun shunning #dane for a reason! Don’t go lay in the sun even though it is #spring sun you flipping dumb ass

  22. Not to self you are sun shunning #dane for a reason! Don’t go lay in the sun even though it is #spring sun you flipping dumb ass

  23. Not to self you are sun shunning #dane for a reason! Don’t go lay in the sun even though it is #spring sun you flipping dumb ass

  24. Not to self you are sun shunning #dane for a reason! Don’t go lay in the sun even though it is #spring sun you flipping dumb ass

  25. Not to self you are sun shunning #dane for a reason! Don’t go lay in the sun even though it is #spring sun you flipping dumb ass