#tls

22 posts · Last used 5d

Back to Timeline
Hab da mal was gebastelt... man hat am Wochenende ja nichts Besseres zu tun: Secure Your ServerZwei praktische Checks. Ein seriöser Sicherheitsbericht. Prüfe eine Domain auf die Härtungsdetails, auf die Angreifer und Audits zuerst schauen. Teste danach, ob deine echten E-Mails sauber authentifiziert und zugestellt werden. Kein Konto, kein Tracking, keine Bezahlschranke. Domain-Sicherheitsscan Vollständige externe Sicht auf TLS/SSL, SSH, offene Ports, DNS, SPF, DKIM, DMARC, MTA-STS, HTTP-Security-Header, WHOIS und PGP/WKD. Mail-Zustellungstest Erzeuge eine einmalige Testadresse, schick eine Mail aus deinem Postfach und sieh SPF, DKIM, DMARC, TLS, rDNS, Spam-Signale und Zustellungsdetails. Bugs, Verbesserungswünsche bitte an "hallo [at] chrislo.de" Mehr Infos: https://www.sichere-deinen-server.de/ #chrislo #sys #secureyourserver #sicheredeinenserver #sicherheit #security #server #domain #tls #ssh
0
0
0
Ian Kluft ✅✈️🎈🌋 @ikluft@avgeek.social · Jul 27, 2026
Replying to @ikluft@avgeek.social
#Airbus A350-1000ULR test flight from Toulouse🇫🇷 #TLS / #LFBO non-stop for 19 hours to Melbourne🇦🇺 #MEL / #YMML was flown on Friday, July 24. https://www.flightaware.com/live/flight/AIB35LR/history/20260723/0530Z/LFBO/YMML #aviation #travel #avgeek
1
1
2
Ian Kluft ✅✈️🎈🌋 @ikluft@avgeek.social · Jul 27, 2026
Replying to @ikluft@avgeek.social
#Airbus A350-1000ULR test flight is currently returning from Melbourne🇦🇺 #MEL / #YMML to Toulouse🇫🇷 #TLS / #LFBO going eastbound with favorable winds to make a one-stop-around-the-world test. Later they will also need to test westbound Australia to Europe against unfavorable winds. https://www.flightaware.com/live/flight/AIB35LR/history/20260727/0700Z/YMML/LFBO #aviation #travel #avgeek
2
1
2
Ian Kluft ✅✈️🎈🌋 @ikluft@avgeek.social · Jul 27, 2026
"Airbus Tests A350-1000ULR With First Flight to Australia" by AirlineGeeks / Zach Vasile - #Airbus test pilots flew a prototype A350-1000ULR (ultra long range) from the Airbus factory in Toulouse🇫🇷 #TLS / #LFBO non-stop for 19 hours to Melbourne🇦🇺 #MEL / #YMML. This test verifies ULR can achieve its purpose for launch customer Qantas🦘: non-stop flight between Western #Europe and Eastern #Australia with margin to route around weather and war zones. https://airlinegeeks.com/2026/07/27/airbus-tests-a350-1000ulr-with-first-flight-to-australia/ #aviation #travel #avgeek
0
1
1
Marin Ivezic @infosec@defcon.social · Jul 23, 2026
Can't migrate everything to PQC at once. Which layer first? TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario. https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/ #PQC #TLS #IPsec #infosec #cryptography
0
0
3
Sven Slootweg, ("still kinky and horny anyway") @joepie91@fedi.slightly.tech · Jul 20, 2026
I've republished to Codeberg my ca-incidents list, a permanent record of security/trust incidents involving SSL/TLS Certificate Authorities, because continuous scrutiny is important for the trust in the system: https://codeberg.org/joepie91/ca-incidents It hasn't been updated in quite a while (last update was in 2016), and I'm sure that more things will have happened since, so please submit a PR if you know of any incidents to add! #ProjectToot #TLS
0
0
0
John Kristoff @jtk@infosec.exchange · Jul 12, 2025
2
0
2
Sven Slootweg, ("still kinky and horny anyway") @joepie91@fedi.slightly.tech · Jul 16, 2026
#TLS question: when using mutual authentication (ie. server and client certs), is it possible for an MITM to spoof the client certificate when the server doesn't know the correct fingerprint yet, while presenting the correct server certificate to the client in the same connection, so without the client knowing anything is wrong?
0
2
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 15, 2026
Two critical RabbitMQ flaws allow authentication bypass. One forges TLS client certs; the other tricks OAuth2 JWKS to accept any JWT. #RabbitMQ #AuthBypass #TLS #OAuth2 #InfoSec https://securityonline.info/rabbitmq-authentication-bypass-flaws/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
CertKit @certkit@infosec.exchange · Jul 13, 2026
If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. https://www.certkit.io/blog/tls-handshake-explained #TLS #SysAdmin
2
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 06, 2026
A widespread OpenSSL error handling flaw makes apt fail HTTPS in FIPS mode. A stale error queue entry gets misread as fatal. Audit your code. #OpenSSL #ErrorHandling #FIPS #apt #Debian #TLS #CyberSecurity #InfoSec https://securityonline.info/openssl-error-handling-apt-fips/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
gary @gary_alderson@infosec.exchange · Jul 05, 2026
hp z4 g4 is the go to but i have to do a bit more research, my cost will be 3500-4k, 1 k margin maybe, ongoing support/upsells/addons but not too much - the basics and focus is what it is all about - big mkt out there - with warm leads from splash/squeeze pages conversion rates go up #tls proxy #central logging #dashboards #arkime #structured data
0
0
0
C. @cazabon@mindly.social · Jul 03, 2026
Replying to @djb@mastodon.cr.yp.to
@djb@mastodon.cr.yp.to They're also getting really testy about us "regular Joes" showing up and voting against publication of the deliberately-weak solo PQ recommendation. You can practically feel their frustration - "We stuffed this list to pass this vote, and they're stuffing it against us!". The blatant hypocrisy of the "not standards-track" thing bugged me too when it came through the list. Anyone who follows me and cares about cryptography or their privacy: read djb's short blurb here: https://nsa.2026.action.cr.yp.to/ There's action you can take to try to prevent the NSA's attempt to get the world to standardize on deliberately weakened cryptography in TLS - i.e. the thing that protects every important web connection on the planet. They have form for doing this in the past, and are trying again. There are other links in the above page for more information. #TLS #HTTP #HTTPS #cryptography #privacy
5
0
5
Wish the sun to stand still 🌞 @tasket@infosec.exchange · Jul 04, 2026
RE: https://mas.to/@nemo/116864001224955528 NSA involved in "off the rails" warrant-less mass surveillance. This (and the fact that their chain of command was purged by the Trump regime) should be factored into the debate around the IETF relying on the NSA's input. If your position is that a simple RFC is "not a big deal" then IDK why you're making a big deal out of people like @djb@mastodon.cr.yp.to being against it. #FISA #crypto #ietf #tls #pqc #privacy #surveillance
1
0
1
Peter N. M. Hansteen @pitrh@mastodon.social · Jun 29, 2026
0
0
0
Ivan Enderlin 🦀 @hywan@floss.social · Jun 09, 2026
Let's Encrypt bans certificate usage in any US sanctioned territory, https://news.ycombinator.com/item?id=48453275 Here we are. Let’s Encrypt is not trustable anymore. Any alternatives? Feeling sad. #LetsEncrypt #tls #ssl #https
113
14
149