Events

TROOPERS20 Training Teaser: TLS in the Enterprise – Post Quantum Security

Our workshop “TLS in the enterprise” was held for the first time at Troopers 2018 and was our special contribution to the IT Security world to increase the usage of TLS and point out the pitfalls, when switching to TLS.

But time is changing and TLS is a kind of standard nowadays, at least when looking at HTTPS, but there are still a lot of things to do regarding other protocols like

Continue reading
Events

TLS in the Enterprise: Is Heartbleed still a Problem?

Our new workshop about TLS/SSL in the enterprise will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.

TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that

  • encrypted traffic should be inspected e.g. for malware
  • customers/users must be able to use important applications
  • crypto attacks are complex and sometimes considered to be only a problem in theory
  • the internal CERT wants to have every issue fixed, if feasible or not 😉
  • impact of configuration changes can not be foreseen
  • Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )
  • … and so forth

In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:

Continue reading