<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>TLS on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/tls/</link>
    <description>Recent content in TLS on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 09 Dec 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/tls/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS20 Training Teaser: TLS in the Enterprise – Post Quantum Security</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</link>
      <pubDate>Mon, 09 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</guid>
      <description>&lt;p&gt;Our workshop “TLS in the enterprise” was held for the first time at Troopers 2018 and was our special contribution to the IT Security world to increase the usage of TLS and point out the pitfalls, when switching to TLS.&lt;/p&gt;&#xA;&lt;p&gt;But time is changing and TLS is a kind of standard nowadays, at least when looking at HTTPS, but there are still a lot of things to do regarding other protocols like&lt;/p&gt;</description>
    </item>
    <item>
      <title>TLS in the Enterprise: Is Heartbleed still a Problem?</title>
      <link>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</link>
      <pubDate>Fri, 16 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</guid>
      <description>&lt;p&gt;Our new workshop about &lt;a href=&#34;https://troopers.de/troopers18/trainings/9afapk/&#34;&gt;TLS/SSL in the enterprise&lt;/a&gt; will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.&lt;/p&gt;&#xA;&lt;p&gt;TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;encrypted traffic should be inspected e.g. for malware&lt;/li&gt;&#xA;&lt;li&gt;customers/users must be able to use important applications&lt;/li&gt;&#xA;&lt;li&gt;crypto attacks are complex and sometimes considered to be only a problem in theory&lt;/li&gt;&#xA;&lt;li&gt;the internal CERT wants to have every issue fixed, if feasible or not 😉&lt;/li&gt;&#xA;&lt;li&gt;impact of configuration changes can not be foreseen&lt;/li&gt;&#xA;&lt;li&gt;Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )&lt;/li&gt;&#xA;&lt;li&gt;… and so forth&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
