Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

This is a courtesy notice that if your company has Entrust-issued TLS certificates in load-bearing capacities, you would do well to figure out how you would move to either or both of a) another CA, or b) 90-day cert validity periods .

Thank you. You may return to burning effigies of the Palo Alto product manager of your choice.

Adbot
ADBOT LOVES YOU

Raymond T. Racing
Jun 11, 2019

Subjunctive posted:

This is a courtesy notice that if your company has Entrust-issued TLS certificates in load-bearing capacities, you would do well to figure out how you would move to either or both of a) another CA, or b) 90-day cert validity periods .

Thank you. You may return to burning effigies of the Palo Alto product manager of your choice.

your certificate authority is a piece of poo poo

Thanks Ants
May 21, 2004

#essereFerrari


Look some were issued incorrectly but our clients told us it would be disruptive for us to revoke them and the customer is always right you see

BlankSystemDaemon
Mar 13, 2009



tadashi posted:

I love how smug I feel when I don't get an interview for an infosec job I applied for and then the company has a huge information security issue.
There's probably no difference I would have made, but they don't know that :argh:
It means they were looking to hire someone to take the fall for existing issues.

Sickening
Jul 16, 2007

Black summer was the best summer.

BlankSystemDaemon posted:

It means they were looking to hire someone to take the fall for existing issues.

I find that the issues are already a known issue internally and this is to backfill the current fall guys.

Defenestrategy
Oct 24, 2010

Sickening posted:

I find that the issues are already a known issue internally and this is to backfill the current fall guys.

How much is the going rate for professional fall guy?

Shumagorath
Jun 6, 2001

BlankSystemDaemon posted:

It means they were looking to hire someone to take the fall for existing issues.
Seppuku as gig work

Rust Martialis
May 8, 2007

At night, Bavovnyatko quietly comes to the occupiers’ bases, depots, airfields, oil refineries and other places full of flammable items and starts playing with fire there

Subjunctive posted:

This is a courtesy notice that if your company has Entrust-issued TLS certificates in load-bearing capacities, you would do well to figure out how you would move to either or both of a) another CA, or b) 90-day cert validity periods .

Thank you. You may return to burning effigies of the Palo Alto product manager of your choice.

Anyone got a summary I can put in front of my CISO boss's eyes

The Fool
Oct 16, 2003


https://substack.com/@aaomidi

Wiggly Wayne DDS
Sep 11, 2010



Rust Martialis posted:

Anyone got a summary I can put in front of my CISO boss's eyes
there'll be one soon ...

tadashi
Feb 20, 2006

I finally registered to take the CISSP.
I've used the official study guide, some classes, Destination CISSP, CISSP flash cards, podcasts.
Basically everything I can think of other than actual Brain Dumps/test banks.

Any last advice from anyone?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rust Martialis posted:

Anyone got a summary I can put in front of my CISO boss's eyes

Expecting one from the head of Mozilla’s root program in the next day or two, maybe today.

Amir’s above is pretty good though incomplete.

spankmeister
Jun 15, 2008






Another successful goon project

unknown
Nov 16, 2002
Ain't got no stinking title yet!


Serious Hardware/Software Crap › The Infosec Thread: Yes, time to move off Entrust

some kinda jackal
Feb 25, 2003

 
 
En"Trust"

BonHair
Apr 28, 2007

Zero trust refers to vendors

Internet Explorer
Jun 1, 2005





unknown posted:

Serious Hardware/Software Crap › The Infosec Thread: Yes, time to move off Entrust

lol, this is great. Reported it to remind myself next time I'm at a computer.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rust Martialis posted:

Anyone got a summary I can put in front of my CISO boss's eyes

https://wiki.mozilla.org/CA/Entrust_Issues just dropped

waiting for Bruce Morton to release a diss track response

spankmeister
Jun 15, 2008






Subjunctive posted:

https://wiki.mozilla.org/CA/Entrust_Issues just dropped

waiting for Bruce Morton to release a diss track response

Step aside Kendrick, Bruce has beef

Hughmoris
Apr 21, 2007
Let's go to the abyss!

Oct posted:

I haven't vetted these myself but the folks behind the DFIR Report have started offering a few hands-on labs which might be good:
https://the-dfir-report-store.myshopify.com/collections/dfir-labs

Considering the quality of their writeups, I'd wager they will be pretty good.

I'll take a look at these, thanks!

Wiggly Wayne DDS
Sep 11, 2010



the email has landed: https://groups.google.com/u/1/a/mozilla.org/g/dev-security-policy/c/LhTIUMFGHNw

The Fool
Oct 16, 2003


hell yes

CLAM DOWN
Feb 13, 2007




eat poo poo entrust you fucks

digitalist
Nov 17, 2000

journey into Kirk's unknown


Rust Martialis
May 8, 2007

At night, Bavovnyatko quietly comes to the occupiers’ bases, depots, airfields, oil refineries and other places full of flammable items and starts playing with fire there

CLAM DOWN posted:

eat poo poo entrust you fucks

So I'm not a certificate guy. A skim says Entrust is sloppy and non-conformant to standards., and doesn't clean up promptly and properly. What's the killer aspect I'm not grasping in this?

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Rust Martialis posted:

So I'm not a certificate guy. A skim says Entrust is sloppy and non-conformant to standards., and doesn't clean up promptly and properly. What's the killer aspect I'm not grasping in this?

"We hosed up."
"Are you going to fix it?"
"No, it wasn't a big deal and we'd make our customers mad."
"But you absolutely need to, it's part of the thing you agreed to do when you were trusted by us"
"Yeah but we're not gonna."

The willful noncompliance for what appears to be strictly customer facing business reputation reasons is apparently the hill they've chosen to die on, and it looks like the root program is accepting that challenge and asking if they're really sure about that.

spankmeister
Jun 15, 2008






Rust Martialis posted:

So I'm not a certificate guy. A skim says Entrust is sloppy and non-conformant to standards., and doesn't clean up promptly and properly. What's the killer aspect I'm not grasping in this?

They have a month to come up with a plan to shape up or face consequences. A full on detrust doesn't seem likely at this point but as posters more in the know have already suggested, limiting them to 90 or even 30 days until they have demonstrated to have significantly improved their attitude seems possible.

Sickening
Jul 16, 2007

Black summer was the best summer.
A CA not worried about their reputation is a bit ironic.

dragon64
Apr 24, 2024
Glad we have two Entrust threads now

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY

dragon64 posted:

Glad we have two Entrust threads now

We can't entrust it to just one

corgski
Feb 6, 2007

Silly goose, you're here forever.

It's fine, entrust me bro

spankmeister
Jun 15, 2008






Who entrusts the entrusters? (It's browser vendors)

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

dragon64 posted:

Glad we have two Entrust threads now

is that you, Bruce?

flakeloaf
Feb 26, 2003

Still better than android clock

Subjunctive posted:

is that you, Bruce?

Prove it isn't

SlowBloke
Aug 14, 2017
Yubico is refreshing their yubikey 5 and security key firmware

https://www.yubico.com/press-releas...ation-at-scale/

Main items are:
- pin complexity assessment
- expanded storage for TOTP and resident fido2 identities

No way to upgrade existing keys so you will have to junk your current one if you need those features. Too little too late on the expanded storage IMHO, most people that used them i know of (me included) eventually moved to other platforms for TOTP and passkeys when they clashed against the limits.

SlowBloke fucked around with this message at 11:38 on May 8, 2024

Zorak of Michigan
Jun 10, 2006


Why such small storage? I've never understood that given how cheap gigabytes of memory have become.

Raymond T. Racing
Jun 11, 2019

Zorak of Michigan posted:

Why such small storage? I've never understood that given how cheap gigabytes of memory have become.

The super secure storage is entirely different than "flash drive memory"

SlowBloke
Aug 14, 2017

Raymond T. Racing posted:

The super secure storage is entirely different than "flash drive memory"

The change is being sold as a firmware upgrade so i would guess they had shorter indexes/pointers for the TOTP and FIDO items to save on complexity in code/memory usage. If hardware changed, they would have said so to make the case for new purchases, rather than a simple firmware replacement in their fabs.

The Earl of ToeJam
Jan 22, 2012
Possible Zscaler data breach.

https://x.com/DarkWebInformer/status/1788186389755969990

Adbot
ADBOT LOVES YOU

Diva Cupcake
Aug 15, 2005

Welp. My day is getting longer.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply