tirza-van-dijk-58298-unsplash

How PKI and Embedded Security Can Help Stop Airplane Cyber ​​Attacks

On July 30th , the U.S. Department of Homeland Security and Cyber ​​Security Infrastructure Agency (KAG) published a Security Warning to warn small aircraft owners of security vulnerabilities that can be exploited to alter the aircraft’s telemetry. The aircraft’s controller area network (CAN bus), which is at risk of cyberattacks, connects the various avionics systems – control, navigation, detection, monitoring, communication and entertainment systems – which enable the safe operation of modern aircraft. This includes the engine telemetry data, compass and position data, flight speeds and the angle of attack of the aircraft. All of this could be hacked to provide false readings to pilots and automated computer systems that help the aircraft fly.

The CISA warning is not hypothetical, and the consequences of inactivity could prove fatal prove. Aircraft systems have already been compromised. In September In 2016, a U.S. government official announced he and his team of IT professionals The Boeing 757 passenger plane is on a runway in New Jersey found successful from the Hacked and could take control of its flight functions. In the year previously a hacker reportedly had vulnerabilities exploited in the IFE system (In Flight Entertainment) to control to take over the flight functions and the aircraft engines for climbing bring to.

The Boeing 757 attack was carried out via the in-flight entertainment WLAN network.

A researcher from security analysis and automation provider Rapid7 recently wrote a blog about the security of CAN bus avionics systems and discussed the challenge at this year’s DEFCON security conference. He explained, ‘I think part of the reason [the avionics sector is lagging behind in terms of network security in relation to the CAN bus] is the heavy reliance on the physical security of aircraft. Just like football helmets can actually increase the risk of brain breaches, the increased perceived physical security of aircraft may paradoxically make them more vulnerable to cyberattacks, not less. ‘

A false sense of [physical] security

The DHS CISA warning states: ‘An attacker with physical access to the aircraft could connect a device to an avionics CAN bus that could inject false data, resulting in false readings in the avionics equipment.’ Vulnerabilities can provide false readings to pilots and lead to crashes or other air incidents involving small aircraft, and attackers with CAN bus access can alter engine telemetry data, compass and attitude data, altitude and airspeed.

Not all of these attacks required physical access.

These risks should serve as a wake-up call for everyone in manufacturing. Any device, system or organisation that controls the operation of a system is at risk, and threats can come from internal or external sources. It is critical for OEMs, their supply chains and organisations to incorporate security and identity management at the device level and continuously improve their security capabilities to close security gaps.

Security solutions for avionics devices

Today’s aircraft have dozens of interconnected subsystems that transmit critical telemetry and control data. Currently, top-tier aerospace suppliers and OEMs have not comprehensively implemented security technologies such as secure boot, secure communications and embedded firewalls on their devices, leaving them vulnerable to hacking. While OEMs have begun to address these issues, there is still much more to be done.

Sectigo provides solutions that enable OEMs, their supply chains and enterprises to take full advantage of PKI and embedded security technology for connected devices. Our industry-first end-to-end IoT platform, enabled by the acquisition of Icon Labs , a provider of security solutions for embedded OEMs and IoT device manufacturers, can be used to issue and renew certificates with a single trust model that is interoperable across any issuance model and for all supported devices, operating systems, protocols and chipsets.  

Similar to that Automotive industry, the aviation sector has a very complex supply chain, and the implementation private PKI and embedded security leads to interoperability problems. in view of the fact that leading avionics manufacturers produce hundreds of SKUs a year introduce it, it’s complex, cumbersome and ultimately unsustainable, hundreds to carry different safe boots in a single airplane. The Simplified use of a single homogeneous secure launch implementation the model significantly.

 

An specifically for the IoT developed PKI, like the Sectigo IoT Manager , enables strong authentication and secure Communication between devices in the airframe. The use of the PKI-based authentication prevents communication from failing authorized components or devices and prevents a variety of attacks.

The embedded firewall technology provides an additional critical layer of security for these systems. This is especially true for attacks such as the Boeing 757 via the airline’s infotainment Wi-Fi network. An embedded firewall supports filtering rules to prevent the Wi-Fi network from accessing the control network.

Icon Labs’ embedded firewall has been used in aircraft and automotive systems to prevent such attacks. In both cases, our embedded firewall sits on a gateway device in the vehicle or aircraft to prevent unauthorised access from external networks or devices to the control network, or from the infotainment network to the control network. We continue to see interest in this area, which indicates that manufacturers are starting to take action.

From the cockpit to the control tower

The backup connected equipment in aviation is not on planes limited. The industry needs secure communication between everyone Parts of the asphalt, from cockpits and control towers to deployment of vehicles and security personnel. For this reason, Sectigo offers an Award-winning co-root of the AeroMACS consortium, which deals with the entire Broadband communications at airports around the world and after Security calls by PKI certificates for airplanes, catering trucks and everything others are used on the asphalt.

Future-proof with Crypto Agility

It is worth noting that aviation is also due to the duration of its components is challenged in a unique way. Unlike devices designed for Airplanes are designed for a lifespan of months or years designed to last for decades. Progress in the area of Quantum computers, which many experts believe to be immediate impending, today’s cryptographic standards could become superfluous do. Aviation suppliers must face this upcoming “crypto-apocalypse” be prepared and update the security of your equipment on site while the devices are in operation. Sectigo’s wireless update functions offer the cryptographic flexibility to face this upcoming Protect crypto-apocalypse (see the associated podcast to the causes ).

The ecosystem needs to work fast. Manufacturers need to secure the CAN buses in their existing and future fleets – whether those aircraft are on fenced tarmacs or idling in aircraft hangars. In the meantime, CISA advises that aircraft owners restrict access to aircraft avionics components ‘to the best of their ability’ and let passengers hope that security will soon move beyond their TSA experience.

EV_Certificate

New Georgia Tech EV SSL Security Investigations: EV Domains Are 99.99% Free From Online Crime

Today we have new research from Cyber ​​Forensics Innovation (CyFI) Lab from Georgia Tech on the topic Extended Validation (EV) SSL and online criminal actors. The CyFI laboratory collected the domain names from 2.6 million EV certificates from 2010 and compared them to a number of sources that identified known or suspected bad actors. These sources included domains related to:

  • Underground marketplaces and forums
  • Bad IP blacklists
  • Malware

This investigation, carried out by a financial Contribution made possible by Sectigo revealed that 99.99% of the domains were with EV certificates have no association with the domains identified above have bad actors. In his research report says the Research Team:

‘The probability of an EV SSL certificate being associated with malicious domains is less than 0.00013 or less than 0.013%. This means that EV SSL certificates are most likely not associated with domains related to underground forums and marketplaces or malware/cybercrime activities. ‘

As some malware programmes ping popular websites for functional reasons that are completely unrelated and innocent of malware activity, this figure may be pessimistic in terms of the level of security provided by an EV certificate. For example, the malware list found by CyFI includes domains from Apple, Symantec, Comodo and Citrix. It is highly unlikely that these companies are bad actors, but that the malware authors are touching these sites entirely for other reasons.

Among the 2.6 million EV domains assessed, CyFI discovered a total of three domains with EV certificates associated with cyber actors actively tracked on underground marketplaces and forums, as well as seven cyber actors associated with them. The description provides details on these domains and actors.

The research team writes: ‘We found that the likelihood of a domain with an EV certificate being abused or associated with cybercrime is negligible compared to cybercrime or abuse. ‘The summary section of the paper adds: ’We conclude that EV certificates are highly indicative of legitimate domains registered by legitimate companies. Therefore, users will benefit from noticing and using browser security indicators as a guide to trust domains with EV SSL certificates. ‘

The CyFI team has proposed to conduct further research on this topic, including the differences between domains that have been established and owned by cyber actors and those that have been compromised due to abuse. CyFI would also like to investigate how browsers can better utilise this information to communicate to the end user the level of known legitimacy for a particular site in a way that enables safer decision making.

Sectigo would like to encourage CyFI and all other academic and white hat researchers to continue working on this topic. The company is strongly committed to working with White Hat to make a significant contribution to overall cybersecurity. We encourage any White Hat who would like to work with Secorio to identify and remediate potential exploits in our global PKI infrastructure to contact us. You can contact us personally – we will then work with Sectigo to identify the key points for collaboration.

0_0 (2)

How do I secure my WordPress site?

How do I secure my WordPress site with SSL in 5 easy steps?

WordPress strives to protect its users. After all, they are a company that benefits from their own customers. They will do their best by protecting their customers from online attacks. However, there are factors that could lead to a website security error, such as human error.

A user of the WordPress website is expected to customize his own website. This is a great opportunity to personalize your own protection and experience with WordPress. However, it can also become a vulnerability if you overlook stronger security settings.

Securing your website

Since there are human downsides to managing a WordPress website, there are a few things to keep in mind when working. Never let human error become your own weak point.

• Keep WordPress Core up to date: when WordPress releases security updates, WP Engine can ensure that your site receives them. Whenever possible, we recommend that you do not postpone these updates. If WordPress core updates are released, it is recommended to test the updates on your staging site. You can then create the update on your live website as soon as you have confirmed all functions.

• Always update your plugins and designs: plugins and design authors frequently publish security updates. These updates can also help to optimize the plugin so that it works well with the current versions of WordPress. It is important to keep up to date with these plugin and design updates. Out-of-date software is the most common cause of malware or infections on websites, as their security features are lost after the period of validity expires.

• Never log in to WordPress on a public computer: If you log in to your website from a public computer, your administrator credentials may be vulnerable to other users using the same computer or to other users on the network.

• Two-factor authentication logon: Implementing two-factor authentication (2FA) for logging in is one of the simplest but most effective ways to prevent brute force attacks. They work by adding an additional level of login security by requesting additional proof of ID, such as a code generated by cell phones or secret questions. The WP Google Authentication plugin is a good example of a 2FA plugin that can be easily installed to secure your site login.

• Regularly check admin users: It is recommended to occasionally check users for your WP admin area and for SFTP (in the user portal) to ensure that only those users who still need access are allowed. This is also a good step to ensure that your website users only get the required level of access (author, publisher, administrator, etc.).

Secorio offers many security functions

There are many options available online, but Secorio, in collaboration with Code Guard, offers the most efficient features for businesses. It has many other features that help keep your website stronger than other security tools. This is the website review tool that combines a Web Application Firewall (WAF) that is delivered through a Secure Content Delivery Network (CDN). It is a fully functional website security review tool from the 24/7 Cyber ​​Security Operation Center (CSOC) certified security analyst. It is supported by a Security Information and Event Management (SIEM) that uses data from over 85 million endpoints for detection to mitigate threats before they occur.

With Code Guard from Secorio, I was able to eliminate the hidden malware on our company website within a few minutes. Thanks to Code Guard, in addition to constant malware monitoring, I now also have a simple and reliable option for website backup services.

Christian Müller
Web Developer

To strengthen the firewall function of the web application, you will find further functions here that Code Guard has at its levels.

Cyber ​​Security Operations Center (CSOC) Cyber ​​Security Operations Center (CSOC) Your team of certified cybersecurity experts who are available 24/7 and provide 24/7 surveillance and repair services.

Sicherheitsinformations- und Veranstaltungsmanagement (SIEM) Security information and event management (SIEM) Website security for my website offers enhanced intelligence that uses current events and data from 85 million endpoints and 100 million domains.

Secure Content Delivery Network (CDN) Website security for my website has a global system of distributed servers that improve the performance of websites and web applications.

PCI-Scanning The website security for my website is equipped with PCI scanning and enables retailers and service providers to comply with the PCI DSS guidelines.

Monitoring and eliminating malware Website security for my website identifies malware, provides the tools and methods for removal, and helps prevent future malware attacks.

You will receive the first test free of charge for all the advantages of free Code Guard protection! No credit cards needed. Our products are suitable for interested online entrepreneurs to increase the security of their websites as a service. Secorio Code Guard contains unique, sophisticated web security functions as service functions that are not available as service tools in other web security systems.

0_1

How S/MIME helps you comply with HIPAA

As everyone knows, who runs a health organization, health care is about more than diagnosing patients and practicing positive bedside behavior. At its core, much of the work in healthcare is rooted in communication. Nurses communicate with patients and their families, doctors communicate with specialists, administrators communicate with insurance specialists, insurance companies communicate with pharmacies, and all these different people communicate with each other.

So it shouldn’t be so shocking that email security is an important concern in the healthcare industry. Secorio has detailed written about the threatsto which companies are exposed via email, e.g. B. targeted Spear-phishing attacks that are designed to entice employees to reveal confidential information or even money. My colleague Tim Callan (CEO of Sectigo CA) also wrote about S/MIME and how its certificate-based authentication technology can help reduce the risk of email-based attacks and keep confidential information under lock and key.

Healthcare is more at stake than many other industries. The information that needs to be protected must be protected not only for ethical reasons, but also for legal reasons. Health Insurance Portability and Accountability Act of 1996 ( HIPAA ) sets firm ground rules for protecting patient privacy and it is up to the healthcare industry to take appropriate measures to comply with these rules.

The type of information that is involved makes the healthcare industry an important target for attackers. Patients’ personal health information (PHI) often needs to be emailed and HIPAA requirements require that the PHI be protected using digital certificates so that healthcare facilities can effectively protect patient privacy. Emails that are sent beyond the firewall must be encrypted consistently: they must be encrypted on the sending mail server, on the receiving mail server and during transmission. This level of encryption ensures that only the sender and recipient of the email can view the content. This means that even the operator of the server or the malicious software can see the content within the established email controls. It even works with mail servers running in third-party cloud services.

Encryption may sound complicated, but S/MIME technology offers a comprehensive email security solution that addresses each of these issues – and in an industry that regularly emails personal, health, insurance, and payment information this is not the case. It is not difficult to understand why these protective measures are important. Through the organization-wide provision of e-mail certificates, S/MIME offers exactly the security measures prescribed by HIPAA in a cost-effective and user-friendly package.

Using S/MIME to encrypt emails allows professionals to meet HIPAA email retention requirements without compromising security requirements. Since the email content is encrypted before being archived, PHI remains protected from being passed on regardless of how it is stored. The search for header information in the application remains critical, so that S/MIME encryption is perfect for both secure storage and simple retrieval of information.

Regulations like HIPAA can be intimidating, but thanks to the simplicity of S/MIME technology available to health organizations today, compliance can be very easy. SMIME offers reliable end-to-end encryption and straightforward protocols for archiving and retrieving information and enables these organizations to protect PHI and protect their own emails from external threats.

image-1

Is the private PKI really private?

If you have a website that provides a service to customers outside your company, it may have a digital certificate that is public rooted. This means that the chain of trust leads to a root certificate issued by a well-known certificate authority (CA) that has already been trusted by your users’ browsers and other key application technologies (e.g. Java). By using a public trunk, you can instantly achieve universal trust in your entire user base.

You may also have a number of other servers that are not externally targeted and do not require publicly rooted certificates. However, these servers may still need authentication, signing, and functionality to establish a secure TLS session with other internal servers or applications. The root of trust for these servers would be a private certification authority (CA). A separate certification body that is part of the cloud-based Sectigo Private PKI- offer.

With our private PKI solution you can mark the certificates for your servers, devices and users. Because the purpose of this certification authority is to serve only your company, it provides more precise control when this PKI infrastructure is used for internal user authentication. For this reason, private PKI is extremely popular for deployment in corporate IT as well as in cloud-native DevOps and Internet of Things (IoT) environments.

Three deployment scenarios

There are three deployment architectures to consider to use Sectigo Private PKI:

  1. Sectigo hosts the private root certification authority and the issuing certification authority (s) in the cloud for you.
  2. Your organization hosts the private root certification authority of your choice and Sectigo hosts the issuing certification authority (s) for you.
  3. Or Sectigo hosts the private root certification authority and your organization hosts the issuing certification authorities

Many of our customers prefer option 1 because all operational aspects of PKI, including hosting, maintenance, security and compliance, are handled by Sectigo. You simply obtain and install certificates from us and make them available in your environment. Some customers may already have a private root CA, or their corporate security policy may require that the root CA be in their area. In this case, Sectigo can host and manage the issuing certification authorities that are signed by their local root certification authority.

Since the majority of the work is done at the issuing certification body, they are relieved of many everyday tasks. In the third situation mentioned above, a certification authority (e.g. Microsoft certification authority, HashiCorp Vault PKI instance or Kubernetes certification authority) may be active in your environment and integrated into your applications. You can significantly improve your security situation by hosting an offline root CA with keys stored in a Hardware Security Module (HSM) in an industry-standard data center, and signing your existing CA, which will then issue and manage end-user certificates and devices.

We can help you choose the option that best suits your situation and help you implement the deployment architecture you choose. Figures 1, 2 and 3 show all three scenarios.

Figure 1. Private PKI hosted by Sectigo
Figure 2. Customer-hosted root certification authority with issuing certification authority hosted by Sectigo
Figure 3. Root Certification Authority hosted by Sectigo with the issuing certification authority hosted by the customer

IT and DevOps friendly private PKI

You will likely use trusted certificates in your AWS, Azure, or other cloud environment for container-to-container and application-to-application authentication and secure communication between them. Sectigo Private PKI is integrated into the most common DevOps tools, so that when you roll out your infrastructure and applications automatically, you can seamlessly register certificates from Sectigo Private PKI and manage their lifecycle. To ensure that your software is not tampered with, you should also code your containers and other applications with code signatures, which can also come from the same PKI infrastructure.

With the advent of cloud-friendly microservices architecture, your services can come and go, requiring high volume and short-lived certificates. Sectigo Private PKI is able to issue and manage certificates with a short lifecycle. Our licensing scheme supports this business model to make it cost-efficient for you.

Automation-oriented solution

Automation plays a key role in our architecture. Sectigo Private PKI supports you in the end-to-end automation of issuing and installing certificates.

We support industry-standard protocols such as registration via secure transport (EST) and the Simple Certificate Enrollment Protocol (SCEP) and work on integration with third-party tools, e.g. B. Kubernetes Cert-Manager, HashiCorp Terraform and Vault, Ansible. Puppet, cook and others. In Microsoft Windows environments you can use our automatic registration function to issue certificates from Sectigo Private PKI. For non-Microsoft companies, you can use other supported tools that have been tested with our private PKI to manage certificates for them.

This latest blog, ” When it comes to automating SSL certificates Sectigo offers many options, “ contains useful ones Information about the suite of automation tools that Sectigo uses to reduce the manual work of administrators.

Central Management Console

Our customers rarely prefer to go to two different providers to get their public and private certificates. For this reason, we have designed our system so that you can manage everything from a central console, which can be used as a Enterprise Certificate Manager is called . The administrator’s experience is the same regardless of the type of certificates you manage. All of your certificates are displayed in the central console with their status and expiry date. Certificate Manager can recognize all your certificates, even if they are not from Sectigo / Comodo, and generate reports on them.

We have other exciting plans to give you a comprehensive overview of your private PKI, public SSL and corporate IoT certificates. Contact us for more information.

rawpixel-com-567026-unsplash1

How Extended Validation SSL directly contributes to online business and why is it important?

We already have mentioned how Extended Validation (EV) SSL is an important and effective component in the online business’s fight against phishing. However, these certificates are only significant if they are used by websites.

So it’s worth taking a look at why websites use EV SSL certificates. It is common knowledge that these certificates are more expensive than in terms of budget and implementation time as Domain Validation (DV) certificates.So if an IT team has no good reason to choose EV, we should expect them to save some money and time. Although the cost and inconvenience of electric vehicles are negligible compared to other parts of the security stack, employees are fundamentally efficiency and budget oriented. If there is no reason to do anything else, choose the cheapest and easiest solution.

Advantages of EV SSL

When we talk about benefits, it’s important to remember that authentication does not apply to the entity being authenticated. Read that again and think about it for a moment: Authentication does not apply to the entity being authenticated. Rather, it is for everyone else. Let’s take an ID card as an example, like a driving licence or a passport. When you go to the airport, you need to carry an official ID with you. This is not because you have doubts about your own identity. Rather, you are carrying your passport because the TSA and customs officials at the airport require it. Your passport is not for you; it’s for them. Why do you carry your passport when travelling? Because they won’t let you on the plane otherwise. In other words, there’s a motivation built into the system for authenticating people. If we want to fly, we have to be authenticated. Our motivation is not to trust our own identity. We all know who we are. Rather, our motivation is to be allowed on the aircraft. The same applies to authenticating online sites and services. IT professionals are not going to spend their time and effort labelling themselves as real because they already know that. To invest in authentication, they need a motivator. Let’s explore some of the possible motivators.

EV is safer

One possible motivation is simply to offer a safer experience. With EV SSLyour Website visitors get more information to distinguish real from fake websites, which undermines the success of social engineering attacks. In an ideal world that would be all motivation, every EV would have to use SSL. For this reason, many companies use EV. Sometimes it’s just because they believe that protecting website visitors is good customer service, and that’s reason enough. Sometimes it’s because they themselves are potential victims of spear phishing attacks that target their own employees, suppliers, suppliers, or other ecosystem partners. Sometimes it is because they are trying to minimize the cost of taking over the account or other service issues due to attacks. Online financial services, ranging from payments to banks to credit cards and securities transactions, are damn well suited for the use of EV SSL. This is because they may be on guard to heal customers if they fall victim to this type of attack. Therefore, these online financial services are directly motivated by the income statement to minimize this problem class. Unfortunately, it is not an ideal world. Many online companies do not seem to have resolved the question of how protecting customers from criminals is worthwhile. Retailers, social media sites, and many other online businesses are not experiencing an acute impact of phishing victimization on a customer. Stolen credit card information is used for all sorts of purposes and may never be returned to the merchant who originally approved the theft. And while the customer is bothered by credit card theft, it is very unlikely that this retailer will ever be to blame. The same is true for many other websites where the primary phishing activity is to steal credentials, not to take over that particular account, but to check other more valuable websites (especially in the financial sector) for similar name / password combinations. If on a sloppy website your credentials are stolen by a phisher who uses this information to gain access to your bank account, the website will never be directly affected by the sloppiness. While EV’s security benefits are motivating in their own right, many important phishing targets do not directly benefit from the enhanced security that EV offers. And that creates a gigantic prisoner dilemma on the web. While we would all be better off if all sites used EV, many single sites that skip EV save money and inconvenience without real disadvantages. That is why many do it and we all suffer from it. To achieve broad acceptance of electric vehicles, we therefore need more motivators than just safety.

EV helps with compliance

Another potential motivator for a subset of websites is compliance. Many major compliance standards such as PCI-DSS and HIPAA / HITECH require that websites take measures to protect their customers from the loss of sensitive information such as credit card numbers, PII, PHI and the like. Because EV provides stronger protection against this type of theft than an OV or DV certificate, many security and governance departments are finding that EV is the best way to ensure successful auditability of these standards. It happens that the overlap between organisations that are strongly motivated by compliance and organisations that are strongly motivated by security for its own sake is very large. Financial use cases fall firmly into these two camps, so we don’t add many websites this way. The main takeaway here is that healthcare and pharmaceutical companies have strict HIPAA / HITECH compliance requirements and are better than average users of EV SSL. Again, the footprint of websites motivated to present their authenticated data is far from ubiquitous. Many websites need an additional motivator.

EV increases site transactions and use

The business is extremely pragmatic. Every company site exists with a specific end goal. If the business is an online retailer or SaaS company, the goal is obvious. They are here to sell or deliver goods and services. But every business location has a destination. Otherwise, the company wouldn’t invest the money, employee time and focus to create and maintain it. These goals can be:

  • Selling goods or services
  • Provision of online services
  • Improved customer service (e.g. activating online checking of your phone or credit card statement)
  • Increased service efficiency (e.g. activating online self-service instead of speaking to a human representative in a telephone bank)
  • New service registrations
  • Lead generation
  • Consumption of advertising material
  • Download assets or applications
  • ‘Stickiness’ for a service, a product or a relationship
  • Market formation for products and brands

For each of these goals, we can calculate the economic value. For example, if you enable superior customer service, you increase customer satisfaction and Net Promoter Scores. This in turn leads to improvements in renewals, increased wallet share and word of mouth. Greater service efficiency allows you to provide the same level of service to the same number of customers at a lower cost. By improving lead generation, the cost per lead can be reduced and sales increased. Increased use of ad-based websites means more ad units can be sold. And so on. In each case, improving performance against this goal is directly beneficial to the organisation. And the security indicator of the green address bar, including the company name in green, must do just that in any case. Improving user confidence will increase website usage and propensity to engage in transactions, which in turn drives all of the above objectives. While the ROI calculation for each of these use cases is different, because the effort and budget required to obtain EV SSL certificates is trivially small, the expected return on investment (ROI) is enormous. For just a few hundred dollars a year and an extra day or two waiting for a certificate to be issued, any measurable change in online business KPIs is more than justified. In jedem Fall ist eine Verbesserung der Leistung in Bezug auf dieses Ziel für das Unternehmen direkt vorteilhaft. Und der Sicherheitsindikator der grünen Adressleiste, einschließlich des Firmennamens in Grün, muss in jedem Fall genau das tun. Durch die Verbesserung des Nutzervertrauens wird die Nutzung der Website und die Neigung zur Teilnahme an Transaktionen erhöht, was wiederum alle oben genannten Ziele bestimmt. Während die ROI-Berechnung für jeden dieser Anwendungsfälle unterschiedlich ist, weil der Aufwand und das Budget für das Erhalten von EV-SSL-Zertifikaten trivial gering sind, ist der erwartete Return on Investment (ROI) enorm. Für nur ein paar hundert Dollar pro Jahr und ein oder zwei zusätzliche Tage, die auf die Ausstellung eines Zertifikats warten, ist jede messbare Veränderung der Online-Geschäfts-KPIs mehr als gerechtfertigt.

EV improves the online brand presence

A slightly more subtle point in terms of increased website usage is the impression a website leaves on its visitors. By displaying a visible security indicator, a company is signalling several important facts to its site visitors. These facts include:

  • This company invests in first-class security.
  • This business takes care of the wellbeing of customers.
  • This business is operational.
  • Business with this company is pleasant and carefree.

Signalling these messages during an online experience has a halo effect on the overall perception of the brand. Given the very large investment many organisations make in creating these brand impressions, EV is again an extremely simple and cost-effective way to contribute to these efforts.

These advantages depend on the conventions of the browser interface

These advantages depend on the conventions of the browser interface

  • To combat phishing, an EV certificate must visually distinguish real websites from fake ones.
  • In order to contribute to the compliance requirements, EV certificates must be recognizable as such so that they can combat phishing.
  • To increase transactions and use of the website, EV certificates must be visible to users in a way that conforms to the conventions of a safer experience.
  • In order to contribute to a positive brand impression, EV certificates have to give the users a positive signal.

Browser manufacturers have the ability to increase the effectiveness of EV by ensuring that the difference between EV and non-EV certificates is clear and that company names and other identity information are easily recognizable to the user. Or browsers can reduce or hide the information about EV certificates and benefit from these advantages. To improve security for users and the Internet as a whole, browser manufacturers must choose the first route and help users protect themselves from online counterfeiting of the sites they trust.

SMIME-1

Why the automated S/MIME issuance pays off twice

Companies in all industries rely on email as an essential communication method that helps customers, customers, employees, partners, providers and more interact. Since private and confidential information is sent via email every day, it should come as no surprise that email encryption tools such as S / MIME have become an important part of corporate security.

The use of encryption and digital signatures remains the best way to ensure the integrity and privacy of email communications. Using tools such as S/MIME, the user can check whether the email is actually from the supposed sender, whether the content of the email – or the attachments it contains – has been changed in any way, and can proceed with the certainty that nobody someone other than the intended recipient reacts to this and may have read the email.

These features are important weapons in the fight against fraud through commercial email compromises. Digital certificates also play a crucial role in helping companies meet legal requirements such as the to comply with strict GDPR requirements worldwide that organizations operating in Europe must meet. SMIME offers an elegant solution: By using SMIME for this type of encryption, both sender and recipient can use their existing SMIME-enabled email applications, while other solutions are likely to use a new, separate email Mail application or its use would require a cumbersome web portal where the recipient would have to perform the risky operation to click a link in an email. S/MIME stands for email security made easy. S/MIME ensures that the email is encrypted on the sender and recipient mail servers. An important level of defense, especially if the mail server is in the cloud.

Without automation, the user has to configure sophisticated email applications like the Outlook shown here.

The costs that arise if the provision is NOT automated

Automatic certificate management is not a requirement for S / MIME, but is strongly recommended. If you allow your employees to share the burden of certificate management, you may save some money in the short term, but problems will almost certainly arise in the long run. A Secorio customer described the experience of not using automatic certificate management:

“We deployed the secure email certificate to our end users four months ago and [were] faced with deployment difficulties. Although we have created step-by-step instructions for end users to download and install their own certificate, numerous support requests have been received to complete the setup. “

The difficulties associated with manual certificate management prompted this customer to zero touch management Solution, which finally included automatic certificate management and installation in your solution. In most cases, setting up this automation costs less than a single support call – and saves employees valuable time because they no longer have to manually manage their S / MIME certificates.

The cost of lost employee productivity is also noteworthy. For example, if a junior lawyer in a law firm (who charges clients EUR 200 per hour) spends at least half an hour installing a digital certificate on their iPhone and the support (pays EUR 100 per hour) does the same Amount needed To fix an incomplete or confused installation, the company spent EUR 270 just providing a digital certificate – more than five times the cost of a zero-touch S / MIME certificate that could be automatically provided to the user.

Avoid painful problems

Without automation, the risk of human error exposure increases dramatically. How does automation help? Below are some of the most common problems caused by manual certificate management. Most (if not all) problems can be solved with effective automation:

    • Failed to publish a new certificate. If a new certificate is not published in the company’s global address list, senders of Outlook and ActiveSync mail applications cannot find the certificate required for the recipient’s encryption. The employee either spends a lot of time trying to figure out how to publish their certificate, or the senders do not use encryption.
    • Error using global address list. If the global address list is not used, employees must send signed emails among themselves so that the sender can extract the recipient’s certificate. This limits the effectiveness, as an encrypted email can only be sent when the recipient has replied to the email. This works until the recipient renews his certificate and the sender has an older, expired certificate. Once the cause of the problem is identified, a new signed email must be sent to everyone the sender wants to communicate with.
    • Problems with the self-service web portal. Without automation, every employee who needs an S/MIME certificate must visit a self-service web portal. There they have to click through 5-10 screens using a shared secret they identify themselves, download the private key and certificate in a PKCS # 12 file and open the file to import the certificate to their desktop. You will then have to manually configure Outlook to use the newly installed certificate.
  • Ineffektiver privater Schlüsselspeicher. Der Mitarbeiter muss seinen privaten Verschlüsselungsschlüssel manuell sichern. Auf diese Weise können E-Mails oder Dateien weiter entschlüsselt werden, falls der private Schlüssel versehentlich zerstört wird. Daraus können zwei Arten von Support-Problemen resultieren:
    • The employee forgets to save the key and can no longer access his previous emails if the private key is destroyed.
    • The employee backs up the private key on a USB drive, mixed with other data files. Their private key can then be made available to an attacker who can force the encryption that protects the private key from theft.

Some providers state that they offer a backup of the encryption key. However, the customer has to implement it on site, with additional hidden costs.

    • Problems installing mobile devices. Many employees have problems exporting the private key and certificate from Outlook when setting up a mobile device. You need to transfer the private key and certificate file to your mobile device. Employees then have to import the private key and certificate into the email application, which can be problematic due to the different methods required for different email applications. Once the private key and certificate are installed on the mobile device, many employees have trouble configuring the email application to use the newly installed certificate.
    • Bad renewal management. If the certificate expires in 1-3 years, the employee must renew the certificate for each device before it expires. Otherwise, all e-mail recipients receive a notification that the digital signature is invalid, which interrupts communication. Even worse, the recipients ignore the errors of an expired certificate, making the solution ineffective.
    • Decrypt older emails. When renewing certificates, the emails stored on the mail server must be accessed with different keys. Without automation, employees have to manually check that the entire key history is available. Otherwise they cannot decrypt the older emails. This leads to help desk calls – or worse, some emails related to a lost key cannot be decrypted.

These problems can be frustrating for users and clearly illustrate how ineffective certificate management can negatively impact the security and reliability of a company’s communications.

S/MIME is an important and user-friendly email encryption tool. Adding zero-touch S/MIME makes installing and renewing the many certificates in an organization easier and cheaper than ever.

More information can be found in the Sectigo Zero-Touch Deployment S/MIME- Product Video.

Sectigo_Certificate-Mgmt-10

How your company can simplify compliance with the GDPR

In 2016, the European Union adopted the most effective data protection mandate in decades, replacing an outdated set of guidelines that was last updated in 1995. Since its entry into force in May 2018, the General Data Protection Regulation ( GDPR ) has caused waves worldwide and companies have tried to understand in recent years what this means, how compliance can be ensured and how it can affect their operations.

The GDPR is currently recognized as law across the EU, and companies looking to do business there need a full understanding of what is involved. At its core, the regulation aims to harmonize data protection laws across the region, protecting the data of EU citizens and reshaping the approach to data protection of organizations across the region. Proponents of the GDPR describe it as “the most significant change to data protection regulation in the last 20 years”, noting that it will “fundamentally change the way data is processed across all sectors, from healthcare to banking and beyond”.

This description makes GDPR sound terrifyingly extensive – and in many ways it is. This comprehensive approach to data security means that, in contrast to HIPAA or DFARS , which only affect certain industries, GDPR requirements must be met by any organization that operates within the EU and the European Economic Area. The regulation is far-reaching, its scope is massive.

In other respects, the provisions that are enforced under the GDPR are both simple and straightforward. Similar to the other regulations in the USA, which are in force to a lesser extent, the GDPR only requires data protection “inherently and by default” for all IT business processes in which personal data is used. The regulation stipulates that those responsible for the processing of personal data must take “appropriate technical and organizational measures” to ensure the protection of this data – with considerable penalties for violations of the law.

And make no mistake: the penalties are severe. According to the GDPR, the penalties for loss , the change or the unauthorized disclosure of data amounts to up to 4% of the worldwide annual turnover or EUR 20 million – whichever is higher. This is a big change for every company and underlines the importance of compliance with the GDPR rules.

So what does that mean? Last but not least, this means that email encryption is a very, very good idea. Since the GDPR came into force, the encryption of e-mails with confidential personal data has generally been regarded as best practice for business operations. This should come as no surprise. Emails in Europe have the same vulnerabilities as emails in the US. E-mails that are not encrypted can be read by a number of different parties, including the company’s IT administrator, Internet service providers, and cloud service e-mail providers. For this reason, sending unencrypted email with personal or confidential information from people under the GDPR is likely illegal.

Don’t risk it. Why would you S/MIME certificate technology offers one simple and effective way to encrypt data and thereby authenticate both the sender and the content of an email. Although email certificates are not specifically required in GDPR, S/MIME is the easiest way to ensure that your email communication is still compatible. Emails that are protected by S/MIME remain encrypted from sending to opening so that they cannot be read during transmission. These messages and attachments also remain encrypted while they are stored on mail servers. This adds another layer of security that includes hibernation information.

For companies looking for an easy way to switch their email communications to GDPR compliance, there is no more comprehensive solution than S/MIME. The end-to-end encryption provided by S/MIME offers a simple and user-friendly approach to email security in all industries.

0_0 (1)

SSL certificate’s validity be limited to 1 year by Safari Browser

Apple announced at the 49th CA/Browser Forum on February 19 that it will limit the term of accepted TLS certificates to 1 year (renewals: maximum 398 days) as of September 1st, 2020. Certificates issued on or after that date with validity beyond 398 days will be distrusted in Apple products.

Certificates issued prior to September 1st, 2020 will have the same maximum validity as certificates do today, which is 825 days. Valid two-year certificates will operate correctly for their full duration, even after September 1st, 2020. No action is required for these certificates. Certificates, if being issued after August 31, 2020, will need to issued for 1 year to remain trusted in the Apple platform.

Secorio_SCM_ACME-automatisation

Support of the ACME protocol in the SCM (Certificate Manager)

Limits human error and website downtime while giving companies the ability to configure automation workflows

Despite the increasing use of modern, flexible computer environments such as virtualization, containerization, Internet of Things (IoT) and cloud by companies, a large number of IT administrators continue to provide and manage certificates. old-fashioned techniques that are better suited to the infrastructure of the 1990s than today’s DevOps environments. This “spreadsheet management” leads to inefficiency and the risk of failure or non-compliance due to human error.

To solve this problem, technology partner Sectigo, the world’s largest commercial certification authority and a leading provider of web security solutions, today announced that it supports the ACME protocol for the popular SCM platform. By adding ACME support, Secorio brings the reliability and efficiency of automation to the management of corporate certificates.

Reduce total cost of ownership for certificate management

Up to nine time-consuming steps are required to install an SSL certificate on a server, including signing in, downloading, renewing configuration, and testing. The cost of each installation or renewal is estimated at $ 50 to $ 100 per web. In addition, complexity and costs only increase for web servers that use multiple domains, wildcard certificates, reverse proxies or load balancers.

Each step requires precise management by a web administrator or an employee with technical knowledge to avoid the risk of human error and unexpected downtime, which can be very costly. For example, the mobile operator asked O2 compensation in the millions from Ericsson after 32 million of its customers and other mobile operators around the world stopped using the service. The day-long collapse of network data in December 2018 was due to an expired certificate in the Ericsson technology stack that serves these network operators.

“Manual installation of SSL certificates requires special knowledge, without which the company can risk misconfiguration, a lack of transparency in the installed certificates and the inability to quickly replace certificates due to unplanned events. A web administrator who is more familiar with HTML coding and website creation and less experienced with the Linux shell may find it difficult to complete the required steps or spend a lot of time learning, ”added Kent.

Four ways to automate while maintaining control

Advances in the Secorio Certificate Manager platform address these enterprise-scale challenges by deploying mechanisms to automate the installation and renewal of SSL certificates on servers in traditional data centers or in a DevOps environment, making both deployment and ongoing management complete be automated. This ACME support applies to SSL certificates with extended validation (EV), organization validation (OV) and domain validation (DV).

    • Industry standard ACME protocol – The Automated Certificate Management Environment (ACME) developed by the IETF defines an extensible framework for automating certificate issuance and validation processes so that servers can receive DV, OV and EV SSL certificates without manual user interaction. Over 100 open source ACME clients are available to automate certificate issuance on Apache, IIS, NGINX, F5 BIG-IP, Citrix NetScaler and other popular web servers and network devices. The ACME tools fully automate key generation, domain control verification, certificate generation and server installation. If public certificates are required, the customer can request them directly from Secorio.
    • Proprietary automated method – For Apache, IIS, Tomcat and F5-BIG-IP environments, Secorio provides a client for installation in one place at the customer, which can then communicate with all of the company’s servers. Sectigo Certificate Manager embeds the web server administrator’s credentials for the installation of certificates and the transfer of private keys in these agents.
    • Custom workflows with REST API – Customers can use Secorio REST Install Full API (Representational State Transfer) certificates, allowing for a bespoke workflow, including approvals and other steps. The administrator can request approval for certificate requests from the ACME client and discover, track, run reports, and make manual changes to certificates.
    • Tighter integration with products from third-party  Secorio has integrated into F5 BIG-IP and is working on additional third-party integrations to ensure full automation and workflow management.

More information can be found in the ACME-Automation Video .