Have you heard that two years after promising to report all HTTP-based web pages as insecure, Mozilla is finally about to deliver? Soon, whenever you visit one of the shrinking number of sites that doesn’t use a security certificate, the Firefox browser will warn you. . Firefox 70 will ship in October. The change is an attempt to crack down on sites that don’t secure their communications. Insecure browsers use the hypertext transfer protocol (HTTP), which sends data in clear text. HTTPS sites are more secure because they use Transport Layer Security (TLS), which establishes an encrypted link between the browser and the Web server before any HTTP requests are sent. The link for this article located at Naked Security is no longer available. . Chrome 80 will implement stricter cookie policies, bolstering user privacy across the web.. Firefox Update, HTTPS Enforcement, Secure Communications, TLS Implementation. . Brittany Day
Unless you haven't been on the net for a year, you know Transport Layer Security/Secure Socket Layer (TLS/SSL) software, such as OpenSSL, have had numerous serious security problems. Now, Amazon, is introducing a new TLS implementation: "Signal to noise," s2n.. Stephen Schmidt, Amazon's VP of security engineering, said that Amazon, the number one online retailer in the Americas, uses strong encryption not just on its eponymous sales site, but on its cloud services as well. The multiple OpenSSL problems, such as Heartbleed, Freak, and Logjam, have led to "time-consuming operational events, such as software upgrades and certificate rotations." The link for this article located at ZDNet Security is no longer available. . Amazon's latest TLS solution, s2n, bolsters security measures by resolving vulnerabilities found in current systems such as OpenSSL.. TLS Implementation, Amazon s2n, Open Source, Security Engineering. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.