LetsEncrypt and email servers
Hi all. I wonder if you can help identify whether my colleague at work is being bullshitted by our IT contractor...The bottom line question is - is it possible to use a free LetsEncrypt SSL certificate with my company's Kerio email server or will we need to pay for an annual certificate?I have used LetsEncrypt with an automatic renewal on a linux webserver, but I don't know if it would be different in this case - a Kerio based email server, sitting on a Mac. If this is possible on this setup too, why are people in the world still paying for premium SSL certificates? I understand that one certificate is as good as the next, so what is the deal?Many thanks!
Submitted September 13, 2017 at 08:04PM by bhison
via reddit http://ift.tt/2wWNIkG
Hi all. I wonder if you can help identify whether my colleague at work is being bullshitted by our IT contractor...The bottom line question is - is it possible to use a free LetsEncrypt SSL certificate with my company's Kerio email server or will we need to pay for an annual certificate?I have used LetsEncrypt with an automatic renewal on a linux webserver, but I don't know if it would be different in this case - a Kerio based email server, sitting on a Mac. If this is possible on this setup too, why are people in the world still paying for premium SSL certificates? I understand that one certificate is as good as the next, so what is the deal?Many thanks!
Submitted September 13, 2017 at 08:04PM by bhison
via reddit http://ift.tt/2wWNIkG
letsencrypt.org
Let's Encrypt - Free SSL/TLS Certificates
Let’s Encrypt is a free, automated, and open certificate authority brought to you by the non-profit Internet Security Research Group (ISRG).
IoT Attack Vector “BlueBorne” Exposes Almost Every Connected Device
http://ift.tt/2jjIolw
Submitted September 13, 2017 at 07:43PM by Hamm3rH3ad
via reddit http://ift.tt/2f69hbv
http://ift.tt/2jjIolw
Submitted September 13, 2017 at 07:43PM by Hamm3rH3ad
via reddit http://ift.tt/2f69hbv
armis
Blueborne • armis
The IoT Attack Vector “BlueBorne” Exposes Almost Every Connected Device General Overview Affected Devices Technical Overview General Overview Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android…
Ransomware "Your Windows is Banned" Muncul Dan Minta Tebusan $50 Bitcoin
http://ift.tt/2h3kqqf
Submitted September 13, 2017 at 07:35PM by khanjadi
via reddit http://ift.tt/2wppOdc
http://ift.tt/2h3kqqf
Submitted September 13, 2017 at 07:35PM by khanjadi
via reddit http://ift.tt/2wppOdc
Mejapraktek
Ransomware "Your Windows is Banned" Muncul Dan Minta Tebusan $50 Bitcoin
Tips, Trik Dan Software Android
Yubikey NFC platform
Is they Yubikey a safe platform, specifically the one with integrated NFC? Is it possible to have the codes on the key taken because of NFC?
Submitted September 13, 2017 at 08:24PM by cancerous_176
via reddit http://ift.tt/2wpzlkB
Is they Yubikey a safe platform, specifically the one with integrated NFC? Is it possible to have the codes on the key taken because of NFC?
Submitted September 13, 2017 at 08:24PM by cancerous_176
via reddit http://ift.tt/2wpzlkB
reddit
Yubikey NFC platform • r/security
Is they Yubikey a safe platform, specifically the one with integrated NFC? Is it possible to have the codes on the key taken because of NFC?
SECUMAIL là gì mà có thể bảo mật email cho bạn?
http://ift.tt/2x1yhXk
Submitted September 13, 2017 at 08:18PM by hangcho123
via reddit http://ift.tt/2wpxa00
http://ift.tt/2x1yhXk
Submitted September 13, 2017 at 08:18PM by hangcho123
via reddit http://ift.tt/2wpxa00
Email Security: Hệ thống email bảo mật đầu tiên tại Việt Nam
SECUMAIL là gì mà có thể bảo mật email cho bạn?
Sự chủ quan của doanh nghiệp Việt Nam trong thời đại bảo mật email đã mở lối cho tin tặc tấn công vào email rất dễ dàng và gây tổn thất vô cùng to lớn
Equifax breach, what about employment verification data?
I haven't read anything concrete regarding the data that belongs to Equifax's employment verification division. If this data was potentially lost in this breach that could make this much worse than originally thought. Imagine the number of employers that have used them for employment verification and I hope they (or anyone else) doesn't have any persistent hooks into Equifax systems or networks.
Submitted September 13, 2017 at 08:54PM by Hamm3rH3ad
via reddit http://ift.tt/2y5H1u4
I haven't read anything concrete regarding the data that belongs to Equifax's employment verification division. If this data was potentially lost in this breach that could make this much worse than originally thought. Imagine the number of employers that have used them for employment verification and I hope they (or anyone else) doesn't have any persistent hooks into Equifax systems or networks.
Submitted September 13, 2017 at 08:54PM by Hamm3rH3ad
via reddit http://ift.tt/2y5H1u4
reddit
Equifax breach, what about employment verification data? • r/security
I haven't read anything concrete regarding the data that belongs to Equifax's employment verification division. If this data was potentially lost...
Email của bạn sẽ được bảo mật toàn diện với SECUMAIL
http://ift.tt/2xy11IL
Submitted September 13, 2017 at 08:46PM by hangcho123
via reddit http://ift.tt/2y5H4WM
http://ift.tt/2xy11IL
Submitted September 13, 2017 at 08:46PM by hangcho123
via reddit http://ift.tt/2y5H4WM
Email Security: Hệ thống email bảo mật đầu tiên tại Việt Nam
Email của bạn sẽ được bảo mật toàn diện với SECUMAIL
Sự phổ biến của email, hàng loạt các vấn đề liên quan đến bảo mật cũng xuất hiện. Theo đó, SECUMAIL ra đời như là giải pháp để giải quyết các vấn đề trên.
CDNs are starting to become a new way of spreading Malware in Brazil
http://ift.tt/2f6veXP
Submitted September 13, 2017 at 08:32PM by majorllama
via reddit http://ift.tt/2eVKZNE
http://ift.tt/2f6veXP
Submitted September 13, 2017 at 08:32PM by majorllama
via reddit http://ift.tt/2eVKZNE
WeLiveSecurity
CDNs are starting to become a new way of spreading Malware in Brazil
Services like Netflix use content delivery networks (CDNs) to maximize bandwidth usage. However, the CDNs might be finding a new way of spreading malware.
Backdoor found in WordPress plugin with 200K installs
http://ift.tt/2jiM6Mj
Submitted September 13, 2017 at 05:45PM by campuscodi
via reddit http://ift.tt/2jo2fjE
http://ift.tt/2jiM6Mj
Submitted September 13, 2017 at 05:45PM by campuscodi
via reddit http://ift.tt/2jo2fjE
They're Trying to Hack Your PayPal Account: Analyzing a Real Phishing Email
http://ift.tt/2xxMj4t
Submitted September 13, 2017 at 10:54PM by sh_tomer
via reddit http://ift.tt/2y6mFkw
http://ift.tt/2xxMj4t
Submitted September 13, 2017 at 10:54PM by sh_tomer
via reddit http://ift.tt/2y6mFkw
dzone.com
They're Trying to Hack Your Account: Analyzing a Real Phishing Email - DZone Security
A DZone MVB breaks down a suspicious email he received to demonstrate how phishing attempts work, and certain key elements of phishing attempts to look out for.
Army Wargames Against Russia
http://ift.tt/2xyVHVO
Submitted September 13, 2017 at 10:49PM by rec0d3
via reddit http://ift.tt/2y6mGVC
http://ift.tt/2xyVHVO
Submitted September 13, 2017 at 10:49PM by rec0d3
via reddit http://ift.tt/2y6mGVC
WarriorScout.com
Army Wargames Russian Electronic Warfare & Cyber Attacks
Army soldiers tried to detect and fend off simulated Russian electronic warfare and cyberattacks in a Cyber Quest exercise aimed at preparing the service for
How do you share your secrets after death or inability?
Hi,so i am trying to set up a method(without relying on some proprietary service) to give an individual or group of people access to my passwords, accounts etc. after i die or am somehow not able to remember anything.I looked into Shamir's Secret Sharing, but my problem is that i would like to keep my side of the equation able to update the information i share. Let's say i change the master password of my favorite password sharing app, or change my Bitcoin seed phrase and so on. Has anybody implemented a system in which relatives or significant others can access this information by giving them an envelope or similar? Also, a somewhat automated way of updating the information i want to share would be perfect. I thought about creating an encrypted archive or text and sharing the password via envelopes using SSSS. But then a problem is how people would be able to restore the phrase in 1000 years, without having the tools we use today or advanced knowledge in computers. I would like to leave simple instructions in a sealed envelope, requiring multiple share holders to group in order to gain access.I think this is a situation in which a lot of people find themselves and i would appreciate any feedback!
Submitted September 13, 2017 at 11:21PM by daywalkerdha
via reddit http://ift.tt/2w9nVWM
Hi,so i am trying to set up a method(without relying on some proprietary service) to give an individual or group of people access to my passwords, accounts etc. after i die or am somehow not able to remember anything.I looked into Shamir's Secret Sharing, but my problem is that i would like to keep my side of the equation able to update the information i share. Let's say i change the master password of my favorite password sharing app, or change my Bitcoin seed phrase and so on. Has anybody implemented a system in which relatives or significant others can access this information by giving them an envelope or similar? Also, a somewhat automated way of updating the information i want to share would be perfect. I thought about creating an encrypted archive or text and sharing the password via envelopes using SSSS. But then a problem is how people would be able to restore the phrase in 1000 years, without having the tools we use today or advanced knowledge in computers. I would like to leave simple instructions in a sealed envelope, requiring multiple share holders to group in order to gain access.I think this is a situation in which a lot of people find themselves and i would appreciate any feedback!
Submitted September 13, 2017 at 11:21PM by daywalkerdha
via reddit http://ift.tt/2w9nVWM
reddit
How do you share your secrets after death or inability? • r/security
Hi, so i am trying to set up a method(without relying on some proprietary service) to give an individual or group of people access to my...
What Computer Security Experts Wish You Knew: The Top Experts Speak
http://ift.tt/2wozJzv
Submitted September 13, 2017 at 11:04PM by InfoSecCrazy
via reddit http://ift.tt/2fi2A2P
http://ift.tt/2wozJzv
Submitted September 13, 2017 at 11:04PM by InfoSecCrazy
via reddit http://ift.tt/2fi2A2P
itsecuritycentral.teramind.co
What Computer Security Experts Wish You Knew: The Top Experts Speak | IT Security Central
When it comes to keeping our information secure, many of us seem to be at a loss. With technology rapidly changing like it does, it's difficult to stay aware of
U.S. to ban use of Kaspersky software in federal agencies amid concerns of Russian espionage
http://wapo.st/2vUhrXr
Submitted September 13, 2017 at 11:03PM by buildops
via reddit http://ift.tt/2xZZfMZ
http://wapo.st/2vUhrXr
Submitted September 13, 2017 at 11:03PM by buildops
via reddit http://ift.tt/2xZZfMZ
Washington Post
U.S. bans use of Kaspersky software in federal agencies amid concerns of Russian espionage
The Homeland Security department issued a directive Wednesday barring use of the Russian company’s product.
socksmon: a TCP interception proxy using BURP or ZAP
http://ift.tt/2f5OnJp
Submitted September 13, 2017 at 11:56PM by mrschyte
via reddit http://ift.tt/2y5YbId
http://ift.tt/2f5OnJp
Submitted September 13, 2017 at 11:56PM by mrschyte
via reddit http://ift.tt/2y5YbId
GitHub
mrschyte/socksmon
socksmon - Monitor arbitrary TCP traffic using your HTTP interception proxy of choice
The only safe email is text-only email
http://ift.tt/2w0OQ79
Submitted September 14, 2017 at 12:50AM by speckz
via reddit http://ift.tt/2f6g9pg
http://ift.tt/2w0OQ79
Submitted September 14, 2017 at 12:50AM by speckz
via reddit http://ift.tt/2f6g9pg
The Conversation
The only safe email is text-only email
It's impossible to be certain of safety while using Gmail, Yahoo mail and other web-based email systems. The best solution is a radical one: It's time to return to plain, text-only email.
Exploiting CVE-2017-8759: SOAP WSDL Parser Code Injection by MDSec ActiveBreach
http://ift.tt/2x1RYyw
Submitted September 14, 2017 at 01:10AM by mdsec
via reddit http://ift.tt/2wpVejw
http://ift.tt/2x1RYyw
Submitted September 14, 2017 at 01:10AM by mdsec
via reddit http://ift.tt/2wpVejw
www.mdsec.co.uk
Exploiting CVE-2017-8759: SOAP WSDL Parser Code Injection – MDSec
A walk through on how to exploit CVE-2017-8759
1.65 Million Attacks: Kaspersky Reveals New Data on Crypto Mining Malware
http://ift.tt/2h1RtPe
Submitted September 14, 2017 at 01:03AM by lazec
via reddit http://ift.tt/2x1SIni
http://ift.tt/2h1RtPe
Submitted September 14, 2017 at 01:03AM by lazec
via reddit http://ift.tt/2x1SIni
CoinDesk
1.65 Million Attacks: Kaspersky Reveals New Data on Crypto Mining Malware - CoinDesk
Kaspersky Labs revealed it protected more than 1.65 million computers from cryptocurrency mining malware in a report on Tuesday.
FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode
http://ift.tt/2f5Ab32
Submitted September 14, 2017 at 12:47AM by FireFart
via reddit http://ift.tt/2jq2NWp
http://ift.tt/2f5Ab32
Submitted September 14, 2017 at 12:47AM by FireFart
via reddit http://ift.tt/2jq2NWp
Insinuator.net
FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode
We recently identified a security issue in FireEye AX 5400, that also affected other products. We responsibly disclosed the bug to FireEye and a fix that addresses the issue has been released with version 7.7.7. The fix was also merged into the common core…
Equifax pulls their vulnerable mobile application from app stores
http://ift.tt/2h3Kl1k
Submitted September 14, 2017 at 01:54AM by patcheudor
via reddit http://ift.tt/2wXHnVS
http://ift.tt/2h3Kl1k
Submitted September 14, 2017 at 01:54AM by patcheudor
via reddit http://ift.tt/2wXHnVS
The Man Behind Plugin Spam: Mason Soiza
http://ift.tt/2wpPfv0
Submitted September 14, 2017 at 01:51AM by speckz
via reddit http://ift.tt/2h4ATun
http://ift.tt/2wpPfv0
Submitted September 14, 2017 at 01:51AM by speckz
via reddit http://ift.tt/2h4ATun
Wordfence
The Man Behind Plugin Spam: Mason Soiza
This is a follow-up to our story noscriptd “Display Widgets Plugin Includes Malicious Code to Publish Spam on WP Sites“. In this post, we explore who is behind the purchase and corruption of the Display Widgets plugin and at least two other popular WordPress…