kuketzblog, to android German
@kuketzblog@social.tchncs.de avatar

Android: Der Beitrag stellt die Vorbereitung des Testgeräts sowie Werkzeuge (Frida, Magisk) zur Analyse des Datensendeverhaltens von Apps vor. Reinschauen! ✌️ 👇

https://www.kuketz-blog.de/in-den-datenstrom-eintauchen-ein-werkzeugkasten-fuer-analysten-von-android-apps/

#share #android #frida #objection #tweasel #pirogue #tls #ssl #CertificatePinning #mitmproxy #proxy #intercepting #analyse #datenschutz #sicherheit #privacy #security #dsgvo

james, to hosting
@james@jamesgallagher.social avatar

Where do people get their SSL certs at reasonable prices these days? I'd like to move some (mostly Wordpress) sites to shared hosting at Blacknight, from a VPS so Let's Encrypt would no longer be suitable

pitrh, to security
@pitrh@mastodon.social avatar
grizeldi, to webdev Slovenian
@grizeldi@mastodon.gamedev.place avatar

What's the purpose of certificates expiring again? From my limited perspective it doesn't serve much else than adding unnecessary work for sysadmins, so I'd love to know if there's a legit reason for it.

metabrainz, to random
@metabrainz@mastodon.social avatar

Yet another tale of shitty companies ripping off little charities. This time it’s SSL*com who have enriched themselves.

If you are with SSL*com for your SSL/TLS certificates:

  1. Check your invoices for extra charges
  2. Swap over to the nonprofit Let’s Encrypt!


https://blog.metabrainz.org/2024/04/23/ssl-com-is-evil-and-deceptive-dont-do-business-with-ssl-com

GrapheneOS, to random
@GrapheneOS@grapheneos.social avatar

SSL Labs (https://www.ssllabs.com/ssltest) from Qualys used to be a useful HTTPS testing tool. However, it hasn't received significant updates since 2019 and is now holding back HTTPS security. The biggest issue is that many of the tests don't support TLSv1.3 so it penalizes disabling legacy TLSv1.2.

dboehmer,

@GrapheneOS Good to know. Thanks for the heads up! 👍

Can't we have a version of SSLlabs? Sounds like generally desirable for the whole industry and likely to receive Merge Requests once established. I think many updates would be mere changes of opinions about recommended settings.

fell, to SmartHome
@fell@ma.fellr.net avatar

I stopped messing with client certificates and went back to good old HTTP basic authentication for my little digital light switch panel.

It's a shame nobody cares about TLS client certificates. With a bit more effort we could've gotten rid of passwords a long time ago.

I wish there was something like SSH keys for the web.

Yeah I know, Passkeys are a thing... but also not really.

jbr_IC, to random German
@jbr_IC@social.tchncs.de avatar

Für Leute, die eigene Server betreiben und mal Klarheit bei der vorliegenden benötigen, können es hiermit testen.

testssl.sh is a free command line tool which checks a server's service on any port for the support of TLS/SSL , protocols as well as recent cryptographic flaws and more.

https://testssl.sh/

davemark, to science
@davemark@mastodon.social avatar

"Cloudflare translates photos of 100 lava lamps into random data for use in SSL encryption."

Wait, what? This true?

Apparently so. @cloudflare uses a clever camera rig pointed at a wall of lava lamps to generate random numbers.

WOW.

https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/

hunleyd, to PostgreSQL
@hunleyd@fosstodon.org avatar

OnGres | The mode behavior in authentication-hooked extensions https://www.ongres.com/blog/ssl_mode_behavior_in_authentication_hooked_extensions/

czach, to fediverse Polish
@czach@pol.social avatar

No dobra... Jest tu jakiś cwaniak?
Próbuję ogarnąć WordPressa/ActivityPub na własnym serwerze. Nawet to działa, ale gdy chcę z tego konta (pol.social) dać follow takiego konta domowego to wywala:

"503 Remote SSL certificate could not be verified”

No rozumiem. Sprawdzam swoją stronę SSL Checker i mam:

"The certificate is not trusted in all web browsers. You may need to install an Intermediate/chain certificate to link it to a trusted root certificate. Learn more about this error. The fastest way to fix this problem is to contact your SSL provider.”

Certyfikat SSL mam (działający i zainstalowany) z home.pl ale brakuje tego co wyżej „chain certificate”. Home.pl tego nie dostarcza i… jak to ogarnąć samemu? Bo jakoś utknąłem.

wyri, to Rabbits
@wyri@haxim.us avatar

Getting close to a full green running fully on @reactphp. There is one / test left to resolve before this will become the base for 0.6.x.

poppastring, to random
@poppastring@dotnet.social avatar

I was late renewing my site cert for Lets' Encrypt and I am now inexplicably getting a rate limit warning when trying to renew.

I was late, I never tried to renew, so I am really confused by the error.

ainmosni, (edited ) to random
@ainmosni@berlin.social avatar

Do you, or any place you work with, still pay for ?

Boosts appreciated for reach.

chris, to webhosting
@chris@mstdn.chrisalemany.ca avatar

Any Firefox website Wizards out there? Even though my website has a verified and valid (LetsEncrypt) SSL certificate, Firefox is reporting that "Parts of the webpage are not encrypted”.

I can't find any other information on why this is occuring, I do have a couple iframes in the page (alberniweather.ca) and lots of images including some that are hosted on Google cloud.

Any help is appreciated.

eosinopteryx, to tech
@eosinopteryx@mastodon.world avatar

Shakespeare once said, 'An SSL error has occurred and a secure connection to the server cannot be made.' 😂

larsmb, to security
@larsmb@mastodon.online avatar

If your software supports TLS/SSL but not client certificates, your software does not support TLS/SSL.

Thanks for coming to my TED talk.

danilo, to random
@danilo@hachyderm.io avatar

Is there a project or something so I can give all my local servers working certificates that don't freak out my browser without exposing everything to the internet AND WITHOUT HAVING TO GET CISCO CERTIFIED or whatever?

servers:

  • Home Assistant
  • Ubiquiti router accessed via its .local domain
  • Synology NAS

Each of these is on distinct hardware and while each has their own solutions with varying flexibility, I'd like something generalizable to all based on my "no internet exposure" need

DS_Stiftung, to baking German
@DS_Stiftung@social.bund.de avatar

Neues Audit-Tool 🤖 des für -Behörden sowie für Verantwortliche und Auftragsverarbeiter, die ihre eigene Website testen wollen:
👉 https://edpb.europa.eu/news/news/2024/edpb-launches-website-auditing-tool_en

Das Tool basiert auf Chrome und untersucht u. a. , , Datenverkehr und -Pixel (). Ob eine Website gesetzeskonform ist oder nicht, entscheiden die testenden Sachbearbeiter*innen.

@lfdi @BayLfD @BlnBDI @HBDI @lfdi_rlp @sdtb
@dsk @bfdi

chris, to web
@chris@mstdn.chrisalemany.ca avatar

Random web host question: Can you not use a proper signed (Let's Encrypt) SSL certificate on a IP address based website?

Schrank, to random
@Schrank@phpc.social avatar

Can someone explain to me what’s wrong here and how to fix it? Because my Safari is not complaining 🤔

ovid, to ai
@ovid@fosstodon.org avatar

In part to protect US superiority in , the US has restricted high-end GPUs from being sold in certain countries, such as China.

As a result, available NVidia GPUs for China aren't much better than what Huawei can offer, leaving China and other countries with little choice but to shift billions of dollars from NVidia to Huawei.

The Biden Administration has, through good intentions, unexpectedly given a massive subsidy to Chinese companies.

(China's still smuggling in NVidia, though)

mjgardner, (edited )
@mjgardner@social.sdf.org avatar

@ovid Similar stupid situation from the mid-1990s: Domestically-developed web browsers such as had to ship a weaker "international" version because of US software export rules. They used a drastically reduced key length (e.g., to “protect" credit card info) which could be decrypted in a matter of days by a single PC.

To make matters worse, even US users mostly ended up with the weak version since it was more of a hassle to get the full-strength download.

governa, to random
@governa@fosstodon.org avatar

11 Best Free Certificate Providers in 2024

https://www.tecmint.com/best-ssl-certificate-authorities/

todd_a_jacobs, to iOS
@todd_a_jacobs@ruby.social avatar

This is more of a security question, but I currently know way more people on ruby.social than infosec.exchange. I want to use a #Yubikey for #SMIME or #GPG signing on #iOS & #iPadOS, but can't find:

  1. Any documentation about how to integrate it with Apple Mail.

  2. Anyplace that offers #x509 certificates for S/MIME at zero or minimal cost the way @letsencrypt offers free #SSL certs.

Self-signed S/MIME certs are a non-starter, and there are no full-featured #OpenPGP apps on iOS. Suggestions?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • magazineikmin
  • Youngstown
  • khanakhh
  • ngwrru68w68
  • slotface
  • ethstaker
  • mdbf
  • everett
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • cisconetworking
  • rosin
  • JUstTest
  • Durango
  • GTA5RPClips
  • anitta
  • tester
  • tacticalgear
  • InstantRegret
  • normalnudes
  • osvaldo12
  • cubers
  • provamag3
  • modclub
  • Leos
  • lostlight
  • All magazines