Tag Archive for: microsoft

Hoping to avert “collision” with disaster, Microsoft retires SHA1

udono

Microsoft is retiring two widely used cryptographic technologies that are growing increasingly vulnerable to attacks that seemed unlikely just a decade ago.

The company’s software will stop recognizing the validity of digital certificates that use the SHA1 cryptographic algorithm after 2016, officials said on Tuesday. SHA1 is widely used to underpin secure socket layer (SSL) and transport layer security (TLS) certificates that authenticate websites and encrypt traffic passing between their servers and end users. SHA1-based certificates are also used to digitally verify that specific software applications are legitimate and not imposter programs or programs that have been tampered with to include hidden backdoors.

The move comes as hardware improvements and research breakthroughs have made SHA1 and several other cryptographic hashing algorithms more susceptible to so-called collision attacks. Collisions occur when two distinct plaintext “messages” produce an identical hash or “digest.” The security of an algorithm rests on it producing unique hashes for each plaintext string or file. The growing ease of producing collisions makes it possible for attackers to create digital forgeries that completely undermine the security of systems that rely on the weak algorithms.

Read 7 remaining paragraphs | Comments


    




Ars Technica » Technology Lab

Microsoft Patch Tuesday – three critical updates coming, but no TIFF zero-day fix yet

November’s patch Tuesday is coming up this week, and Microsoft’s usual “announcement that doesn’t say an awful lot” is out to help us prepare. What we do know is that the latest TIFF image zero-day vulnerability *isn’t* fixed yet…
Naked Security – Sophos

Microsoft, Facebook unite for Internet Bug Bounty program – CNET


Times of India

Microsoft, Facebook unite for Internet Bug Bounty program
CNET
"If the public is demonstrably safer as a result of your contribution to internet security, we'd like to be the first to recognize your work and say 'thanks' by sending some cash to you or your favorite non-profit," the site promises. The bounty varies
Rivals Microsoft, Google, FB team up for internet securityTimes of India
Contest To Debug the InternetCIO Today
Microsoft and Facebook team up to offer Internet Bug BountyITProPortal

all 45 news articles »

“internet security” – read more

Microsoft warns of zero-day attack, graphics vulnerability exploited through Word

Do you still have images enabled in Outlook? If so, then right now is a great time to disable pictures since there’s a new Microsoft zero-day vulnerability.
Ms. Smith’s blog