Showing posts with label TLS. Show all posts
Showing posts with label TLS. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Sunday, December 8, 2019

Google extends its Android TLS adoption program; covers 80% apps by default

Google announced this week that 80 percent of Android apps are encrypting traffic by default. The percentage is even greater for apps targeting Android 9 and higher, with 90 percent of them encrypting traffic by default.

Android is committed to keeping users, their devices, and their data safe. One of the ways that Google is keeping data safe is by protecting network traffic that enters or leaves an Android device with Transport Layer Security (TLS). 


Android 7 (API level 24) introduced the Network Security Configuration in 2016, allowing app developers to configure the network security policy for their app through a declarative configuration file. To ensure apps are safe, apps targeting Android 9 (API level 28) or higher automatically have a policy set by default that prevents unencrypted traffic for every domain.

The Network Security Configuration feature lets apps customize their network security settings in a safe, declarative configuration file without modifying app code. These settings can be configured for specific domains and for a specific app. 


This feature can customize which Certificate Authorities (CA) are trusted for an app's secure connections. For example, trusting particular self-signed certificates or restricting the set of public CAs that the app trusts. It also safely debugs secure connections in an app without added risk to the installed base; protects apps from accidental usage of cleartext traffic; and restricts an app's secure connection to particular certificates.

Since Nov. 1 2019, all app (updates as well as all new apps on Google Play) must target at least Android 9. As a result, we expect these numbers to continue improving. Network traffic from these apps is secure by default and any use of unencrypted connections is the result of an explicit choice by the developer.


The latest releases of Android Studio and Google Play’s pre-launch report warn developers when their app includes a potentially insecure Network Security Configuration (for example, when they allow unencrypted traffic for all domains or when they accept user provided certificates outside of debug mode). 

This encourages the adoption of HTTPS across the Android ecosystem and ensures that developers are aware of their security configuration.

Saturday, November 9, 2019

StoneFly Smart Cloud Gateway improves efficiency, scalability for IT systems; allows transfer of data to the cloud of choice

StoneFly Smart Cloud Gateway delivers enhanced performance and scalability that gives enterprises the power to configure storage, backup, disaster recovery and archival options in the cloud of their choice by integrating StoneFly Smart Cloud Gateway with their existing infrastructure. 

The Smart cloud gateway is purpose-built to support enterprise-scale workloads without compromising performance and data availability. StoneFly Smart cloud gateway makes data transfers simple, hassle-free and easy for IT administrators.


Being an eighth generation product, StoneFly Smart Cloud gateway has been developed in accordance with user feedback. The appliance classifies data into tiers according to user-defined policies. Users can choose to move data from on-premises to cloud storage tiers like Azure Cool blob, AWS S3-IA or Azure Archival Blob. This automated process reduces cost of data retention and simplifies data management for IT administrators.

StoneFly smart cloud gateway appliance is a purpose-built plug and play infrastructure. The gateway appliance can effortlessly move hotdata to high performance storage tiers, cold data to lower-cost, high capacity drives and older data to archival data tiers for exceptional application performance and reduced TCO (Total Cost of Ownership) of storage.

Headquartered in the Silicon Valley (Hayward) California, StoneFly was founded to deliver upon the vision of simple and affordable enterprise-class products. Purpose-built, optimized, fully security hardened and tested enterprise-class products, StoneFly provides physical, virtual, cloud, software as a service (SaaS), consulting, enterprise managed services, cloud migration services, public/private cloud infrastructure, backup, disaster recovery (DR), cloud file/sync collaboration and office in the cloud.


With constant threats like ransomware, power outages and hardware failure targeting business data, it’s important that businesses have reliable data protection strategies setup. With StoneFly cloud storage gateway, businesses can setup the 3-2-1 rule of data protection, creating copies of their backup data in the cloud. This creates an additional layer of recoverability and enables IT administrators to initiate data recovery from anywhere, anytime.

Last December, StoneFly Smart Cloud Gateway added backup and archiving to its capabilities, thus enabling the service that connects on-premise appliance with cloud-based storage. Users can adopt the Smart Cloud Gateway to store data in Microsoft Azure Cloud, Amazon AWS, any S3 compatible cloud or any other public or private cloud for scalable and cost-effective storage.

Using standard backup software and the Smart Cloud Gateway, consumers can write backups to the cloud and store data durably. This enables both long-term data retention for compliance and recovery into the cloud, locally or other site on-premises.

With the Smart Cloud Gateway, clients can expand on-premise storage into the cloud without having to physically buy additional disks to expand on-premise storage. It works with existing applications whether it is a backup application, a line of business application or file server. The Smart Gateway works with all those types of scenarios and provides a low latency access to users/customers.


StoneFly cloud storage gateway protects important business data using SSL/TLS tunneling and AES 256-bit encryption. This prevents malicious software from gaining access to the data in transit. Businesses can choose to encrypt data before transit as well and then decrypt using secure decryption key on the receiving end. It also leverages snapshot technology to create snapshot images that deliver data protection from ransomware and data loss, while going back in time and quickly recovering in the event of a ransomware attack, accidental and malicious deletion or similar disaster.

StoneFly cloud storage gateway can transfer from terabytes (TBs) to petabytes (PBs) of data. With StoneFly’s technology, the cloud gateway facilitates data transfers for enterprise-scale workloads without affecting the outbound network. With a simple to use interface, users can easily setup data transfers from on-premises to cloud or cloud to cloud. The cloud storage gateway does not require complex setup and deployment procedures. It’s easy to setup and can be deployed within minutes.

Saturday, November 2, 2019

Fortinet’s FortiGate 60F sets new benchmark for security compute ratings; boosts performance for integrated security and SD-WAN

Fortinet announced the FortiGate 60F Next-Generation Firewall, its latest desktop secure SD-WAN appliance. With over 1.5 million units sold worldwide, the FortiGate 60 series is the best-selling next-generation firewall and now includes Fortinet’s purpose-built system on a chip 4 (SOC4) security processor to achieve the highest Security Compute Ratings in the industry to support customers’ WAN edge transformation.

Digital innovation and rapid cloud adoption is changing the face of today’s business and has created significant challenges for organizations, such as poor user experience due to network bandwidth constraints and increased security risks with branches connected to the internet. 



Software-defined wide area networks (SD-WANs) have emerged as the favored solution to solve these issues while also reducing the costs associated with MPLS connections. 

However, not all SD-WAN solutions have risen to the requirements of existing WAN edge. Many SD-WAN solutions on the market are incomplete and do not adequately provide the right performance, visibility, or security to ensure a secure connection and high quality of user experience.

To continue its focus on supporting enterprises’ WAN edge transformation and delivering Secure SD-WAN, Fortinet is announcing the latest next-generation firewall to include its patented SOC4 security processor - the FortiGate 60F. 


FortiGate 60F now consolidates SD-WAN, advanced routing, and advanced security capabilities into a single appliance that enables network leaders to deploy Secure SD-WAN, while reducing complexity by consolidating point products into a single offering. This allows high performance and improved user experience at an optimal total cost of ownership (TCO).
 
To help customers maintain high quality user experience for their business critical traffic (be it SaaS, multi-cloud, or unified communications), FortiGate 60F delivers ideal application steering, giving visibility to all traffic (even if encrypted) without impacting performance and ensuring all critical applications are routed to their best path.
 
FortiGate 60F leverages Security-Driven Networking principals – powered by Fortinet’s patented SOC4 security processor – to deliver the fastest deep inspection of SSL/TLS encrypted traffic (including the industry’s first support for TLS 1.3) at 750Mbps, 11 times greater than the industry average. 

The FortiGate 60F offers comprehensive threat prevention with IPS, application control, and anti-malware at 700Mbps, four times greater than the industry average, to help customers protect their network without impacting performance.


Fortinet security processors radically increase the performance, scalability, and value of Fortinet solutions while greatly improving user experience and shrinking space and power requirements. Security Compute Rating is a benchmark that compares the performance of Fortinet’s purpose-built ASIC-based next-generation firewall appliance to other NGFW and SD-WAN vendors in that same price range that utilize generic CPUs for networking and security capabilities. 

“We hear from an increasing number of customers who are struggling to achieve the required level of user experience, visibility, and security at their WAN edge to support key business applications,” said John Maddison, EVP of Products and CMO at Fortinet. “With today’s introduction of the FortiGate 60F powered by our latest security processor, Fortinet continues its commitment to security innovation, setting industry records for performance to empower network leaders to truly transform their WAN edge.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...