<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » Encryption</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/encryption/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>How safe is a career at Symantec?</title>
		<link>http://countermeasures.trendmicro.eu/how-safe-is-a-career-at-symantec/</link>
		<comments>http://countermeasures.trendmicro.eu/how-safe-is-a-career-at-symantec/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 14:19:39 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[cetificate]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1251</guid>
		<description><![CDATA[I had a call from a head-hunter this morning, and I was fairly sure he was sounding me out for a Symantec job. So I went over to the Symantec careers web site to confirm my suspicions, only to have Firefox advise me to &#8220;GetÂ me out of there&#8220;. Â  Now I certainly don&#8217;t expect careers [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/how-safe-is-a-career-at-symantec/' addthis:title='How safe is a career at Symantec? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>I had a call from a head-hunter this morning, and I was fairly sure he was sounding me out for a Symantec job. So I went over to the Symantec careers web site to confirm my suspicions, only to have Firefox advise me to &#8220;<em>GetÂ me out of there</em>&#8220;.</p>
<div id="attachment_1253" class="wp-caption alignleft" style="width: 572px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/SYMC1.png"><img class="size-full wp-image-1253" title="Symantec Careers Website" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/SYMC1.png" alt="Symantec Careers Website" width="510" height="348" /></a><p class="wp-caption-text">Symantec Careers Website</p></div>
<p>Â </p>
<p>Now I certainly don&#8217;t expect careers advice from Firefox, neither am I trying to pick a fight with Symantec, their office is literally opposite ours in California (although you know if it came to a rumble how it would turn out). Plus, I hear it&#8217;s a great place to work anyway :)</p>
<p>Â </p>
<p>What has actually happened is that the site certificate had expired and not yet been renewed and that is why it shows as invalid.Â To someÂ extent computer certificates function similar toÂ passports. They are issued by a trusted central authority, normally only valid for a certain period of time and need to be renewed.</p>
<p>Â </p>
<p>In technical terms, an expired certificate does not affect the functionality of the website, secure connections can and will still be made. Clearly it doesn&#8217;t reflect too well on the site&#8217;s owner in terms of process, and there is a risk that something untoward may be happening, but it&#8217;s relatively minor. The risk is in the fact that when a certificate is expired, then the issuer of that certificate &#8211; the Passport Authority if you like -Â may no longer maintain details on whether that certificate has been revoked (a much more serious state of affairs) and if so for what reasons.</p>
<p>Â </p>
<p>There is however a wider message to this. The real problem, as evidenced by a <a href="http://www.usenix.org/event/sec09/tech/full_papers/sunshine.pdf" target="_blank">study </a>at Carnegie-Mellon University presented last week at theÂ <a href="http://www.usenix.org/event/sec09/tech/" target="_blank">Usenix Security Symposium</a>Â 2009 is that the vast majority of internet users think that SSL warnings like this are of little consequence. This is partially because they see them on legitimate websites, and have been conditioned to accept the risk and click through and partially because the error messages presented by the leading browsers very often present the user with information they do not understand and then ask them to make a decision they don&#8217;t have the resources to make.</p>
<p>Â </p>
<p>Below is the same error with the &#8220;<em>Technical Details</em>&#8221; and &#8220;<em>I Understand the Risks</em>&#8221; sections expanded. I think it&#8217;s fair to say that if I asked my mum to explain what it meant, she would offer to go and make me a cup of tea instead. To be fair, how many users even read the messages before deciding to ignore them?</p>
<div id="attachment_1255" class="wp-caption alignleft" style="width: 595px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/error-expanded.png"><img class="size-full wp-image-1255" title="Firefox 3.5 Certificate Error Message" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/error-expanded.png" alt="Firefox 3.5 Certificate Error Message" width="510" height="459" /></a><p class="wp-caption-text">Firefox 3.5 Certificate Error Message</p></div>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/how-safe-is-a-career-at-symantec/' addthis:title='How safe is a career at Symantec? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/how-safe-is-a-career-at-symantec/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

