Google and Mozilla's message to AV and security firms: Stop trashing HTTPS

Discussion in 'other security issues & news' started by Rafales, Feb 8, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,648
    Location:
    U.S.A.
    Another point that is not mentioned in these periodic SSL scanning "bashing" studies is if all SSL/TLS traffic is scanned by the AV vendors that do so. The answer is no for the majority of the vendors. Almost all do not scan web sites that use EV certificates as most banking and major financial orgs. employ. AV vendors such as Eset also employ whitelists where known "safe" web sites are also excluded from scanning. The vast majority of these sites use certificates issued by the major CA certificate authorities.
     
  2. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Sounds great, I'll go pay some money to reduce my security right away, now that you've assured everyone is safer in the hands of 3rd party AV vendors!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.