5 ms·
Troy and Krebs should team up to create a security hall of shame and only remove companies when issues are fixed. We have security vendors who have sslv2 enabl
by abarringer 8y ago
Troy and Krebs should team up to create a security hall of shame and only remove companies when issues are fixed.
We have security vendors who have sslv2 enabled and they can't understand why that's an issue.
We have huge fortune 250 companies that we exchange full credit card data with that have TLS 1.0 enabled with Symantec certs and only two weak ciphers. I sent them an ssl labs report and they accused me of breach of contract for hacking the site.
This list of security and finance related vendors that are double facepalm worthy is just astonishing.
- tempuser24 8y agohttp://attrition.org/ http://attrition.org/ does this, though it doesn't look like they've kept up with companies.
- medecau 8y agoattrition.org doesn't even provide HTTPS.
- Sohcahtoa82 8y agoWow...how can a site about security not support HTTPS?
- tombrossman 8y agoI'm doing this in the community where I live and I have discovered that it is super effective. I send an email to each company explaining a security problem with their site (currently focusing on simple lack of HTTPS for form data, and not mentioning the public disclosure because I want to see who fixes things because they care vs. those just avoiding negative publicity) and if they haven't resolved it or replied within a week, I list them publicly on https://www.insecure.org.je https://www.insecure.org.je. The site isn't winning me any design awards and needs expanding of the advice articles, but dozens of local companies are immediately spurred to action when they appear in the "Sites requiring extra caution" section. Thousands of local users have directly benefited by the added security, even though they are completely unaware of why it was upgraded. The reaction from some business has been very predictable, with a mix of hostility, threats, confusion, outright lies, but enough respond politely and want to fix things, and I go out of my way to help those who want to learn. Source is public and if you want to try this locally, I highly recommend it: https://gitlab.com/tombrossman/insecure.org.je https://gitlab.com/tombrossman/insecure.org.je
- craftyguy 8y agoThat is a great idea! Do you reach out to companies after adding them to the public list of shame letting them know, or do they eventually discover then are on it? I may have to implement this..
- tombrossman 8y agoNo, I just list them and I do not send any follow-up message. Many do find out immediately though, because others tell them about it. I seem to get a lot of referral traffic from LinkedIn after doing updates, so I guess someone is posting about it over there. I had someone well known in the local tech community call it "The most unprofessional thing I have ever seen" but later he was using it as a sales tool to persuade one of the companies listed to hire him to upgrade their site. I don't condone this but once the info is public I can't control what people do with it.
- dschep 8y agoFreedom of the press foundation does this for HTTPS for news sites: https://securethe.news/sites/ https://securethe.news/sites/ Though, imo, they should be sorted with the worst offenders on top.
- itsameta4 8y agoThere's also Plain Text Offenders, for those who clearly store passwords in plaintext. http://plaintextoffenders.com/ http://plaintextoffenders.com/
- user5994461 8y agoExcel 2010 only supports TLS 1.0 Can't update SSL until Excel is updated.
- ianlevesque 8y ago2010 was almost a decade ago.
- deleted 8y ago[deleted]
- thaumaturgy 8y agoFedEx just sent out a message last Friday: "FedEx will renew the security certificate with Symantec for the following FedEx Web Services servers at 11 pm CDT on September 15, 2018. Please note that these certificates are valid for two years and will expire on October 4, 2020." Heh.