Enterprises and Government bodies continue to rely on outdated TLS certificates, according to a security advisory published by the US National Security Agency. Earlier this week, the Dutch NCSC released a similar alert, to bolster encryption for public sector bodies that up till now has left them open to attacks and created a ‘false sense of security’.
Web browsers have been gradually moving away from TLS 1.0 and 1.1, but the shift has been slower for the public sector, and various national cybersecurity agencies are being forced to act.
Experts Comments
Dot Your Expert Comments
Only for registered and approved experts. Please register before providing comments. Register here
These protocols and algorithms advised against are widely known to be insecure, so it is concerning that the NSA still feels it’s necessary to advise against their use. This warning underscores the need for better certificate agility in today’s enterprise. Certificate automation platforms can reduce the risk of breach of outage by enabling the discovery, monitoring, and renewal of TLS certificates automatically.
Linkedin Message
@Tim Callan, Chief Compliance Officer, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Certificate automation platforms can reduce the risk of breach of outage...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/nsa-and-dutch-ncsc-warn-outdated-tls-certs
Facebook Message
@Tim Callan, Chief Compliance Officer, provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"Certificate automation platforms can reduce the risk of breach of outage...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/nsa-and-dutch-ncsc-warn-outdated-tls-certs