<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Nerds On Site Blog &#124; Business Technology Partners &#124; IT Support &#187; SSL</title>
	<atom:link href="http://www.nerdsonsite.com/blog/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nerdsonsite.com/blog</link>
	<description>Nerds On Site - Local Nerds... Powered by a Global TEAM</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:11:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Nerds On Site Client Podcast. We interview Nerds On Site SME clients about what they do and how they make sure of technology to increase their business productivity!</itunes:summary>
	<itunes:author>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile.jpg" />
	<itunes:owner>
		<itunes:name>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:name>
		<itunes:email>nerdcast@nerdsonsite.com</itunes:email>
	</itunes:owner>
	<managingEditor>nerdcast@nerdsonsite.com (Nerds On Site Blog | Business Technology Partners | IT Support)</managingEditor>
	<copyright>Copyright 2009 Nerds On Site Inc.</copyright>
	<itunes:subtitle>Nerds On Site - Local Nerds... Powered by a Global TEAM</itunes:subtitle>
	<itunes:keywords>nerds on site, nerds, nerd, podcast, client</itunes:keywords>
	<image>
		<title>Nerds On Site Blog | Business Technology Partners | IT Support &#187; SSL</title>
		<url>http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile_128.jpg</url>
		<link>http://www.nerdsonsite.com/blog</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
		<item>
		<title>What is SSL and Why is it Important?</title>
		<link>http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/#comments</comments>
		<pubDate>Sat, 13 Nov 2010 02:43:47 +0000</pubDate>
		<dc:creator>Kevin</dc:creator>
				<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Online Services]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[secuirty]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=7358</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/' addthis:title='What is SSL and Why is it Important? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Many web hosts provide the ability for clients to provide their customers with SSL (Secure Socket Layer) connections when signed into their websites or email. It’s important to understand how SSL works, and why so many websites use the protocol to protect user data. Websites use SSL to encrypt and secure each user’s session while [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/' addthis:title='What is SSL and Why is it Important? ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/' addthis:title='What is SSL and Why is it Important? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F11%2F12%2Fwhat-is-ssl-and-why-is-it-important%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F11%2F12%2Fwhat-is-ssl-and-why-is-it-important%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Many web hosts provide the ability for clients to provide their customers with SSL (Secure Socket Layer) connections when signed into their websites or email. It’s important to understand how SSL works, and why so many websites use the protocol to protect user data.</p>
<p>Websites use SSL to encrypt and secure each user’s session while they’re logged in. Without it, it’s very possible for someone to monitor or hijack that session.</p>
<p>Websites such as Facebook or Twitter currently do not use SSL, and thus should not be used on a public network because a user’s session can be monitored.</p>
<p>You can immediately tell when a website session is secure by a lock icon in the bottom right hand corner of the browser, and the website address should have <a href="https:///">https://</a>, the “<strong>s</strong>” meaning secure. If the address only starts with <a href="http:///">http://</a>, the website is not secure.</p>
<p>When you login to a website that uses SSL, you can rest assured that no one can monitor your session while you are logged in.</p>
<p>When a user accesses an SSL-enabled website, it automatically asks the server for a digital Certificate of Authority (CA). The browser will verify the information on the certification with server’s identity and to ensure data will remain secure. If all goes as it should, this process should happen behind-the-scenes.</p>
<p>When the browser verifies the certificate, it uses the public key to encrypt a “key” that includes the user’s login information and sends it to the server.</p>
<p>The SSL server decrypts the “key” and uses a private key to decrypt the data, and sends back the requested information in an encrypted “key” to the web browser, which decrypts the data and displays the requested web page and data.</p>
<p>Make sure that you are using a modern web browser that takes advantage of SSL, and that your hosting provider offers SSL capability so you can rest assured that traffic between your computer and their web server will be secure. Also make sure that the information you are entrusting to your hosting provider for those SSL sessions will not be sold to third parties.</p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/' addthis:title='What is SSL and Why is it Important? ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/11/12/what-is-ssl-and-why-is-it-important/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on the Latest SSL Woes, and Some Interesting Stats on Data Breaches</title>
		<link>http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/</link>
		<comments>http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 15:09:09 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://nerdsonsite.com/blog/?p=4908</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/' addthis:title='More on the Latest SSL Woes, and Some Interesting Stats on Data Breaches '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>My apologies for the lapse in Security Corner Posts. The next one will continue the series on building an Information Management Plan for clients. There has been a lot of talk the past couple of weeks about the recently-discovered session renegotiation vulnerability in SSL. If you are interested in the details, here is a link [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/' addthis:title='More on the Latest SSL Woes, and Some Interesting Stats on Data Breaches ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/' addthis:title='More on the Latest SSL Woes, and Some Interesting Stats on Data Breaches '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F11%2F20%2Fmore-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F11%2F20%2Fmore-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignleft size-full wp-image-4912" title="popup_ssl" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/popup_ssl.jpg" alt="popup_ssl" width="224" height="197" />My apologies for the lapse in Security Corner Posts. The next one will continue the series on building an Information Management Plan for clients.</p>
<p>There has been a lot of talk the past couple of weeks about the recently-discovered session renegotiation vulnerability in SSL. If you are interested in the details, <a href="http://extendedsubset.com/?p=8" target="_blank">here</a> is a link to a .pdf of the original research.  <a href="http://www.computerworld.com/s/article/9140741/Opinion_Can_the_SSL_vulnerability_hurt_you_" target="_blank">Here</a> is a link to another article discussing the vulnerability.  Mr. Google can find many more for you.  This week&#8217;s episode of <a href="http://twit.tv/sn" target="_blank">Security Now!</a> will be devoted to this subject as well.</p>
<p>What does this mean to us and to clients? What are the real risks? These questions are difficult to answer at this point, because not all of the details have been made public. Initial reports focused on SSL connections that employ client-side certificates, which would not include most connections. Ironically, client-side certificates are generally considered more secure. However, since the protocol allows for more session renegotiation when using client-side certs, the risk is increased. There are more recent reports of attacks that do not involve client-side certs.</p>
<p>All versions of this attack require a successful MITM (man-in-the-middle) attack to be established first. This means that WIFI connections, especially on a public network, do present a real risk. A wired connection to a home or office network presents little risk, as does a well-secured wireless connection.</p>
<p>There have been reports of attacks &#8220;in the wild&#8221;, and at least one <a href="http://www.theregister.co.uk/2009/11/14/ssl_renegotiation_bug_exploited/" target="_blank">successful attack against twitter</a>.</p>
<p>All browsers and all web servers are affected, but there is already a <a href="http://isc.sans.org/diary.html?storyid=7603" target="_blank">patch</a> available for OpenVPN that addresses the issue. it will be a while before there are patches for all browsers and web servers. I will keep tabs on this and post news as it develops. In the meantime, even SSL connections are not necessarily secure when in on a public network.</p>
<p>Here are some interesting stats from a webinar on cloud security that I attended today:</p>
<p>The average &#8220;hard cost&#8221; (not including the cost of lost business or damaged reputation) of a data breach is $202 PER RECORD. The &#8220;less tangible&#8221; costs, such as loss of business, are often much higher. Remember this when advising clients about data protection, which has a cost. The cost of not protecting data can be much higher.</p>
<p>65% of data losses are caused by someone with privileged access (employees, contractors, etc). This includes malicious acts and errors.</p>
<p>40% of losses are caused by a third-party service supplier or contractor.</p>
<p>We focus a lot of thought and energy on hackers and outside attacks, but these are certainly not the only threats.</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>November 20, 2009</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/' addthis:title='More on the Latest SSL Woes, and Some Interesting Stats on Data Breaches ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2009/11/20/more-on-the-latest-ssl-woes-and-some-interesting-stats-on-data-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

