<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>flaw Archives - CritchCorp Computers Ltd</title>
	<atom:link href="https://www.cc-computers.com/tag/flaw/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cc-computers.com</link>
	<description>Complete Computer Support</description>
	<lastBuildDate>Thu, 17 Aug 2023 06:50:46 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.cc-computers.com/wp-content/uploads/2020/07/favicon.ico</url>
	<title>flaw Archives - CritchCorp Computers Ltd</title>
	<link>https://www.cc-computers.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>3 million Let&#8217;s Encrypt certificates to be cancelled</title>
		<link>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=3-million-lets-encrypt-certificates-to-be-cancelled</link>
					<comments>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 04 Mar 2020 10:04:29 +0000</pubDate>
				<category><![CDATA[Archive]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[CAA]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[Let's Encrypt]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[ssl]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=2207</guid>

					<description><![CDATA[<p>Let&#8217;s Encrypt revoked certificates Let&#8217;s Encrypt has announced that it is to revoke aroound 3 million TLS/SSL certificates because of a serious flaw found in the CAA (Certificate Authority Authorization). The certificates will be revokend on the 4th March 2020 from 00:00 UTC. Let&#8217;s Encrypt has around 116 million certificates issued at the moment which [&#8230;]</p>
The post <a href="https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/">3 million Let’s Encrypt certificates to be cancelled</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h2>Let&#8217;s Encrypt revoked certificates</h2>
<p>Let&#8217;s Encrypt has announced that it is to revoke aroound 3 million TLS/SSL certificates because of a serious flaw found in the CAA (Certificate Authority Authorization). The certificates will be revokend on the 4th March 2020 from 00:00 UTC.<span id="more-2207"></span></p>
<p>Let&#8217;s Encrypt has around 116 million certificates issued at the moment which means that around 2.6% of them are to be revoked. Sites that have not reissued their certificates will find that users will be unlikely to visit them as they will be warned when trying to visit that the site is likely to be fake or compromised as the certificate has been revoked.</p>
<p>A revoked certificate is far worse from a security point of view for users as it shows that positive action has been taken to make users aware that the certificate has been tagged as &#8220;<strong>Not to be trusted</strong>&#8220;.</p>
<h2>How can you fix it?</h2>
<p>If you own a website that uses Let&#8217;s Encrypt, an automated free certificate system, then you should get your certificate changed ASAP. It is free and easy to do. There is a list of the affected certificate serial numbers which can be downloaded <a href="https://d4twhgtvn0ff5.cloudfront.net/caa-rechecking-incident-affected-serials.txt.gz">here</a> and there is a tool that you can use to check your site <a href="https://checkhost.unboundtest.com/">here</a>. Let&#8217;s Encrypt has sent an email notification to those that have registered an email address whith them but many are thought to be out of date and to be that of their hosting provider. If you are unsure please use the tools to check your site yourself.</p>
<h2>Our clients who use Let&#8217;s Encrypt</h2>
<p>CritchCorp Computers Ltd has already checked all of our clients sites that use Let&#8217;s Encrypt certificates; which come FREE with any of our Feature Rich Hosting accounts. Also anyone using a paid certificate from CritchCorp Computers Ltd is not affected by this latest issue.</p>
<p>If you are affected then you should contact your hosting company or webmaster urgently to get the issue resolved. If you have no-one to contact then we maybe able to help, please submit a support ticket from <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">our store ticket system</a>.</p>
<h2>Is Let&#8217;s Encrypt still good?</h2>
<p>We have been asked whether or not Let&#8217;s Encrypt certificates are safe given the latest bug. We are confident that they are a great starter certificate and are much better than having no certificate. Let&#8217;s Encrypt have been upfront and transparent about the issue and that is exactly what they should do, so we are confident that they ACME system is a good way to ensure that all sites have some form of security. If your site need better security or more gurentees about who you are and better protection then you should upgrade to a paid certificate whch come with different levels of security and guarentees.</p>
<p>Stay Safe</p>
<p>Support.</p>


<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<h2 class="wp-block-heading" id="h-don-t-forget-to-checkout-these-other-products-too">Don&#8217;t forget to check out these other Products too</h2>



<div class="wp-block-blockspare-blockspare-list aligncenter blockspare-393e5569-01e3-4 blockspare-block-iconlist-wrap" blockspare-animation=""><style>.blockspare-393e5569-01e3-4 .blockspare-list-wrap{border-radius:0px;margin-top:30px;margin-bottom:30px;padding-top:0px;padding-right:0px;padding-bottom:0px;padding-left:0px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{color:#404040;text-align:left;font-size:16px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li:before{color:#404040}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}@media screen and (max-width:1025px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}@media screen and (max-width:768px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}</style><div class="blockspare-blocks blockspare-list-wrap blockspare-hover-item"><ul class="blockspare-list-arrow-right listDescription"><li><a href="https://www.cc-computers.com/critchcorp-smart-light-bulb/">CritchCorp Smart™ Light Bulbs</a></li><li><a href="https://www.cc-computers.com/incense/">Resin Incense</a></li><li><a href="/subscribe-and-save/">NEW: Subscribe and Save</a></li><li><a href="https://store.cc-computers.com/collections/all-subscribe-and-save-items" target="_blank" rel="noreferrer noopener">NEW: Subscribe and Save Collections</a></li><li><a href="https://www.cc-computers.com/free-hosting/">Free Hosting</a></li><li><a href="https://www.cc-computers.com/feature-rich-hosting-cpanel/">Feature Rich Hosting</a></li><li><a href="https://www.cc-computers.com/wordpress/">WordPress Hosting</a></li><li><a href="https://www.cc-computers.com/website-security/">Website Security</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-email/">Cloud eMail</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-files-data-backup-and-collaboration/">Cloud Sharing &amp; backup</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-sharepoint/">Cloud Share Point</a></li><li><a href="https://www.cc-computers.com/phone-and-internet/">Internet &amp; VoIP</a></li></ul></div></div>



<p>You can also read more <a href="https://www.cc-computers.com/about-critchcorp-computers-ltd/">about us</a> and the products and services we offer.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>The post <a href="https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/">3 million Let’s Encrypt certificates to be cancelled</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/3-million-lets-encrypt-certificates-to-be-cancelled/feed/</wfw:commentRss>
			<slash:comments>59</slash:comments>
		
		
			</item>
		<item>
		<title>WordPress Flaw found in Social Media plugin</title>
		<link>https://www.cc-computers.com/wordpress-flaw-found-in-social-media-plugin/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=wordpress-flaw-found-in-social-media-plugin</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Fri, 15 Feb 2019 16:40:19 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Simple Social Buttons]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1681</guid>

					<description><![CDATA[<p>&#160; URGENT &#8211; If you use the plugin &#8216;Simple Social Buttons&#8217; in your WordPress installation, you should immediately update it to the latest version as there has been a serious flaw found in it that could allow an attacker to take over the site. The flaw, which was discovered last week by security researcher and [&#8230;]</p>
The post <a href="https://www.cc-computers.com/wordpress-flaw-found-in-social-media-plugin/">WordPress Flaw found in Social Media plugin</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span style="color: #ff0000;"><strong>URGENT</strong></span> &#8211; If you use the plugin &#8216;Simple Social Buttons&#8217; in your WordPress installation, you should immediately update it to the latest version as there has been a serious flaw found in it that could allow an attacker to take over the site. The flaw, which was discovered last week by security researcher and developer Luka Šikić, has been discovered and a video showing how to use it to break in to WordPress websites has been released.</p>
<p>The flaw has been fixed by the developer and a patch released. So if you haven&#8217;t already then you should update now.</p>
<p>The flaw can only be leveraged in sites that allow user sign-up, which most sites have disabled due to security reasons. Never the less you should update before they figure out how to exploit the flaw without user sign-up requirements.</p>
<p>Any of our customers who have website maintenance contracts will have already been updated to the latest security patch. If you are not sure then you should contact your web development team and/or your host to see if they can help.</p>
<p>If you are really stuck then we may be able to help, please submit a <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">support ticket</a> with your website URL and contact information. Do <span style="color: #ff0000;">NOT</span> post your username and password in the ticket we will contact you separately for the information if needed.</p>
<p>If you use the Simple Social Buttons plugin for WordPress then make sure you update your site to correct the security flaw immediately.</p>
<p>Stay Safe</p>
<p>CritchCorp Computers Ltd.</p>
<p>&nbsp;</p>The post <a href="https://www.cc-computers.com/wordpress-flaw-found-in-social-media-plugin/">WordPress Flaw found in Social Media plugin</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Update to Apple FaceTime Flaw</title>
		<link>https://www.cc-computers.com/update-to-apple-facetime-flaw/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=update-to-apple-facetime-flaw</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Mon, 11 Feb 2019 14:06:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[facetime]]></category>
		<category><![CDATA[flaw]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1673</guid>

					<description><![CDATA[<p>&#160; Apple has finally fixed the FaceTime Flaw we reported on week before last. They issued a patch (12.1.4) for iPhones (5S+) and iPad Air+ and iPod Touch 6th gen+ on Friday after initially disabling the group chat on the server side. They fixed the server side early last week but still needed to patch [&#8230;]</p>
The post <a href="https://www.cc-computers.com/update-to-apple-facetime-flaw/">Update to Apple FaceTime Flaw</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Apple has finally fixed the FaceTime Flaw we reported on week before last. They issued a patch (12.1.4) for iPhones (5S+) and iPad Air+ and iPod Touch 6th gen+ on Friday after initially disabling the group chat on the server side. They fixed the server side early last week but still needed to patch the software on the phones, iPads and iPods. This has now been done.</p>
<p>If you disabled FaceTime on your devices, as was advised, then after you install the latest update for your device, it is safe to turn it on again.</p>
<p>The issue was discovered by a 14 year old boy, who was thanked by Apple in their statement, which is here:</p>
<blockquote><p>We have fixed the Group FaceTime security bug on Apple&#8217;s servers and we will issue a software update to re-enable the feature for users next week. We thank the Thompson family for reporting the bug. We sincerely apologize to our customers who were affected and all who were concerned about this security issue. We appreciate everyone&#8217;s patience as we complete this process.</p>
<p>We want to assure our customers that as soon as our engineering team became aware of the details necessary to reproduce the bug, they quickly disabled Group FaceTime and began work on the fix. We are committed to improving the process by which we receive and escalate these reports, in order to get them to the right people as fast as possible. We take the security of our products extremely seriously and we are committed to continuing to earn the trust Apple customers place in us.</p></blockquote>
<p>Don&#8217;t forget to install the update first before switching it back on.</p>
<p>Stay Safe.</p>
<p>CritchCorp Computers Ltd.</p>The post <a href="https://www.cc-computers.com/update-to-apple-facetime-flaw/">Update to Apple FaceTime Flaw</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple FaceTime flaw</title>
		<link>https://www.cc-computers.com/apple-facetime-flaw/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=apple-facetime-flaw</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Tue, 29 Jan 2019 21:31:00 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[facetime]]></category>
		<category><![CDATA[flaw]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1499</guid>

					<description><![CDATA[<p>&#160; This is an urgent alert for Apple FaceTime users. A serious flaw has been discovered in Apples FaceTime app on all platforms. The remedy Until further notice, Apple recommends turning off FaceTime on your devices and Apple computers. To do this, go to SETTINGS —&#62; FaceTime and then turn off. However If you simply [&#8230;]</p>
The post <a href="https://www.cc-computers.com/apple-facetime-flaw/">Apple FaceTime flaw</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>This is an urgent alert for Apple FaceTime users. A serious flaw has been discovered in Apples FaceTime app on all platforms.</p>
<h2>The remedy</h2>
<p>Until further notice, Apple recommends turning off FaceTime on your devices and Apple computers.</p>
<p>To do this, go to SETTINGS —&gt; FaceTime and then turn off.</p>
<h2>However</h2>
<div>If you simply cannot live without Facetime, then you need to read the next bit to see what the problem is and how it affects you.</div>
<div></div>
<h2>What has happened</h2>
<div>Today, Tuesday 29th January 2019, Apple has reported that they have discovered a serious flaw in their FaceTime app. In short, the issue is that the person calling you may be able to hear or see you before you accept or decline the call. So if you don’t want to turn it off then you must remember that they may be able to see you or hear you before you answer, so no swearing about who‘s calling you!</div>
<div>Apple are working on the issue and will hopefully have a patch out later this week or next week so make sure you update your devices.</div>
<div>They have begun turning off the group chat function on their servers which is believed to be the cause of the issue but some users are still reporting the problem exists.</div>
<div></div>
<div><strong>We will let you know when it is fixed.</strong></div>
<div></div>
<div>Stay Safe</div>
<div></div>
<div>CritchCorp Computers Support Team</div>The post <a href="https://www.cc-computers.com/apple-facetime-flaw/">Apple FaceTime flaw</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
