<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tls certificates Archives - CritchCorp Computers Ltd</title>
	<atom:link href="https://www.cc-computers.com/tag/tls-certificates/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cc-computers.com</link>
	<description>Complete Computer Support</description>
	<lastBuildDate>Thu, 10 Sep 2020 22:12:39 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.cc-computers.com/wp-content/uploads/2020/07/favicon.ico</url>
	<title>tls certificates Archives - CritchCorp Computers Ltd</title>
	<link>https://www.cc-computers.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>GoDaddy breach found after 6 months</title>
		<link>https://www.cc-computers.com/godaddy-breach-found-after-6-months/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=godaddy-breach-found-after-6-months</link>
					<comments>https://www.cc-computers.com/godaddy-breach-found-after-6-months/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Tue, 05 May 2020 09:26:20 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[tls certificates]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=2736</guid>

					<description><![CDATA[<p>Security Breach GoDaddy, the largest hosting company in the world, announced on the 23th April 2020 that their security was breached on the 19th October 2019. The public announcement from GoDaddy reads: “On April 23, 2020, we identified SSH usernames and passwords had been compromised by an unauthorized individual in our hosting environment. This affected [&#8230;]</p>
The post <a href="https://www.cc-computers.com/godaddy-breach-found-after-6-months/">GoDaddy breach found after 6 months</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h2>Security Breach</h2>
<p>GoDaddy, the largest hosting company in the world, announced on the 23th April 2020 that their security was breached on the 19th October 2019.</p>
<p><span id="more-2736"></span>The public announcement from GoDaddy reads:</p>
<blockquote><p>“On April 23, 2020, we identified SSH usernames and passwords had been compromised by an unauthorized individual in our hosting environment. This affected approximately 28,000 customers. We immediately reset these usernames and passwords, removed an authorized SSH file from our platform, and have no indication the individual used our customers’ credentials or modified any customer hosting accounts. The individual did not have access to customers’ main GoDaddy accounts.”</p></blockquote>
<p>If you have been affected by this breach, you would probably already been notified or will be notified soon. There are several issues with this breach. Firstly, it can be presumed that the breach affected their main operation and not one of the other companies that they own.  They own the hosteurope group of hosting companies which they bought in 2017. Host Europe includes: Heart Internet, Mesh Digital Host Europe, Webfusion, Red Coruna and Domainbox. GoDaddy has also bought up many other companies. Any of these could have been in the breach but it appears that only the main brand that is affected.</p>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-2741 size-full" title="GoDaddy web server SSH hacked" src="https://cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757.png" alt="Certificate found on GoDaddy SSH server" width="1920" height="585" srcset="https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757.png 1920w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757-600x183.png 600w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757-300x91.png 300w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757-1024x312.png 1024w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757-768x234.png 768w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1923446_1920-e1588842153757-1536x468.png 1536w" sizes="(max-width: 1920px) 100vw, 1920px" /></p>
<h3>What happened</h3>
<p>It appears that someone managed to get their certificate in to a server. This allowed them to have access to everyones files on the server even if the affected client changed their password.</p>
<h3>How does this affect the server</h3>
<p>There are generally two ways to authenticate to the SSH server, through either username and password or username and certificate (private/public key). Using a certificate is very secure and the recommended way to connect as it doesn&#8217;t require the exchange of a password but uses the robist public key technology to authenticate you. In this case the attacker managed to get their certificate installed on teh server and granted access to every account on the server.</p>
<h3>What have they done to fix it</h3>
<p>GoDaddy said that they have removed the certificate and that there is no evidence that anything malicious had happened. That being said they did not notice that there was a problem for nearly seven months.</p>
<h2>Alternatives</h2>
<p>We can help if you have been negatively affected by this experiance. Get your account in the <a href="https://shop.cc-computers.com/cart.php?gid=1">CritchCorp Computers Ltd Store</a>. If you prefer friendly, personal assistance with your website then we can help.</p>
<p>Keep Safe</p>
<p>CrichCorp</p>
<p><img decoding="async" class="alignnone wp-image-2744 size-full" title="CrichCorp Computers Ltd Hosting" src="https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857.png" alt="Get secure hosting on servers with far less than 28,000 other clients." width="1280" height="710" srcset="https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857.png 1280w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857-600x333.png 600w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857-300x166.png 300w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857-1024x568.png 1024w, https://www.cc-computers.com/wp-content/uploads/2020/05/cyber-security-1784985_1280-e1588843510857-768x426.png 768w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>The post <a href="https://www.cc-computers.com/godaddy-breach-found-after-6-months/">GoDaddy breach found after 6 months</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/godaddy-breach-found-after-6-months/feed/</wfw:commentRss>
			<slash:comments>35</slash:comments>
		
		
			</item>
		<item>
		<title>Google Forces Sites to use SSL Certificates</title>
		<link>https://www.cc-computers.com/google-forces-ssl-use/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-forces-ssl-use</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 06 Jun 2018 11:01:16 +0000</pubDate>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[google forces]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[prevent hacking]]></category>
		<category><![CDATA[secure website]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SSL certificates]]></category>
		<category><![CDATA[tls certificates]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=596</guid>

					<description><![CDATA[<p>***Notice to all Website owners*** That&#8217;s right, as of July 2018 Google Chrome will start reporting non-SSL sites (that is sites that don&#8217;t use https:// for access) as insecure. This is a major change from the current norm which is to highlight sites that use SSL certificates with a green SECURE next to the address [&#8230;]</p>
The post <a href="https://www.cc-computers.com/google-forces-ssl-use/">Google Forces Sites to use SSL Certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h1>***Notice to all Website owners***</h1>
<p>That&#8217;s right, as of <strong>July 2018</strong> Google Chrome will start reporting non-SSL sites (that is sites that don&#8217;t use http<strong>s</strong>:// for access) as insecure. This is a major change from the current norm which is to highlight sites that use SSL certificates with a green <strong><span style="color: #339966;">SECURE</span></strong> next to the address and other browsers who use a green padlock. They will from July this year not show the green <strong><span style="color: #339966;">SECURE</span></strong> but they will show a<strong> <span style="color: #ff0000;">NOT SECURE</span> </strong>next to any site that does not have an SSL certificate. Making the norm to have an SSL certificate. That is going to be followed in the future by a warning screen that informs users that continuing to your site is not recommended. Though the warning wall is not being implemented right away it is planned for the future.</p>
<figure id="attachment_598" aria-describedby="caption-attachment-598" style="width: 640px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-598 size-full" src="https://cc-computers.com/wp-content/uploads/2018/06/google-https-july.png" alt="Google's July update, what it looks like" width="640" height="231" srcset="https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july.png 640w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-600x217.png 600w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-300x108.png 300w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-500x180.png 500w" sizes="(max-width: 640px) 100vw, 640px" /><figcaption id="caption-attachment-598" class="wp-caption-text">What the browser will report before and after July for sites that do not have an SSL certificate.</figcaption></figure>
<p>The new move forces website owners to have an SSL certificate and make their site secure, even if it is not required, or risk losing visitors that are scared away.</p>
<p>There are several different types of SSL certificate and the higher (more expensive) ones will still show the green bar in the address bar, but the norm will be to have one of the cheaper ones and if you don&#8217;t have any or it expires, the company backing the SSL cert (Cert provider not the retailer) goes out of business or has their master certificate rejected then you will be faced with a blocking screen when trying to get to your site which will prevent users from going there, with warnings that your site is insecure and should not be visited. This is obviously not good for business.</p>
<p>Google have also hinted that sites that use SSL certificates currently get a boost in the Google rankings over those who do not.</p>
<p>At CritchCorp Computers Ltd we have a quick and easy way for you to comply with this new Google rule for all our shared hosting customers you can purchase a fully managed SSL certificate from your yesDomains account or submit a support ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a> to get the ball rolling. It is quite an in-depth process but we will take care of it for you, with as little interaction as possible required by you. Please go <a href="https://shop.cc-computers.com/cart.php?gid=2">here</a> to get started.</p>
<p>The industry is working towards lowering the cost of SSL certificates to nothing and automating the install and renewal process, but that is still in development so for the time being you will need to purchase an SSL certificate in the normal way. If you want the users browser to light up in green then you need to select the Extended Validation (EV) certificate otherwise the cheaper normal one will suffice to prevent you being labelled as <span style="color: #ff0000;"><strong>NOT SECURE</strong>.</span> We have monthly or annual billing options to spread the cost but all certificates are annual commitments.</p>
<p><span style="color: #3366ff;"><em>We use Comodo, DigiCert, Symantec, Thwarte, GeoTrust and Trustwave certificates  that are strong providers in this field and highly unlikely to go out of business or have their master certificates rejected. This provides you with stability and reassurance that your certificate will not become invalid before it expires as does happen from time to time with smaller SSL providers.<br />
</em></span></p>
<p>If you want to read the Google blog entry about this; with their advertising spin on it then click <a href="https://blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html">here</a>. What this does do is add further costs to businesses. Whilst we absolutely agree that any site that accepts payments or collects user data should be secure, there are still many sites that do not and so forcing them to have this does seem unfair to us, but that is what the mighty Google has decided and so it shall unfortunately be.</p>
<p>There has been some discussion about the colour of the <span style="color: #ff0000;"><strong>NOT SECURE</strong></span>. The current <span style="color: #339966;"><strong>SECURE</strong></span> label is green and it is understood that the new <strong><span style="color: #ff0000;">NOT SECURE</span></strong> is going to be Red, although some discussions at Google say it will be more neutral, which ever it is it isn&#8217;t good for business.</p>
<p>Keep safe</p>
<p>CritchCorp Computers Ltd</p>The post <a href="https://www.cc-computers.com/google-forces-ssl-use/">Google Forces Sites to use SSL Certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
