

{"id":993,"date":"2012-05-05T06:52:08","date_gmt":"2012-05-05T11:52:08","guid":{"rendered":"http:\/\/rud.is\/b\/?p=993"},"modified":"2018-03-10T07:53:18","modified_gmt":"2018-03-10T12:53:18","slug":"both-candidates-weak-on-ssl-security","status":"publish","type":"post","link":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/","title":{"rendered":"Both Candidates Weak On [SSL] Security"},"content":{"rendered":"<p><b>UPDATE:<\/b> <i>Fixed link to cached Obama image thx to notice from JB<\/i><\/p>\n<p>While the two front-running candidates engaged in a bizarre, Klingon-esque ritual of hubris regarding which one was the better killer, their respective technical campaign staffers were failing to make the grade on security when it comes to taking your donations.<\/p>\n<p>Earlier this week, I <a href=\"https:\/\/rud.is\/b\/2012\/04\/28\/slaying-the-beast-in-nginx\/\">mentioned<\/a> the most excellent <a href=\"https:\/\/www.ssllabs.com\/ssltest\/\">Qualys SSL Certificate Tester<\/a> and thought it would be interesting to try it on the two front-running US Presidential candidates online donation forms, especially since both candidates are focusing on how much they want to protect the American public.<\/p>\n<p>Let&#8217;s just say that the results aren&#8217;t stellar, but they are better than I expected.<\/p>\n<p>You can view the results directly from the SSL Labs site by hitting the following links:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=www%2emittromney%2ecom&#038;s=23%2e46%2e224%2e216\">Romney Campaign Site SSL Report<\/a><\/li>\n<li><a href=\"https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=donate.barackobama.com\">Obama Campaign Site SSL Report<\/a><\/li>\n<\/ul>\n<p>While I&#8217;m not exactly hopeful either staff will end up fixing the SSL configurations, in the event they do, here are image-cached results of the scans I ran on Saturday, May 5, 2012:<\/p>\n<ul>\n<li><a href=\"https:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney.jpg\">Cached Romney full report<\/a><\/li>\n<li><span class=\"removed_link\" title=\"http:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama.jpg\">Cached Obama full report<\/span><\/li>\n<\/ul>\n<p>But, you don&#8217;t want links, you want results, so here&#8217;s the top-level summary comparison:<\/p>\n<p><center><\/p>\n<table border=\"0\">\n<tr>\n<td><b>Mitt Romney<\/b><br \/><a href=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"995\" data-permalink=\"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/romney-ssl-summary\/\" data-orig-file=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?fit=817%2C414&amp;ssl=1\" data-orig-size=\"817,414\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"romney-ssl-summary\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?fit=510%2C258&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?resize=300%2C152&#038;ssl=1\" alt=\"\" title=\"romney-ssl-summary\" width=\"300\" height=\"152\" class=\"aligncenter size-medium wp-image-995\" srcset=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?resize=300%2C152&amp;ssl=1 300w, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?w=817&amp;ssl=1 817w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<\/tr>\n<\/table>\n<p><\/p>\n<table border=\"0\">\n<tr>\n<td><b>Barack Obama<\/b><br \/><a href=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"994\" data-permalink=\"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/obama-ssl-summary\/\" data-orig-file=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?fit=815%2C368&amp;ssl=1\" data-orig-size=\"815,368\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"obama-ssl-summary\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?fit=510%2C230&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?resize=300%2C135&#038;ssl=1\" alt=\"\" title=\"obama-ssl-summary\" width=\"300\" height=\"135\" class=\"aligncenter size-medium wp-image-994\" srcset=\"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?resize=300%2C135&amp;ssl=1 300w, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/obama-ssl-summary.png?w=815&amp;ssl=1 815w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<\/tr>\n<\/table>\n<p><\/center><\/p>\n<p>So, both candidates earn a &#8220;C&#8221; with Obama&#8217;s team scoring 10 total points higher than Romney, but let&#8217;s look at the details (only comparing the &#8220;bad&#8221; categories):<\/p>\n<p><center><\/p>\n<h3>Candidate SSL Configuration Comparison<\/h3>\n<p><\/center><link rel=\"stylesheet\" href=\"http:\/\/www.compareninja.com\/template\/skins\/Classic\/skin.css\" type=\"text\/css\">\n<div id=\"tableWrapper\" style=\"width: 100%; \">\n<table id=\"vsTable\">\n<tbody>\n<tr>\n<td class=\"cat title\" style=\"width: 33%; \"><\/td>\n<td class=\"title\" style=\"width: 33%; \">\n<div class=\"\">Romney<\/div>\n<\/td>\n<td class=\"title\" style=\"width: 33%; \">\n<div class=\"\">Obama<\/div>\n<\/td>\n<\/tr>\n<tr class=\"second\">\n<td class=\"cat\" style=\"width: 33%; \">\n<div class=\"\">Issuer<\/div>\n<\/td>\n<td style=\"width: 33%; \" class=\"text\">\n<div class=\"\">USERTrust Legacy<br \/>Secure Server CA<\/div>\n<\/td>\n<td style=\"width: 33%; \" class=\"text\">\n<div class=\"\">Go Daddy Secure<br \/>Certification Authority<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"cat\" style=\"width: 33%; \">\n<div class=\"\">Supports Insecure SSL 2.0<\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"yes\"><\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"no\"><\/div>\n<\/td>\n<\/tr>\n<tr class=\"second\">\n<td class=\"cat\" style=\"width: 33%; \">\n<div class=\"\">Number Of Weak Cipher Suites<\/div>\n<\/td>\n<td style=\"width: 33%; \" class=\"text\">\n<div class=\"\">7<\/div>\n<\/td>\n<td style=\"width: 33%; \" class=\"text\">\n<div class=\"\">3<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"cat\" style=\"width: 33%; \">\n<div class=\"\">Vulnerable to the BEAST<\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"yes\"><\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"no\"><\/div>\n<\/td>\n<\/tr>\n<tr class=\"second\">\n<td class=\"cat\" style=\"width: 33%; \">\n<div class=\"\">Weak Ephemeral DH<\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"no\"><\/div>\n<\/td>\n<td style=\"width: 33%; \">\n<div class=\"yes\"><\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"text-align:right;font-size:8px\">Chart made with <span class=\"removed_link\" title=\"compareninja.com\">CompareNinja<\/span><\/div>\n<p>While it&#8217;s somewhat ironic that Romney is vulnerable to the BEAST, both candidates show their true cipher weakness. Ultimately, though, I have to agree with the numerical results (Obama coming out the least bad of the two) if not solely based on Romney supporting insecure SSL 2.0 connections.<\/p>\n<p>Given that the <a href=\"https:\/\/www.ssllabs.com\/ssl-pulse\/\">Trustworty Internet Movement<\/a>&#8216;s <a href=\"https:\/\/www.ssllabs.com\/ssl-pulse\/\">SSL Pulse Report<\/a> made tech headlines just recently and that both the scan and the fixes take about 10 minutes to complete, these results are just, plain sad.<\/p>\n<p>Hopefully no one decided to donate to either candidate while sipping their quad grande no-whip mocha macchiatos at Starbucks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UPDATE: Fixed link to cached Obama image thx to notice from JB While the two front-running candidates engaged in a bizarre, Klingon-esque ritual of hubris regarding which one was the better killer, their respective technical campaign staffers were failing to make the grade on security when it comes to taking your donations. Earlier this week, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":3,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":""},"categories":[60,56],"tags":[648],"class_list":["post-993","post","type-post","status-publish","format-standard","hentry","category-certificates","category-ssl","tag-presidential-election"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Both Candidates Weak On [SSL] Security - rud.is<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Both Candidates Weak On [SSL] Security - rud.is\" \/>\n<meta property=\"og:description\" content=\"UPDATE: Fixed link to cached Obama image thx to notice from JB While the two front-running candidates engaged in a bizarre, Klingon-esque ritual of hubris regarding which one was the better killer, their respective technical campaign staffers were failing to make the grade on security when it comes to taking your donations. Earlier this week, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/\" \/>\n<meta property=\"og:site_name\" content=\"rud.is\" \/>\n<meta property=\"article:published_time\" content=\"2012-05-05T11:52:08+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-03-10T12:53:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary-300x152.png\" \/>\n<meta name=\"author\" content=\"hrbrmstr\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"hrbrmstr\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/\"},\"author\":{\"name\":\"hrbrmstr\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"headline\":\"Both Candidates Weak On [SSL] Security\",\"datePublished\":\"2012-05-05T11:52:08+00:00\",\"dateModified\":\"2018-03-10T12:53:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/\"},\"wordCount\":371,\"commentCount\":3,\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"image\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2012\\\/05\\\/romney-ssl-summary-300x152.png\",\"keywords\":[\"presidential election\"],\"articleSection\":[\"Certificates\",\"SSL\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/\",\"name\":\"Both Candidates Weak On [SSL] Security - rud.is\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2012\\\/05\\\/romney-ssl-summary-300x152.png\",\"datePublished\":\"2012-05-05T11:52:08+00:00\",\"dateModified\":\"2018-03-10T12:53:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2012\\\/05\\\/romney-ssl-summary.png?fit=817%2C414&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2012\\\/05\\\/romney-ssl-summary.png?fit=817%2C414&ssl=1\",\"width\":\"817\",\"height\":\"414\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2012\\\/05\\\/05\\\/both-candidates-weak-on-ssl-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/rud.is\\\/b\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Both Candidates Weak On [SSL] Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/\",\"name\":\"rud.is\",\"description\":\"&quot;In God we trust. All others must bring data&quot;\",\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rud.is\\\/b\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\",\"name\":\"hrbrmstr\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"width\":460,\"height\":460,\"caption\":\"hrbrmstr\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\"},\"description\":\"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7\",\"sameAs\":[\"http:\\\/\\\/rud.is\"],\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/author\\\/hrbrmstr\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Both Candidates Weak On [SSL] Security - rud.is","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/","og_locale":"en_US","og_type":"article","og_title":"Both Candidates Weak On [SSL] Security - rud.is","og_description":"UPDATE: Fixed link to cached Obama image thx to notice from JB While the two front-running candidates engaged in a bizarre, Klingon-esque ritual of hubris regarding which one was the better killer, their respective technical campaign staffers were failing to make the grade on security when it comes to taking your donations. Earlier this week, [&hellip;]","og_url":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/","og_site_name":"rud.is","article_published_time":"2012-05-05T11:52:08+00:00","article_modified_time":"2018-03-10T12:53:18+00:00","og_image":[{"url":"https:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary-300x152.png","type":"","width":"","height":""}],"author":"hrbrmstr","twitter_card":"summary_large_image","twitter_misc":{"Written by":"hrbrmstr","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#article","isPartOf":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/"},"author":{"name":"hrbrmstr","@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"headline":"Both Candidates Weak On [SSL] Security","datePublished":"2012-05-05T11:52:08+00:00","dateModified":"2018-03-10T12:53:18+00:00","mainEntityOfPage":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/"},"wordCount":371,"commentCount":3,"publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"image":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#primaryimage"},"thumbnailUrl":"https:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary-300x152.png","keywords":["presidential election"],"articleSection":["Certificates","SSL"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/","url":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/","name":"Both Candidates Weak On [SSL] Security - rud.is","isPartOf":{"@id":"https:\/\/rud.is\/b\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#primaryimage"},"image":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#primaryimage"},"thumbnailUrl":"https:\/\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary-300x152.png","datePublished":"2012-05-05T11:52:08+00:00","dateModified":"2018-03-10T12:53:18+00:00","breadcrumb":{"@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#primaryimage","url":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?fit=817%2C414&ssl=1","contentUrl":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/05\/romney-ssl-summary.png?fit=817%2C414&ssl=1","width":"817","height":"414"},{"@type":"BreadcrumbList","@id":"https:\/\/rud.is\/b\/2012\/05\/05\/both-candidates-weak-on-ssl-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/rud.is\/b\/"},{"@type":"ListItem","position":2,"name":"Both Candidates Weak On [SSL] Security"}]},{"@type":"WebSite","@id":"https:\/\/rud.is\/b\/#website","url":"https:\/\/rud.is\/b\/","name":"rud.is","description":"&quot;In God we trust. All others must bring data&quot;","publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rud.is\/b\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886","name":"hrbrmstr","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","url":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","contentUrl":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","width":460,"height":460,"caption":"hrbrmstr"},"logo":{"@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1"},"description":"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7","sameAs":["http:\/\/rud.is"],"url":"https:\/\/rud.is\/b\/author\/hrbrmstr\/"}]}},"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p23idr-g1","jetpack_likes_enabled":true,"jetpack-related-posts":[{"id":11659,"url":"https:\/\/rud.is\/b\/2018\/11\/17\/tis-the-season-to-check-your-ssl-tls-cipher-list-thrice-rcurl-curl-openssl\/","url_meta":{"origin":993,"position":0},"title":"Tis the Season to Check your SSL\/TLS Cipher List Thrice (RCurl\/curl\/openssl)","author":"hrbrmstr","date":"2018-11-17","format":false,"excerpt":"The libcurl library (the foundational library behind the RCurl and curl packages) has switched to using OpenSSL's default ciphers since version 7.56.0 (October 4 2017). If you're a regular updater of curl\/httr you should be fairly current with these cipher suites, but if you're not a keen updater or use\u2026","rel":"","context":"In &quot;R&quot;","block_context":{"text":"R","link":"https:\/\/rud.is\/b\/category\/r\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":703,"url":"https:\/\/rud.is\/b\/2011\/12\/29\/three-resolutions-for-mac-os-x-users\/","url_meta":{"origin":993,"position":1},"title":"Three Resolutions For Mac OS X Users","author":"hrbrmstr","date":"2011-12-29","format":false,"excerpt":"In 2011, we saw a large increase in web site exploits that exposed private user data as well as a breakdown in the trust of SSL (for various reasons) and the introduction of real malware on to the OS X scene. If there were just three things I could ask\u2026","rel":"","context":"In &quot;Firewall&quot;","block_context":{"text":"Firewall","link":"https:\/\/rud.is\/b\/category\/firewall\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":187,"url":"https:\/\/rud.is\/b\/2011\/02\/23\/herding-firesheep\/","url_meta":{"origin":993,"position":2},"title":"Herding [Fire]sheep","author":"hrbrmstr","date":"2011-02-23","format":false,"excerpt":"By now, many non-IT and non-Security folk have heard of Firesheep, a tool written by @codebutler which allows anyone using Firefox on unprotected networks to capture and hjijack active sessions to popular social media sites (and other web sites). The sidebar\/extension puts an attactive and easy-to-understand GUI over a process\u2026","rel":"","context":"In &quot;Information Security&quot;","block_context":{"text":"Information Security","link":"https:\/\/rud.is\/b\/category\/information-security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":12636,"url":"https:\/\/rud.is\/b\/2020\/01\/29\/monitoring-website-ssl-tls-certificate-expiration-times-with-r-openssl-pushoverr-and-dt\/","url_meta":{"origin":993,"position":3},"title":"Monitoring Website SSL\/TLS Certificate Expiration Times with R, {openssl}, {pushoverr}, and {DT}","author":"hrbrmstr","date":"2020-01-29","format":false,"excerpt":"macOS R users who tend to work on the bleeding edge likely noticed some downtime at <mac.r-project.org> this past weekend. Part of the issue was an SSL\/TLS certificate expiration situation. Moving forward, we can monitor this with R using the super spiffy {openssl} and {pushoverr} packages whilst also generating a\u2026","rel":"","context":"In &quot;R&quot;","block_context":{"text":"R","link":"https:\/\/rud.is\/b\/category\/r\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":588,"url":"https:\/\/rud.is\/b\/2011\/06\/14\/weis-2011-session-2-identity-the-inconvenient-truth-about-web-certificates\/","url_meta":{"origin":993,"position":4},"title":"WEIS 2011 :: Session 2 :: Identity :: The Inconvenient Truth About Web Certificates","author":"hrbrmstr","date":"2011-06-14","format":false,"excerpt":"Nevena Vratonjic Julien Freudiger Vincent Bindschaedler Jeane-Pierre Hubaux Presentation [PDF] Twitter transcript #weis2011 Overview of basic ssl\/tls\/https concepts. Asking: how prevalent is https, what are problems with https? #weis2011 Out of their large sample, only 1\/3 (34.7%) have support for https, login is worse! only 22.6% < #data! #weis2011 (me)\u2026","rel":"","context":"In &quot;Certificates&quot;","block_context":{"text":"Certificates","link":"https:\/\/rud.is\/b\/category\/certificates\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":968,"url":"https:\/\/rud.is\/b\/2012\/04\/28\/slaying-the-beast-in-nginx\/","url_meta":{"origin":993,"position":5},"title":"Slaying the BEAST in nginx","author":"hrbrmstr","date":"2012-04-28","format":false,"excerpt":"Just a quick post as I noticed that my nginx configuration was vulnerable to the BEAST attack thanks to the #spiffy SSL Certificate Tester from Qualys (I scored an \"A\", btw :-). The nginx docs show how to do this, now, and it's pretty simple (very similar to the Apache\u2026","rel":"","context":"In &quot;Certificates&quot;","block_context":{"text":"Certificates","link":"https:\/\/rud.is\/b\/category\/certificates\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/comments?post=993"}],"version-history":[{"count":0,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/993\/revisions"}],"wp:attachment":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/media?parent=993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/categories?post=993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/tags?post=993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}