SANS builds digital certificate checker

By

Free tool will monitor changes to web brower certificate lists.

The SANS Internet Storm Center will in the coming months release a tool that will alert users to changes in digital certificate lists held by web browsers.

SANS builds digital certificate checker
The program, designed by SANs Tom Liston will work with all major web browsers and operating systems and will be free of charge. 
Ed Skoudis
 
Counter Hack founder Ed Skoudis announced the tool at RSA 2012 in San Francisco and said it will help users more easily spot rogue certificates that are trusted by web browsers. 
 
He said that such certificate checks should be a function of anti-virus software.
 
"Right now changes can be made to certificate lists that web browsers trust and users might not know," Skoudis said. 
 
"I would love to see it added to AV tools. That should already be a part of AV."

Non-technical end users were particularly exposed to risks in the certificate model. Fraudulent certificates can be used to impersonate web sites and intercept account information.

Security researcher Moxie Marlinspike, who launched the Convergence project as an alternative to the trust model had long-called for the framework to be replaced.
 

 

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?