• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Digital Grog — Australia’s Tech, Gadgets & Digital Life Unfiltered

Digital Grog is Australia’s go‑to tech blog for sharp reviews, digital trends, AI tools, gadgets, cybersecurity updates, and practical how‑tos covering the latest in Aussie technology

  • About Us
  • Contact Us
  • Block Examples
  • Landing Page

Defence-in-depth – protecting us from ourselves

August 28, 2016 by admin Leave a Comment

security for wordpress plugins  themes with https and ssl

It really is astonishing how many cyber-attacks we hear about in the media. How can these companies that have become household names be so vulnerable to attack?

It’s a little bit disillusioning, in a lot of ways like finding out that a superhero isn’t real. We waggle our finger and chastise, but sometimes it’s worth taking a step back and looking at our own cyber hygiene. The tech industry is booming, and for a long time the mantra has been “how easy can we make this for the consumer?”. At the end of the day, this has done the average computer user a tremendous disservice. It’s all of our responsibilities to follow secure practices, and the best way to do that is to practice what the security community refers to as “defense-in-depth”.

By making sure that we follow secure practices every step of the way, we can protect ourselves from one or even many failing. Some of the biggest offenders might surprise you, and some you might have been aware of but never had it hit home exactly how this can be exploited. This article aims to take a practical approach at how failing to follow safe practices can easily be manipulated.

 

Thinking HTTP is okay on your local network:

security for  wordc press websites  in 2016Gone are the days where we can trust your local network. Each piece of equipment should be configured such that it believes every other piece of equipment is potentially malicious. BYOD (Bring Your Own Device) has become a very popular paradigm for corporations, but it means that someone might bring an infected device onto the network. It’s absolutely trivial for say, malware to put the infected user’s NIC into promiscuous mode and sniff specifically for authentication over HTTP. Then, your credentials get stolen and possibly used to log into a machine that allows RDP access for all domain members (any machine).

Numerous privilege escalation attacks exist allowing the attacker to then simply monitor main memory (RAM) for juicier credentials. Always use https, for all of your communications, and ideally only allow ECDHE ciphers to allow for Perfect Forward Secrecy.

Not treating your private keys like a valuable:

As you should all know by now, SSL/TLS functions by establishing a shared session key (symmetric encryption) by forging a temporary secure channel via public key cryptography (asymmetric encryption). This relies on generating a public/private keypair.

The private key is known only to the secure web endpoint, and the public key is your certificate which must be signed by a trusted third party (a CA, like SSLTrust.AU) for browsers to mark it as safe to visit. What happens if you’re lax with the private key though? Well, it depends. If communication is over SSL/TLS with a cipher that utilized Diffie-Hellman with large enough parameters, you’re still safe.

This kind of cipher guarantees that even if the private key is compromised, the communication remains illegible by use of constantly changing session keys. Without this special kind of cipher though, an attacker could have been sitting on your communication for months, waiting for you to do something insecure like generating the keypair on your laptop and then leaving it in the open. Then, the attacker merely needs to open up wire shark, provide it with the private key, and can read the communication – passwords and all! Protect your private keys – they are passwords.

The best way to store these certificates is in an HSM – a hardware module that makes absolutely sure the key can never leave the device. They’re expensive, but if you can afford one they’re well worth it. Did you know that even if you mark a private key as non-exportable in Windows that it can still be easily exported?

Blindly trusting certificates, or worse, root certificates:

How many times has it happened to you? “Just click past the SSL/TLS warning. Trust the cert.” This one boggles my mind how many professionals don’t realize this – a self-signed cert is its own root certificate. They’re not inherently dangerous, in that if you take proper precautions you’re limiting your exposure, but how many of you realize that every time you add a self-signed cert to your root certificate store that that route certificate can now be used in conjunction with manipulating your routing in order to pose as legitimate for any site or service?

With an SSL/TLS intercepting forward proxy, an attacker can sit between you and any legitimate service, inspecting all traffic in the clear. All they have to do is control any hop before you get to the internet, and they can route through their own malicious service. If they can run an executable on your machine with an administrative user’s context, they can also poison your static route table and accomplish the same thing. If this happens, the only thing protecting you from sure ruin is that your browser does not trust the SSL/TLS cert of their malicious endpoint!

If you ever hop onto a free Wi-Fi hotspot, and it wants you to install something on your computer before you connect, it’s game over. That’s both protections from your traffic being decrypted transparently being stripped in one fell swoop. Make sure you don’t reuse keys between different services if it’s not needed, however tempting!

Not using Extended Validation certs for your business:

Hear me out on this one. I know that they’re more expensive and that we have a vested interest in selling them to you, but they really do make a difference. The extra verification procedures protect the end user against a lot of shenanigans – time and time again people are able to game automated systems that use a poor algorithm for choosing administrative contact email addresses for verification. Having to revoke a certificate, especially a wildcard certificate, that your clients trust can do a lot of harm to your reputation.

Conversely, extended validation certificates can help bring in security conscious clients who see that you’ve gone the extra mile for them to conduct business with you safely. They can’t see the measures you’ve got behind the scenes. They need to accept on blind faith that you hash and salt their credentials correctly. This is something they can see, and it does make a difference.

Security for your websites should definitely be a priority for your privacy and your users privacy, and while taking measures to minimize breaches make it more secure, there is no fool proof way to 100% secure a website.

As they say “Prepare for Disaster: Recover Faster”

paul bakaPaul Baka is an Account Manager for Website Security Solutions, SSLTrust [https://www.ssltrust.com.au] Specialising in Website and Server Security for small to medium sized businesses and educational institutions, SSLTrust has fast become Australia’s #1 source for SSL Certificates, Code Signing Certificates, Security Scanners and Cyber Security Support.
Paul specialises in industry leading brands including Symantec, GeoTrust, Thawte and Comodo. He guides customers through the process of selecting and installing the optimal solution for their needs.

Filed Under: Hackers, Internet, Software, Solution Tagged With: Websites

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Underwater Drones for Recording Video and Taking Pictures
  • Why I chose hostgator for blog hosting
  • Top 10 Software Programs For Your Windows PC
  • What you should know before investing in Cryptocurrency and bitcoin
  • The Best Social Media Platforms for Marketing a Gaming App

Recent Comments

  1. Patrick McCormick on How to secure your desktop and laptop with antivirus software
  2. JJ on 20 Top brands with affilate programs to make you money in 2019
  3. JJ on This WPengine Genesis Pro Deal Will Give You 35 Studiopress themes
  4. Lisa Gomes on 16 Ways to Make Money Online Working From Home
  5. KatVine on This WPengine Genesis Pro Deal Will Give You 35 Studiopress themes

Archives

  • June 2022
  • February 2022
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • November 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • July 2018
  • June 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010

Categories

  • $heldon $ingh
  • 2010
  • 2011
  • 2012
  • 2013
  • 2015
  • 2017
  • 2018
  • 2019
  • 2020
  • 2021
  • 2022
  • Accounting
  • Adsense
  • Affiliate
  • Amazon
  • Anti Virus
  • Apple
  • Apps
  • Asus
  • Aussie
  • Australia
  • Australian
  • Australian Bloggers
  • Australian wordpress hosting
  • Banks
  • Blog-Hosting
  • Blogger
  • Blogger Tool
  • Blogger Tools
  • BloggerTools
  • BuddyPress
  • CARS
  • CDN
  • Celebrity
  • Clickbank
  • Compare
  • Computer
  • Domains
  • Done Deals
  • Ebook
  • Email
  • Facebook
  • Featured
  • Finance
  • Free
  • Gadgets
  • Google
  • Gpost
  • Guide
  • Hackers
  • Hosting
  • India
  • Internet
  • Ipad
  • Kindle
  • Laptop
  • Make money blogging
  • Makemoney online
  • Marketing
  • Melbourne Cup
  • Movies
  • Netbook
  • Network
  • News
  • Online betting account
  • PC
  • Review
  • Search
  • SEO
  • sheldon singh
  • Software
  • Solution
  • Sports
  • Subscribers
  • Taxes
  • Technology News
  • Themes
  • Top 10
  • Tutorial
  • Video
  • Wacky
  • web hosting
  • Website Review
  • Wierd
  • Windows
  • wordpress
  • Wordpress 3.0
  • Wordpress 3.1
  • wordpress themes
  • World cup
  • Wp Answers
  • WP Turbo
  • WPMU

Footer

Design

With an emphasis on typography, white space, and mobile-optimized design, your website will look absolutely breathtaking.

Learn more about design.

Content

Our team will teach you the art of writing audience-focused content that will help you achieve the success you truly deserve.

Learn more about content.

Strategy

We help creative entrepreneurs build their digital business by focusing on three key elements of a successful online platform.

Learn more about strategy.

Copyright © 2026 · Genesis Sample on Genesis Framework · WordPress · Log in