{"id":85407,"date":"2018-01-20T21:46:18","date_gmt":"2018-01-21T02:46:18","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-09-03T10:17:51","modified_gmt":"2021-09-03T14:17:51","slug":"browser-security-updates","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/browser-security-updates\/","title":{"rendered":"Browser Security Updates"},"content":{"rendered":"<p><a href=\"https:\/\/www.telegraph.co.uk\/technology\/microsoft\/8239342\/Microsofts-Internet-Explorer-loses-top-spot-to-Firefox.html\" target=\"_blank\" rel=\"browser security updates noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"Browser Security Updates\" src=\"https:\/\/i0.wp.com\/secure.i.telegraph.co.uk\/multimedia\/archive\/01734\/browser-wars_1734382c.jpg?resize=121%2C76&#038;ssl=1\" alt=\"Browser Security Updates\" width=\"121\" height=\"76\" \/><\/a>If you bank, shop, or work on the Intertubes your security is changing. Your browser Security is changing because <strong>Symantec <a href=\"https:\/\/web.archive.org\/web\/20200801032252\/https:\/\/www.digicert.com\/news\/digicert-completes-acquisition-of-symantec-ssl\/\" target=\"_blank\" rel=\"noopener noreferrer\">is selling<\/a> <\/strong>its Website Security and related PKI business to PKI encryption solutions to <a href=\"https:\/\/www.digicert.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">DigiCert<\/a> for nearly <strong>$1 Billion<\/strong>.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-119875\" title=\"SSL and TLS logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ssl-logo-1.jpg?resize=95%2C82&#038;ssl=1\" alt=\"SSL and TLS logo\" width=\"95\" height=\"82\" \/>Experts <a href=\"https:\/\/web.archive.org\/web\/20180218212837\/https:\/\/www.csoonline.com\/article\/3213664\/internet\/symantec-sells-its-problem-ssl-unit-to-digicert-for-1b.html\" target=\"_blank\" rel=\"noopener noreferrer\">estimate<\/a> that <a title=\"Symantec\" href=\"https:\/\/securitycloud.symantec.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Symantec<\/a> (<a title=\"NASDAQ : SYMC\" href=\"https:\/\/wp.me\/p2wgaW-pra\" target=\"_blank\" rel=\"noopener noreferrer\">SYMC<\/a>) owns 40% of the SSL certificate market. <strong>SSL\/TLS certificates<\/strong> are used to encrypt the connections between browsers and HTTPS-enabled websites. The certificates are used to verify that users are actually visiting the websites they intended to and not spoofed versions. Certificates are issued by organizations known as certificate authorities that are trusted by default in browsers and operating systems.<\/p>\n<p>As a result of the sale, many firms are going to have to <strong>reissue<\/strong> <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/SSL-certificate-Secure-Sockets-Layer-certificate\" target=\"_blank\" rel=\"noopener noreferrer\">SSL\/TLS server certificates<\/a>. The reissued certs will ensure browser security and make sure there is no impact on your online experiences. These certificates are essential to ensure <strong>secure, encrypted<\/strong> communication for user interaction on the Intertubes.<\/p>\n<h3><a href=\"https:\/\/www.godaddy.com\/web-security\/multi-domain-san-ssl-certificate\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright \" src=\"https:\/\/i0.wp.com\/www.synergymktsolutions.com\/wp-content\/uploads\/2018\/02\/SSL.png?resize=120%2C90&#038;ssl=1\" width=\"120\" height=\"90\" \/><\/a>Google Chrome browser security<\/h3>\n<p><strong><a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">G<\/a><\/strong><strong><a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">oogle<\/a> <\/strong>(<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>)\u00a0has led the effort to decrease the disruption that could come along with this change. Google posted a <strong><a href=\"https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/blink-dev\/eUAKwjihhBs%5B1-25%5D\" target=\"_blank\" rel=\"noopener noreferrer\">plan<\/a><\/strong> back in July of 2017 regarding Symantec-issued SSL\/TLS server certificates.<\/p>\n<p style=\"padding-left: 30px;\">\u2022 In March 2018 <a href=\"https:\/\/www.google.com\/chrome\/browser\/desktop\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">Google Chrome<\/a> (Chrome 66 Beta) will show a warning for sites secured with SSL\/TLS certificates issued before June 1, 2016. Your security is at risk and data encryption will function normally, but your transactions will be disrupted by a <strong>warning in Chrome<\/strong>.<br \/>\n\u2022 Google has also stated that all SSL\/TLS certificates that had been issued by Symantec before December 1, 2017, will not be trusted starting in September 2018 (Chrome 70 Beta). Doing transactions at sites that have not been updated will put your <strong>security at risk<\/strong>, and you will get a warning in Chrome.<\/p>\n<h3>Mozilla Firefox<\/h3>\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Mozilla<\/strong><\/a>, publisher of the <a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Firefox<\/strong> web browser<\/a> <a href=\"https:\/\/groups.google.com\/forum\/#!topic\/mozilla.dev.security.policy\/_nQpJnJnQEI\" target=\"_blank\" rel=\"noopener noreferrer\">says<\/a> that it intends to follow the same timeline proposed by Google.<\/p>\n<p><strong><em>rb-<\/em><\/strong><br \/>\n<em> This change is a <strong>normal procedure<\/strong> for typical certificate renewal. There should be no service disruption when the new certificates are issued as long as your web browser is up to date. There is no reason to have an out-of-date browser anymore. All three major <strong>browsers will auto-update<\/strong>. Other keys to staying safe online include:<\/em><\/p>\n<ul>\n<li><em>Always check for <strong>HTTPS<\/strong> when you plan on providing personal data to a website. <\/em><a href=\"https:\/\/www.howtogeek.com\/181767\/htg-explains-what-is-https-and-why-should-i-care\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" title=\"Always check for HTTPS\" src=\"https:\/\/i0.wp.com\/web.archive.org\/web\/20191025134631\/https%3A\/\/www.howtogeek.com\/wp-content\/uploads\/2017\/03\/ximg_58cb2b0b07c08.png.pagespeed.gp%2Bjp%2Bjw%2Bpj%2Bws%2Bjs%2Brj%2Brp%2Brw%2Bri%2Bcp%2Bmd.ic.pP8A5Hdi7A.png?resize=349%2C161&#038;ssl=1\" alt=\"Always check for HTTPS\" width=\"349\" height=\"161\" \/><\/a><\/li>\n<\/ul>\n<ul>\n<li><em>Pay attention to any <strong>security warnings<\/strong> you receive when you visit a website. Although you can almost always trust the HTTPS you see in your browser URL, any additional warnings from your browser should show that there may be a problem with the connection, so you should proceed with caution.<\/em><\/li>\n<\/ul>\n<p><em>Nearly 54% of all U.S. web browsers will be affected by these changes. <a href=\"https:\/\/www.statista.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Statista<\/a> <a href=\"https:\/\/www.statista.com\/statistics\/545520\/market-share-of-internet-browsers-usa\/\" target=\"_blank\" rel=\"noopener noreferrer\">says<\/a> that Chrome held almost 50% of the browser market share and Firefox held over 5% of the share in December 2017. 41% of Internet users are not covered by this change (Safari 32.7% and IE\/Edge 9%).<\/em><\/p>\n<p><strong>Related article<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20220103201711\/https:\/\/www.techrepublic.com\/blog\/data-center\/ssl-tls-certificates-what-you-need-to-know\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">SSL\/TLS certificates: What you need to know<\/a>\u00a0<a href=\"https:\/\/www.techrepublic.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">(TechRepublic)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Symantec is selling it&#8217;s SSL\/TLS certificate business to DigiCert so Chrome and Firefox browser users may have to update their browser security settings.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3046,1773,2991,824,973,536,92,286,2321,4,305,165,1366],"class_list":["post-85407","post","type-post","status-publish","format-standard","hentry","category-security","tag-3046","tag-chrome","tag-digicert","tag-encryption","tag-firefox","tag-goog","tag-google","tag-https","tag-mozilla","tag-security","tag-ssl","tag-symantec","tag-symc"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/85407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=85407"}],"version-history":[{"count":12,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/85407\/revisions"}],"predecessor-version":[{"id":128968,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/85407\/revisions\/128968"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=85407"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=85407"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=85407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}