Posts
The Certificate Expiry Apocalypse: Why Manual TLS Management is a Security Anti-Pattern
Let’s be honest: if your deployment workflow still involves an engineer manually downloading a .crt, pasting it into a web server configuration, and praying to the gods of uptime that they don’t forget to do it again in 90 days… you aren’t running a production environment. You are running a time bomb.
The industry is undergoing a massive compression in certificate lifespans. We’ve moved from years to months, and now—driven by the momentum of Let’s Encrypt and pressure from browser vendors (Apple, Google) favoring high-frequency rotation—we are rapidly approaching an era where 90-day lifespans will feel like an eternity.
read morePosts
Type of Investing Active or Passive - An Introduction
I’d try to elaborate on the options available from the active/passive investments PoV.
Most Passive - VPS: Relatively safer, as you just have to identify the AMC/insurance copmany. Benefits: You can claim upto 20% tax rebate immediately in your tax returns (by claiming it from your employer if you are salaried individual) You have tax free (CGT, SST) compounding, meaning no tax on dividends/bonuses. Drawback: You have to pay extra fees incase of early (before duration of 25Y or age of 60Y) withdrawal.
read morePosts
Curve selection for Digital Signatures
This article explores the most feasible curve for Elliptic Curve Cryptography for the use case of Document Signing as per recommendations from the Guideline/standards formulating bodies.
National Institute for Standards and Technology (NIST) As per NIST’s recommendations (see NIST SP 800-186) P-256, P-384, P-521 (for ECDSA) and Curve25519 and Curve448 (for EdDSA) are recommended as shown below: WebTrust & CAB Forum WebTrust or CA/B forum doesn’t have a dedicated requirements/standard for Document Signing use-case, however, the S/MIME requirements (both in WebTrust and CA/Browser forum) cover this use-case under multi-purpose certificates.
read morePosts
DEEP (Digital Economy Enhancement Project)
DEEP is Pakistan’s (probably) largest Information Security Project with World Bank backed funding of about USD 78 million, and aims to digitize the core of Government services by providing a National Data Exchange Layer (NDEL) and Digital Identity.
Project Goals and Components Enhance Digital Public Infrastructure (DPI): Build capabilities for responsible data exchange, digital authentication, and verifiable credentials to support a digital economy and society. Improve Government Service Delivery: Digitize public services through a national portal and platform-based approach, making them more accessible and efficient, especially for vulnerable groups.
read morePosts
PKI Training Registration Authority
Functions Roles Super Administrator: Security Officer: Admin Registration Authority Officer (RAO): Will have a High Trust Certificate issuing process. and not the natural person certificates. Enterprise RAO: Also known as Local Registration Authority. This role can be deployed in a client enterprise for convenience of customer handling for the provided service. Auditor: This has the view of reviewing logs. High Trust Certificates: SSL certificate, Code-Signing or e-Seal certificate are called high trust certificates because they are issued to the Organizations and can only be issued by the Admin RAO.
read morePosts
PKI Training - ITIL
Following is a list of Services employed via ITIL:
Incident Management: Event Management: Change/Release Management: Asset Management: Configuration Management: Problem Management: Knowledge Management: End Point Protection Knowledgebase: Knowledge articles are created to avoid such issues in the future. Q: Why are we employing ITIL and not some other process (i.e. COBIT)? A: Deployment is not an actual/certifiable ITIL deployment, but to establish a formal minimal deployment of all relevant management and services.
read morePosts
PKI Training - Day3 - Advanced Cryptography 2
Q: Name the extensions in the Certificate. Ans: AIA: CDP: CRL Distribution Point
Public Key Cryptography standards (PKCS) PKCS# 1: Raw Signature standard. This is then used with PKCS# 7 to make it meaningful.
PKCS# 7: Cryptographic Message Syntax Standard Standard describes general syntax for data that may have cryptography applied to it, such as digital signatures and digital envelopes. Also known as CMS - Cryptographic Message Syntax (RFC 5652).
read morePosts
PKI Training Difference between Cryptography and Encryption
Cryptography:
The discipline that embodies the principles, means, and methods for providing information security, including confidentiality, data integrity, source authentication, and non-repudiation. Source(s): NIST SP 800-175B Rev. 1 under Cryptography
It is to be noted that Cryptography provides not only encryption but many other services.
Encryption:
Cryptographic transformation of data (called “plaintext”) into a form (called “ciphertext”) that conceals the data’s original meaning to prevent it from being known or used.
read morePosts
PKI Training Cryptography - Day2
Certificate Path Validation: This is performed for all the identities of the chain. It commonly checks for the following things:
build & validate the certificate chain from the user certificate upto the trusted root. Check for intended purpose Check for expiry or “not yet valid” Check for revoked certificate Certificate Life Cycle Following are the
Register Issue Distribute/Store Use (Sign/Encrypt) Expire/Revoke Renew/Rekey Q: Can ECAC issue an Accreditation Certificate for the usage of Signing process?
read morePosts
Preparing for CEH practical
Ahoy Mates! I have always been interested in Pen-testing but it hasn’t been my day job yet. Avoiding the Certs vs. skills discussion, I want to acquire 1-2 basic pen-testing certs to round out my profile in Cyber Security. Considering that, last year I applied for EC-Council’s CEH scholarship and received the scholarship and I must appear for the practical exam within 1-year. Since then it has been 3-4 months without any progress on the preparation.
read more