Subscribe:

Sunday, 7 August 2011

Web Hosting Provider Go Daddy’s Rapid Growth Extends To EV SSL Certificate Market

August 5, 2011 – (HOSTSEARCH.COM) – Go Daddy, the world's largest provider of Web hosting, domain names and net new SSL Certificates, leveraged its pricing and unparalleled customer care to become the second largest EV SSL certificate provider in the world ... showing how giving customers what they want is a winning proposition.

According to a report issued yesterday by leading industry analyst, Netcraft Ltd., "Go Daddy's continued strong growth has caused it to become the second largest EV certificate authority this month." Netcraft's report also states Go Daddy was the fastest growing domain validated SSL provider in the market.

"Our rapid growth in the EV SSL market demonstrates how important it is to give customers what they want - a reliable product at a great price," said Go Daddy President and COO Warren Adelman. "Go Daddy Certificates cost up to 15 times less than our competitors. Our customers know Go Daddy Certificates provide the same industry-standard security as other companies, but are backed by our industry-best customer support." 

Go Daddy began providing SSLCertificate in 2004 with a dedication to its core principles - affordability, ease of use and world-class 24/7 customer care. In 2007, Go Daddy helped draft the guidelines for Extended Validation (EV) certificates, helping improve the security for online transactions dramatically. In June, Go Daddy announced it had surpassed 500,000 SSL certificates under management.

SSL certificates encrypt transactions between servers and browsers to ensure data is kept secure. The process to obtain an SSL certificate varies based on the kind of certificate purchased. Go Daddy's Premium SSL Certificates, or Extended Validation Certificates, require the highest level of identity verification prior to issuance. A site secured by an Extended Validation certificate displays a green address bar in most browsers, along with the organization to which the certificate was issued.

With one-third of the Internet running through its DNS servers, Go Daddy recognizes the role it plays in Internet security. Go Daddy provides an entire security solution - products like SSL certificates and Premium DNS, which protect against traffic redirection and DNS poisoning, help website owners, and visitors alike, stay safe online.

About The Go Daddy Group, Inc.

Go Daddy is a leading provider of services that enable individuals and businesses to establish, maintain and evolve an online presence. Go Daddy provides a variety of domain name registration plans and website design and hosting packages, as well as a broad array of on-demand services. Go Daddy has more than 40 cloud-based products and services. These include products such as SSL Certificates, Domains by Proxy private registration, ecommerce website hosting, blog software, search engine optimization utilities, podcast packages and online photo hosting. The Go Daddy Group has more than 49 million domain names under management. Go Daddy registers, renews or transfers more than one domain name every second of every day. GoDaddy.com is the world's largest Web hosting provider and is the world's No. 1 domain name registrar according to Name Intelligence, Inc. In 2010, The Go Daddy Group registered more than one-third of all new domain names created in the top six generic top-level domains, or gTLDs, including .com, .net, .org, .info, .biz and .mobi.


Source URL:-http://www.hostsearch.com/news/the_go_daddy_group_inc_news_10761.asp

Wednesday, 3 August 2011

Global Cyber Attack Revealed by McAfee


(The Hosting News) – A new breach has been identified in the area of global cyber hacking. Recently internet security company McAfee detailed “Shady Rat,” a hacking operation that targeted 72 top worldwide entities. Such victims included various U.S. defense contractors, government agencies, top companies, the United Nations, and plenty more.

The operation occurred over five years. Although it mostly had U.S. targets, various other victims were based in countries such as Canada, South Korea, Taiwan, Switzerland, and the United Kingdom.

The security company’s analysis of the attack was based off of accessing the intruders’ “Command & Control server.” Despite the magnitude of the breach, McAfee says that most of the targets had already corrected problems caused by the infections.

According to the report, the operation relied on setting up a backdoor channel through malware. Concluding its findings, McAfee stated, “This is a problem of massive scale that affects nearly every industry and sector of the economies of numerous countries, and the only organizations that are exempt from this threat are those that don’t have anything valuable or interesting worth stealing.”

Although the source of the operation wasn’t revealed, many tech analysts have suspected China as the source of various recent cyber-attacks. Despite denying any involvement, the country was said to be the source of a recent high-profile attack on Google’s Gmail service.

Meanwhile, countries such as the United States have looked to increase their efforts against global cyber security threats by working with other nations, as well as developing new technology. Other recent global cyber-attacks have included a breach on defense contractor Lockheed-Martin and one involving the Pentagon (which the U.S. said likely originated from an unidentified nation state).

Besides these larger scale global breaches that seem more mysterious, this year has seen plenty of other attacks where individual hacking groups have openly taken credit for particular breaches.

Groups LulzSec and Anonymous have recently dominated the headlines. LulzSec has been responsible for attacks on sites belonging to Sony, PBS, the U.S. Senate, the CIA, and more while Anonymous has recently targeted the likes of U.S. defense contractor Booz Allen Hamilton and Monsanto, an agricultural company. Fighting back, authorities in various countries have recently arrested people suspected of involvement in the organizations.

Even with all the bad news recently regarding cyber breaches, hopefully such developments have spread awareness and pushed entities to increase their protection against large cyber threats.

You can access the entire report by McAfee in PDF format here: http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf

Alternatives to Wildcard SSL


When browsing the Internet, you may notice that some websites include a padlock next to the URL. This signifies that that website is secured by an SSL certificate, which is short for "Secure Socket Layer." The certificates are used by website developers to encrypt data transmitted on websites. For example, you should be using a SSL Certificate if you will receive customer's credit card or other sensitive information on your website. There are several alternatives to Wildcard SSL.

  1. GoDaddy SSL Certificates

    • GoDaddy offers standard and premium SSL certificates that are used to secure websites. According to the site's description of the two options, the standard certificate validates domain ownership, and secures the site "within minutes." Unlike the premium version, the standard version does not offer a green address bar, which alerts visitors that the site is secure. However, it does offer the padlock icon for covered domains.

    Symantec SSL Certificates

    • Symantec offers more than 70 percent of the SSL certificates on the world's top 1,000 domains. Symentac's offers SSL certificates through its VeriSign service. It also includes daily malware scanning, ensuring that visitors machines will not be infected by visiting your site. Finally, the VeriSign SSL certificates offers the green address bar and the padlock.

    GeoTrust

    • GeoTrust is another option for SSL certificates. The website lists six different SSL certificate options. They are the True BusinessID, True Business ID with EV SSL, True BusinessID Wildcard, UC/SAN and GeoTrust QuickSSL Premium. Each certificate option offers varied features. For example, the True BusinessID certificate offers full authentication and a GeoTrust site seal, while the True BusinessID with Extended Validation offers the same features with an extended warranty.

    Network Solutions

    • Network Solutions also offers five different SSL certificate options: Limited Verification, Basic and Advanced Business/Organization Verification, along with Wildcard SSL Certificate and Extended Verification. The major differences between these are the degree of warranty for each package, along with the difference in organization sizes. For example, large organizations may prefer the "Wildcard" or the "Extended Verification," which both include a larger warranty than the smaller packages. Each also offers the browser padlock and a site seal.

Tuesday, 2 August 2011

Microsoft adds free root certificate authority to Windows


A couple of weeks ago some very interesting Windows news flew by under the radars that I think deserves much more credit than it received, considering how much we rely on the web and the impact this has on making it safer.
In the September 2009 update to the Windows Root Certificate Program, Microsoft has added to the list of trusted root certificate authorities StartCom Ltd, notably its first member who issues amongst others free SSL digital certificates.
What this means in practice is that out-of-the-box in Windows 7and if installed as an optional patch under Windows Vista and XP, free digital certificates issued by StartCom will be inherently trusted by the operating system and its applications.
Besides simple identification, one other benefit delivered by digital certificates is the ability to transparently encrypt and secure the connection to a server via HTTPS and this is what makes what Microsoft did so notable.
Up and until now the Digital Certificates market has been dominated by large corporations who charge quite a pretty penny for the privilege, limiting the use of HTTPS. Unfortunately at the same time due to the nature of digital certificates and the chain of trust, a limited number of root certificate authorities (CA) in operating systems such as Windows has limited the adoption of free digital certificates as offered by some companies like StartCom. Granted Firefox and Safari has supported many of the certificate authorities issuing free certificates for some time, Microsoft has not, until now.
With StartCom as a Windows root CA, web developers now have a practical free alternative for digital SSL Certificate if they wish to secure their websites or web services that by default works with Internet Explorer and other Windows applications.
Not only is this great for developers but even more so users who can look forward to more websites that encrypt the data they send to and receive from – reducing the risks of sniffing and man-in-the-middle vulnerabilities, especially when using wireless and public networks.

GlobalSign Expands Online Security Offerings to Canadian Market


GlobalSign (www.globalsign.com), a specialist in Digital Certificate and PKI security, today announced the availability of its leading Digital Certificate and SSL products through the launch of a new dedicated Canadian website (globalsign.ca). With language options for sales and support now available in both English and French, GlobalSign can support its growing Canadian customer base and partner network.

As expansion in e-commerce and web service deployments continue to accelerate in Canada, more and more online businesses are in need of security solutions to protect their websites, online data, and intellectual property and ensure they are safe from phishing attacks and online fraud. The most common protocol used today is the Secure Sockets Layers (SSL) which essentially provides a secure channel between two machines operating over the internet or internal network. The SSL market in Canada experienced growth of over 20% during the last year, becoming the sixth largest market for SSL Certificate usage worldwide.*

GlobalSign’s Canadian web site will have both English and French language content available to aid Canadian customers in deploying the strongest SSL Security and associated services. By launching a website catered directly for Canadian customers, GlobalSign aims to help protect individuals and organizations against ever growing online security threats by supporting new customers and educating them on how to look for strong website security. GlobalSign is also aiming to contribute to overall SSL market growth and following recent industry upheavals will seek to attract customers who are apprehensive about their existing SSL provider and seeking a more stable alternative.

GlobalSign will be offering its full range of SSL Certificate via the new website, including fast issuance Domain Validated SSL and the most advanced Extended Validated EV SSL Certificate, which activate the green address bar in new high security browsers such as IE, Firefox, Opera, Chrome and Safari. Customers will be able to easily and conveniently purchase SSL to secure their websites, online transactions, web mail and other next generation online services using GlobalSign’s highly trusted and future-proof technology. All GlobalSign Certificates include Server Gated Cryptography (SGC) (to “step up” weak browser-to-server-connections to strong encryption levels), have the option of including additional premium features (for example, Subject Alternative Names (SANs) and wildcard characters to allow the securing of multiple domain names, sub domains, IP addresses or hostnames with a single Certificate). All Certificates are issued from GlobalSign’s 2048 bit Certificate Authority Root, pre-installed in all browsers, operating systems and mobile devices.

“Launching a localized suite of services for the Canadian market and catering to Canada’s language requirements further proves GlobalSign’s ongoing commitment to our global customers,” said Motto Noda, CEO, GMO GlobalSign Inc., “This expansion will improve sales and support services for our existing Canadian customers and offer a much needed alternative to the standard market players.”

GlobalSign SSL Certificates are currently available to order in English or French at http://www.globalsign.ca

*Source: netcraft.com

About GlobalSign:-

Established in 1996 and as a WebTrust accredited public certificate authority, GlobalSign offers publicly trusted SSL Certificates, EV SSL, Managed SSL Services, S/MIME email security andCode Signing for use on all platforms including mobile devices. Its Trusted Root solution uses the widely embedded GlobalSign Root CA certificates to provide immediate PKI trust forMicrosoft Certificate Services and internal PKI, eliminating the costs of using untrusted Root Certificates. Its partnership with Adobe to provide Certified Document Services (CDS) enables secure digitally signed PDF documents, certified transcripts and e-invoices.  These core Digital Certificate solutions allow its thousands of authenticated customers to conduct secure online transactions, data transfer, distribution of tamper-proof code, and protection of online identitiesfor secure email and access control.  The company has a history of innovation within the online security industry and has offices in the US, UK, Belgium, Japan, and China.

GMO Internet Group:-

GMO Internet Group, headquartered in Japan, is a leading force in the Internet industry offering one of the most comprehensive ranges of Internet services worldwide. The group holds top domestic market share in domain registration, web hosting, and payment processing and provides a host of other Internet services including global online security services, e-commerce solutions, and Internet advertising to both businesses and individuals. At the centre of the group is GMO Internet, Inc. a company listed on the prestigious first section of the Tokyo Stock Exchange (TSE: 9449). Please visit www.gmo.jp/en for further details.

For further details please contact:-

GlobalSign Singapore

Tel: (toll-free) 800-101-2546


Monday, 1 August 2011

Is the Green Bar Worth it, or is Extended Validation (EV) SSL a Scam?


Many SSL shoppers don't know the difference between the various certificates or can't ascertain the value of one versus another; and often figure that "an SSL certificate is an SSL certificate," and the pricing differences are really just a way for the certificate authorities and other SSL businesses to make more profit. In this article, I'd like to try to refute that notion and give you a sense of how EV -- the type of SSL that generates the green address bar indicators in Internet Explorer, Google Chrome, and Firefox -- might be of value to your business/organization or the businesses/organizations you represent.

  • Why EV SSL Means a Safer Web
  • How EV Increases Online Profits
  • How EV Can Reduce the Effectiveness of Phishing
  • Making EV Application Fast & Easy

 


Any further questions regarding EV can be directed to me, The SSL Store Retail/Enterprise Director Kent Roberts, at (727) 820-1161. Alternately, you can use our Live Chat or write to sales@thesslstore.com.

Source URL:-https://www.thesslstore.com/ev/is-the-green-bar-worth-it.aspx

The Risks In Wildcard Certificates


They may not be real-world problems, but Wildcard Certificate have some definite theoretical problems. But they can be so much cheaper that users will buy them anyway.



The imperative to use SSL, for web authentication and encryption or VPNs, is reasonably universal. Competition has driven prices of certificates down over the years to the point where you can get conventional SSL certificates from reputable vendors for well under $100 per year.

Another product gaining popularity due to competition is the Wildcard SSL Certificate. A conventional certificate works on a single domain, e.g. www.foo.com. A wildcard certificate protects all subdomains of a domain subject to the use of wildcard characters in the name. So a wildcard certificate for *.foo.com protects www.foo.com, bar.foo.com, mail.foo.com, chasephish.foo.com, and so on.

I have received many notes from vendors about them, both as press and as a prospective customer. Most CAs (certificate authorities) clearly see them as a way to grow markets. If you've got a lot of domains you can save a lot of money with a wildcard certificate relative to buying individual certificates for them, but not from all vendors. VeriSign, the 800 lb. gorilla in the CA room, prices wildcard certs by the domain being protected, so that they don't save much, if any money outright.

There is still a potential to save in convenience of administration with a wildcard certificate. But there are real downsides to wildcard certificates. When things go wrong the convenience may evaporate quickly. The VeriSign site lists their take on the disadvantages of wildcard certs:
  • Security: If one server or sub-domain is compromised, all sub-domains may be compromised.
  • Management: If the wildcard certificate needs to be revoked, all sub-domains will need a new certificate.
  • Compatibility: Wildcard certificates may not work seamlessly with older server-client configurations.
  • Protection: VeriSign Wildcard SSL Certificate are not protected by NetSure extended warranty.

I hope it doesn't need to be said that VeriSign, as the dominant market player, has an interest in prices remaining high, so take their advice on wildcards in that light. The last point is VeriSign saying that wildcards get a lesser level of service from them, so that's not a problem inherent in the technology, but the other 3 points are reasonable generally.