The Last Mile of Encrypting the Web: 2023 Year in Review

At the start of 2023, we sunsetted the HTTPS Everywhere web extension.
It encrypted browser communications with websites and made sure users benefited from the protection of HTTPS wherever possible.
HTTPS Everywhere ended because all major browsers now offer the functionality to make HTTPS the default.
This is due to the grand efforts of the many technologists and advocates involved with Let's Encrypt, HTTPS Everywhere, and Certbot over the last 10 years.
While VPNs still serve a purpose, they are no longer necessary just to encrypt your traffic on the web.
Firefox reports that over 80% of the web is encrypted, and Google reports 95% over all of its services.
Let's Encrypt made much of this possible, by serving as a free and easily supported Certificate Authority that issued TLS certificates to 363 million websites.
Let's Encrypt differs from other prominent CAs.
Let's Encrypt from the start encouraged short-lived certificates that were valid for 90 days.
Other CAs were issuing certificates with lifespans of two years.
The CA/B Forum, a voluntary consortium of CAs, browser companies, and other partners that maintain public key infrastructure adopted ballot SC-063.
Which allows 10-day certificates, and in 2026 will allow 7-day certificates.
This pivotal change will make the ecosystem safer, reduce the toll on partners that manage the metadata chain, encourage automation, and push for the ecosystem to encrypt faster, with less overhead, and with better tools.
Chrome will require CAs in its root store to support the Automatic Certificate Management Environment protocol.
We are glad to see the continued push for HTTPS by default, without the users needing to turn it on themselves.
Its Article 45 requires browsers to display website identity with a Qualified Web Authentication Certificates issued by a government-mandated Root Certificate Authority.
These measures hinder browsers from responding if one of these CAs acts inappropriately or has bad practices around issuing certificates.
This framework enables EU governments to snoop on their residents' web traffic.
This would roll back many of the web security and privacy gains over the past decade to a new, yet unfortunately familiar, fragmented state.
We will fight to make sure HTTPS is not set up for failure in the EU. In the movement to make HTTPS the default for everyone, we also need to be vigilant about how mobile devices handle web traffic.


This Cyber News was published on www.eff.org. Publication date: Mon, 25 Dec 2023 17:43:05 +0000


Cyber News related to The Last Mile of Encrypting the Web: 2023 Year in Review

How Autonomous Vehicles are Revolutionizing the Last-Mile Logistics Industry - Cybersecurity will be one of the key concerns as last-mile logistics companies look to enhance efficiency with autonomous vehicles. The growing acceptance of robotaxis is good news for delivery companies who see autonomous vehicles as a tool for ...
9 months ago Cyberdefensemagazine.com
A personal Year in Review to round out 2023 - As you've probably seen by now, Talos released our 2023 Year in Review report last week. It's an extremely comprehensive look at the top threats, attacker trends and malware families from the past year with never-before-seen Cisco Talos telemetry. ...
1 year ago Blog.talosintelligence.com
Vade Releases 2023 Phishers' Favorites Report - PRESS RELEASE. SAN FRANCISCO, Feb. 15, 2024 /PRNewswire/ - Vade, a global leader in threat detection and response with more than 1.4 billion mailboxes protected, today announced its annual Phishers' Favorites report for 2023. Phishers' Favorites ...
10 months ago Darkreading.com
Taking Back the Web with Decentralization: 2023 in Review - In the past few years, there's been an accelerating swing back toward decentralization. Users are fed up with the concentration of power, and the prevalence of privacy and free expression violations, and many users are fleeing to smaller, ...
11 months ago Eff.org
Cybersecurity considerations to have when shopping for holiday gifts - Another aspect of security that many shoppers don't consider this time of year is the security of the products they're buying, even through a legitimate online marketplace. This is a glaring issue with home security cameras and Wi-Fi-connected ...
1 year ago Blog.talosintelligence.com
Year in Malware 2023: Recapping the major cybersecurity stories of the past year - Botnets kept coming back from the dead, ransomware actors found new ways to make money through data theft extortion and threat actors and malware who have been around for more than a decade find ways to stay relevant. After Microsoft blocked macros ...
1 year ago Blog.talosintelligence.com
Samsung 'Sees Fourth-Quarter Chip Rebound' - Analysts expect Samsung to show lowest profit drop in six quarters in latest sign of semiconductor market recovery. Samsung Electronics is expected to report a smaller drop in profits than has become usual over the past year and a half, in the latest ...
11 months ago Silicon.co.uk
12 Essential Steps Mac Users Need To Take At Year End - As the year comes to a close, Mac users should take these steps to ensure their device's security, performance and organization. Here are the year-end steps you should take to ensure your Mac is ready for 2024. After ensuring your Mac's files are ...
1 year ago Techrepublic.com
In the Trenches of Broadband Policy: 2023 Year In Review - Lawmakers recognized this during the pandemic and set in motion once-in-a-generation opportunities to build the future-proof fiber infrastructure needed to close the digital divide once and for all. Monopolistic internet service providers, with ...
11 months ago Eff.org
The Last Mile of Encrypting the Web: 2023 Year in Review - At the start of 2023, we sunsetted the HTTPS Everywhere web extension. It encrypted browser communications with websites and made sure users benefited from the protection of HTTPS wherever possible. HTTPS Everywhere ended because all major browsers ...
11 months ago Eff.org
Poking holes in Google products bagged bug hunters $10M The Register - Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs. The web goliath's 2023 total represents a slight dip compared to the $12 million in bounties it paid the previous year. Hopefully this means ...
9 months ago Go.theregister.com
Fighting For Your Digital Rights Across the Country: Year in Review 2023 - EFF works every year to improve policy in ways that protect your digital rights in states across the country. Thanks to the messages of hundreds of EFF members across the country, we've spoken up for digital rights this year from Sacramento to ...
11 months ago Eff.org
The malware, attacker trends and more that shaped the threat landscape in 2023 - The 2023 Cisco Talos Year in Review is now available to download. Once again, the Talos team has meticulously combed through a massive amount of data to analyze the major trends that have shaped the threat landscape in 2023. Global conflict ...
1 year ago Blog.talosintelligence.com
The Most Dangerous People on the Internet in 2023 - It was a banner year for chaos, present and impending, and all reflected in the digital mirror. Each year, WIRED assembles a list of the most dangerous people, groups, and organizations on the internet-both those who intentionally endanger innocent ...
11 months ago Wired.com
Food and agriculture sector hit with more than 160 ransomware attacks last year - The U.S. food and agriculture sector dealt with at least 167 ransomware attacks last year, according to the leading industry group. In its first annual report, the Food and Agriculture-Information Sharing and Analysis Center said the industry was the ...
8 months ago Therecord.media
Google's Post-Quantum Upgrade Doesn't Mean We're All Protected Yet - Google's announcement was the product of a long chain of events, triggered by NIST choosing Kyber as the candidate for general encryption last year. As a result, Google has announced that it has added Kyber, beginning with version 116 of its Chrome ...
9 months ago Darkreading.com
With Attacks on the Upswing, Cyber-Insurance Premiums Poised to Rise Too - An increase in cyber-insurance claims in 2023, driven by a more active threat landscape, will likely mean that last year's price plateau in cyber-insurance premium costs will be short-lived, according to industry experts. While premium costs fell by ...
11 months ago Darkreading.com
Chainalysis: 2023 a 'watershed' year for ransomware - 2022 was generally seen as a down year for ransomware. CrowdStrike saw the average ransom payment drop from $5.7 million in 2021 to $4.1 million in 2022; Mandiant said it responded to 15% fewer ransomware incidents in 2022 than the previous year. ...
10 months ago Techtarget.com
Cyberattacks on Hospitals Are Likely to Increase, Putting Lives at Risk, Experts Warn - Cybersecurity experts are warning that hospitals around the country are at risk for attacks like the one that is crippling operations at a premier Midwestern children's hospital, and that the U.S. government is doing too little prevent such breaches. ...
10 months ago Securityweek.com
US Consumers Lose a Record $10bn+ to Fraud Last Year - US adults lost over $10bn to fraud in 2023, with investment scams the biggest earner for threat actors, according to the latest figures from the FTC. The figures represent a record high for fraud losses, having increased 14% year on year. Investment ...
10 months ago Infosecurity-magazine.com
Cybersecurity Funding Dropped 40% in 2023: Analysis - The volume of cybersecurity transactions increased in 2023 compared to the previous year, but the total amount of funding secured by companies decreased significantly, according to cybersecurity recruitment firm Pinpoint Search Group. Pinpoint's 2023 ...
11 months ago Securityweek.com
Human error still perceived as the Achilles' heel of cybersecurity - While fears of cyber attacks continue to rise, CISOs demonstrate increasing confidence in their ability to defend against these threats, reflecting a significant shift in the cybersecurity landscape, according to Proofpoint. CISOs' confidence is ...
6 months ago Helpnetsecurity.com
Ransomware in 2023 recap: 5 key takeaways - This provides the best overall picture of ransomware activity, but the true number of attacks is far higher. While some ransomware trends hardly changed over the last year, such as LockBit's continued dominance, ransomware criminals also challenged ...
10 months ago Malwarebytes.com
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
1 year ago Esecurityplanet.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)