What is SSL and why is it not enough when it comes to encryption?
Answer / chaitanya
SSL is identity verification, not hard data encryption. It is designed to be able to prove that the person you are talking to on the other end is who they say they are. SSL and its big brother TLS are both used almost everyone online, but the problem is because of this it is a huge target and is mainly attacked via its implementation (The Heartbleed bug for example) and its known methodology. As a result, SSL can be stripped in certain circumstances, so additional protections for data-in-transit and data-at-rest are very good ideas.
| Is This Answer Correct ? | 0 Yes | 1 No |
What is the difference between an HIDS and a NIDS?
Why would you bring in an outside contractor to perform a penetration test?
What is XSS?
I’m the CEO of a Fortune 500 company. I make more in an afternoon than you make in a year. I don’t care about this stupid security stuff, it just costs time and money and slows everything down. Why should I care about this junk?
How do you protect your home Wireless Access Point?
What is data source in computer?
You see a user logging in as root to perform basic functions. Is this a problem?
How would you lock down a mobile device?
What is data protection in transit vs data protection at rest?
What is your opinion on hacktivist groups such as Anonymous?
You are remoted in to a headless system in a remote area. You have no physical access to the hardware and you need to perform an OS installation. What do you do?
How would you compromise an “Office Workstation” at a hotel?