Skip to main content
banner image
venafi logo

Browser Security Fails: Can We Trust Your Website?

Browser Security Fails: Can We Trust Your Website?

browser security fails
May 19, 2017 | Emil Hanscom

2017 is nearly halfway over and it’s already been quite the year for web browser security. We’ve grown accustomed to seeing pages that block us from accessing websites with ineffective security methods, especially as organizations move away from vulnerable SHA-1 certificates.

In fact, just last week Microsoft released a security advisory stating websites protected with SHA-1 certificates will no longer load in Microsoft Edge and Internet Explorer 11 web browsers.  

Despite the prospect of their users witnessing unsubtle warnings about their vulnerable certificates, a surprisingly large number of websites do not follow best security practices. In fact, we’ve seen warnings on some pretty surprising, and noteworthy, sites.

For example, Tom Henderson of Network World published an article regarding browser certificate failures on April 25th. According to Tom, when he attempted to access a website affiliated with the US government, a familiar notification popped up.

“My case in point is a website that explains the U.S. Safety Act,” writes Tom. “The Act speaks to the practice of offering legal liability protection for products or services that have been certified for anti-terrorism protection. Any legitimate browser at the moment of this writing will block you from that site and warn you that the chain of authorities needed to vet the site as protected by SSL/TLS does not exist. The site is untrusted.”


Image via Tom Henderson

At this point, the U.S. Safety Act’s website appears to load without issue. However, Safari still brings up the warning Tom encountered. Chrome treats the certificate, which was issued in 2015, as trusted.

Unfortunately, this is not the only example of on certificate misuse online. Users should still display caution when visiting questionable websites.

Are you sure we can trust the certificates on your website? 

Like this blog? We think you will love this.
Featured Blog

With Rapid Rise in Funds Stolen from DeFi Protocols, Private Keys in Play

Massive heist begins with

Read More
Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

Subscribe Now

See Popular Tags

You might also like

TLS Machine Identity Management for Dummies

TLS Machine Identity Management for Dummies

Certificate-Related Outages Continue to Plague Organizations
White Paper

CIO Study: Certificate-Related Outages Continue to Plague Organizations

About the author

Emil Hanscom
Emil Hanscom

Emil is the Public Relations Manager at Venafi. Passionate about educating the global marketplace about infosec and machine-identity issues, they have consistently grown Venafi's global news coverage year over year.

Read Posts by Author
get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more