Slings and Arrows
Graduate Poster
Just so we're clear. To the best of my knowledge someone reported they found certs were not purchased. Unless you can provide direct evidence that NO encryption was present, the best you can say no evidence has been found that the servers were encrypted. I know to the HDS folks among us that's a distinction w/o a difference. To those with technical knowledge, the difference is significant.
Just to remind. I manged a team of system admins who supported fortune 100 web sited, department stores, insurance companies, professional sports leagues, etc. Many of which, at some point, were using self signed certs as a temporary/interim encryption solution until signed ones were obtained.
"Venafi, a Salt Lake City computer security firm, has conducted an analysis of clintonemail.com and determined that 'for the first three months of Secretary Clinton’s term, access to the server was not encrypted or authenticated with a digital certificate.'”
Reference:
Hillary Clinton’s email access was unencrypted, vulnerable to spies (March 11, 2015)
Last edited: