< ciso
brief />
Tag Banner

All news with #encryption in transit tag

59 articles

Cloudflare adds TLS post-quantum visibility tools

🔒 Cloudflare has added post-quantum (PQ) cryptography visibility into its Application Security and Logs products, enabling customers to inspect TLS key exchange algorithms in Logpush, Log Explorer, and HTTP Traffic Analytics. The update surfaces the negotiated key exchange per incoming request so teams can audit PQ adoption, assess compliance, and identify cryptographic gaps across domains. Cloudflare highlights X25519MLKEM768 as the primary TLS 1.3 PQ key-exchange and provides guidance for enabling TLS 1.3 and collecting PQ telemetry.
read more →

Amazon RDS Adds Post‑Quantum TLS for PostgreSQL

🔐 Amazon RDS for PostgreSQL now supports post-quantum TLS (PQ-TLS) key exchange to provide post-quantum cryptography options for data in transit. RDS for PostgreSQL versions 18 and higher allow modification of the ssl_groups parameter so administrators can pick cryptographic groups from the RDS allow list. Customers can deploy or update managed PostgreSQL instances through the Amazon RDS Console or the AWS CLI to enable these options.
read more →

Amazon RDS Adds Latest Community MariaDB Minors

🆕 Amazon RDS for MariaDB now supports community minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, which include operational improvements and post-quantum TLS (PQ-TLS) key exchange support for in-transit encryption. AWS recommends upgrading to gain CVE fixes, bug fixes, performance improvements, and new features. You can upgrade via Blue/Green deployments, in-place upgrades, or snapshot restores, and automate rollouts with automatic minor upgrades and the AWS Organizations Upgrade Rollout Policy. Migration from external MariaDB sources is supported via AWS Database Migration Service.
read more →

Amazon Aurora MySQL 8.4.8: PQ‑TLS and replication

🔒 Amazon Aurora MySQL-Compatible Edition 8.4 now supports MySQL 8.4.8, introducing security enhancements and bug fixes plus features such as post-quantum TLS (PQ-TLS) key exchange, transaction timeout, multi-source replication, and delayed replication. These additions strengthen in-transit encryption options and improve operational resilience by preventing long-running transaction impacts and enabling consolidated or lagged replicas for recovery and reporting. Upgrades are available via automatic minor version upgrades during scheduled maintenance and supported across all AWS Regions where Aurora MySQL is offered.
read more →

Android 17 adds OS‑wide ECH to shield connections

🔒 Google announced Android 17 will add system‑level support for Encrypted Client Hello (ECH) to obscure domain names and prevent network eavesdropping. The update enables ECH GREASE by default so connections to non‑ECH servers remain indistinguishable, and OkHttp has integrated ECH for third‑party apps. Android 17 also enforces Local Network Protection, enables Certificate Transparency by default, and allows carriers to disable 2G to mitigate downgrade and SMS blaster attacks.
read more →

Android 17 Adds ECH to Strengthen Connection Privacy

🔒 Android 17 introduces network protections including support for Encrypted Client Hello (ECH) to hide visited domain metadata and work alongside private DNS. The platform-level ECH support encrypts the TLS Client Hello hostname, reducing ISP and Wi‑Fi operator visibility when using compatible apps and browsers. ECH will be enabled by default for apps targeting Android 17 that use supported networking libraries, with a GREASE fallback for non‑ECH servers to avoid detection.
read more →

Amazon RDS for MySQL 8.4.11 Now Supported

🚀 Starting today, Amazon RDS for MySQL supports community MySQL minor version 8.4.11, which includes operational improvements and introduces post-quantum TLS (PQ-TLS) key exchange for enhanced in-transit encryption options. AWS recommends upgrading to newer minor versions to receive CVE fixes, performance improvements, and bug fixes provided by the MySQL community. You can use automatic minor version upgrades during maintenance windows or Amazon RDS Managed Blue/Green deployments for safer updates.
read more →

Storage Gateway adds FIPS PrivateLink support

🔒 AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape Gateway and Volume Gateway. Previously restricted to the public internet, FIPS traffic can now stay on the private AWS network, simplifying use for regulated workloads. To use it, create a FIPS interface VPC endpoint and choose the FIPS option when activating your gateway; gateways must run software version 3.2.7 or later. The feature is available in eight Regions, including US East, US West, and AWS GovCloud.
read more →

Signal adds automatic key verification feature

🔐 Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contacts’ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more →

End-to-End Encryption and the Going Dark Debate

🔐 This article summarizes a new paper updating 2012 research on encryption and globalization, focusing on “Round 3” of the Going Dark Debate over end-to-end encryption (E2EE). It outlines the technical foundations, market changes, and government proposals to limit E2EE for law enforcement and national security. The paper identifies five distinct E2EE scenarios and explains why broad restrictions would harm cybersecurity, commerce, and government operations. It concludes by urging skepticism toward new claims for restricting effective encryption, noting persistent lessons from prior rounds.
read more →

AWS Direct Connect 100G expansion in Lima, Peru

📢 AWS has expanded 100 Gbps dedicated Direct Connect capacity at the Cirion data center in Lima, Peru. This location now supports private connections to all public AWS Regions (excluding China), AWS GovCloud, and AWS Local Zones, and is the first in Peru to offer 100 Gbps with MACsec encryption. Direct Connect provides private, physical links between AWS and customer data centers, offices, or colocation environments to deliver more consistent network performance than the public internet.
read more →

Declarative VPC Encryption Controls for AWS Organizations

🔐 You can now use declarative policies to enable VPC Encryption Controls in monitor or enforce mode across all VPCs in your environment. This capability lets security teams centrally define and apply consistent encryption-in-transit settings for an account, organization, or specific organizational unit. The feature provides centralized visibility into Encryption Controls status for all accounts and VPCs and is available in all AWS regions that support VPC Encryption Controls. There is no additional charge to use declarative policies in AWS Organizations.
read more →

Google Cloud advances Confidential Computing for AI

🔒 Google Cloud announces expanded Confidential Computing capabilities to protect data in use for AI workloads. The update includes Confidential G4 VMs with NVIDIA RTX PRO 6000 Blackwell GPUs, open-source Prompt Encryption SDKs, Intel TDX on C4 machines, and broader Confidential Space enhancements. These innovations aim to provide verifiable attestation, end-to-end encrypted inference, and support for multi-party collaboration while preserving performance and scalability.
read more →

Amazon MSK Replicator adds mTLS support for Express

🔒 Amazon MSK Replicator now supports mutual TLS (mTLS) authentication for replicating data from external Apache Kafka clusters — including on‑premises, self‑managed on AWS, or other cloud providers — to Amazon MSK Express brokers. This enables migrations, disaster recovery, and hybrid or multi‑cloud data distribution using mTLS‑configured external clusters. MSK Replicator automates replication while preserving topic names and avoiding infinite loops, and also synchronizes consumer group offsets bidirectionally to allow independent movement of producers and consumers.
read more →

XChat launch raises serious privacy and security doubts

🔒 Elon Musk’s XChat launched on iOS in April 2026 as a purportedly private messaging alternative, but its encryption model and key handling have raised alarm among experts. XChat stores users’ private keys on servers protected by HSMs and uses four-digit PINs to encrypt those keys for multi-device sync, a design that undermines classic end-to-end guarantees. Practical issues — message requests sent without E2EE, confusing PIN prompts, and weak brute-force protection — further complicate user security. The net result: XChat offers convenience at the cost of meaningful privacy assurances.
read more →

Amazon Aurora MySQL Adds MySQL 8.4 Support

🔒 Amazon Aurora MySQL-Compatible Edition now supports community MySQL 8.4, aligning Aurora version numbers with community releases and managing underlying patches for customers. The release enforces stronger security defaults—TLS 1.2/1.3 only and caching_sha2_password for new accounts—and offers customizable password validation via DB cluster parameter groups. Automated upgrade prechecks reduce upgrade risk, and multiple upgrade and migration paths are supported, including Blue/Green Deployments and AWS DMS.
read more →

Discord Rolls Out End-to-End Call Encryption Globally

🔒 Discord has enabled default end-to-end encryption (E2EE) for all voice and video calls after completing the deployment in March. The company extended the open-source DAVE protocol across desktop, mobile, web browsers, PlayStation, Xbox and Discord SDKs, and is removing legacy unencrypted fallback code. The encryption layer now covers DMs, group DMs, voice channels and Go Live streams, while Stage channels remain excluded. Discord says it has no current plans to apply DAVE to text due to major engineering constraints tied to its existing messaging architecture.
read more →

Apple and Google Enable Cross-Platform E2EE RCS Messaging

🔒 Apple and Google have initiated a beta rollout of end-to-end encrypted RCS messaging between iPhone and Android devices, closing a long-standing interoperability gap. The feature requires iOS 26.5 on supported iPhones and the latest Google Messages on Android, with carrier activation determining availability. Encryption is enabled by default, marked by a lock icon, and the rollout implements the GSMA Universal Profile 3.0 with MLS.
read more →

Apple Enables Default E2EE for RCS in iOS 26.5 Beta

🔐 Apple released iOS 26.5, adding beta support to enable end-to-end encryption for RCS messages across iPhone and Android devices when used with supported carriers and the latest Google Messages. The feature is enabled by default for new and existing conversations and displays a lock icon to indicate encryption. Apple and GSMA say this is part of a cross‑industry effort to modernize SMS. The update also patches over 50 vulnerabilities in iOS and iPadOS.
read more →

Elastic Beanstalk Adds TLS Listener Support for NLB

🔐 AWS Elastic Beanstalk now supports configuring TLS listeners for environments that use a Network Load Balancer. You can attach an SSL/TLS certificate and select a security policy so the load balancer terminates encrypted connections and forwards decrypted traffic to instances. TLS listener settings are configurable via the Elastic Beanstalk console or CLI, and the feature is available in all regions that support Beanstalk and NLBs.
read more →