<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HubSpot's certificate is getting flagged by a security tool for SWEET32 in Tickets &amp; Conversations</title>
    <link>https://community.hubspot.com/t5/Tickets-Conversations/HubSpot-s-certificate-is-getting-flagged-by-a-security-tool-for/m-p/661037#M3597</link>
    <description>&lt;P&gt;Our company is using HubSpot for our website and the certificate provided from hubspot is vulnerability to a SWEET32 attack.&amp;nbsp; See&amp;nbsp;&lt;A href="https://sweet32.info/" target="_blank" rel="noopener"&gt;https://sweet32.info/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is a highvulnerability&amp;nbsp;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2016-2183" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln/detail/CVE-2016-2183&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 22:20:07 GMT</pubDate>
    <dc:creator>KSorensen7</dc:creator>
    <dc:date>2022-07-06T22:20:07Z</dc:date>
    <item>
      <title>HubSpot's certificate is getting flagged by a security tool for SWEET32</title>
      <link>https://community.hubspot.com/t5/Tickets-Conversations/HubSpot-s-certificate-is-getting-flagged-by-a-security-tool-for/m-p/661037#M3597</link>
      <description>&lt;P&gt;Our company is using HubSpot for our website and the certificate provided from hubspot is vulnerability to a SWEET32 attack.&amp;nbsp; See&amp;nbsp;&lt;A href="https://sweet32.info/" target="_blank" rel="noopener"&gt;https://sweet32.info/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is a highvulnerability&amp;nbsp;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2016-2183" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln/detail/CVE-2016-2183&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 22:20:07 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/Tickets-Conversations/HubSpot-s-certificate-is-getting-flagged-by-a-security-tool-for/m-p/661037#M3597</guid>
      <dc:creator>KSorensen7</dc:creator>
      <dc:date>2022-07-06T22:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot's certificate is getting flagged by a security tool for SWEET32</title>
      <link>https://community.hubspot.com/t5/Tickets-Conversations/HubSpot-s-certificate-is-getting-flagged-by-a-security-tool-for/m-p/663142#M3629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/413797"&gt;@KSorensen7&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has been already been mitigated by Cloudflare, which is documented toward the end of&amp;nbsp;&lt;A href="https://support.cloudflare.com/hc/en-us/articles/205043158-PCI-compliance-and-Cloudflare-SSL-TLS" target="_blank" rel="nofollow noopener noreferrer"&gt;this page.&lt;/A&gt;&amp;nbsp; For additional context, Cloudflare is our Content Delivery Network which is used to protect our websites and services from hackers and to speed up the performance of our customer’s websites).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wanted to share this snippet from the linked website with you:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"A vulnerability in the use of the Triple DES (3DES) encryption algorithm in the Transport Layer Security (TLS) protocol. Sweet32 is currently a proof of concept attack, there are no known examples of this in the wild. Cloudflare has manually mitigated the vulnerability for TLS 1.0 in the following manner:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;attacker must collect 32GB of data from a single TLS session&lt;/LI&gt;
&lt;LI&gt;Cloudflare forces new TLS 1.0 session keys on the affected 3DES cipher well before 32GB of data is collected&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;If you would like to test the protections built into the HubSpot platform using a fully-featured free trial, it is possible to test within the guidelines of our bug bounty program. For more info about HubSpot bug bounty and the guidelines, please visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://bugcrowd.com/hubspot" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bugcrowd.com/hubspot&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Kristen&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 19:49:24 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/Tickets-Conversations/HubSpot-s-certificate-is-getting-flagged-by-a-security-tool-for/m-p/663142#M3629</guid>
      <dc:creator>kvlschaefer</dc:creator>
      <dc:date>2022-07-11T19:49:24Z</dc:date>
    </item>
  </channel>
</rss>

