Featured Video

Privacy Policy Privacy Policy :This blog may from time to time collect names and/or details of website visitors. This may include the mailing list, blog comments sections and in various sections of the Connected Internet site.These details will not be passed onto any other third party or other organisation unless we are required to by government or other law enforcement authority.If you contribute content, such as discussion comments, to the site, your contribution may be publicly displayed including personally identifiable information.Subscribers to the mailing list can unsubscribe at any time by writing to info (at) copsandbloggers@googlemail.com. This site links to independently run web sites outside of this domain. We take no responsibility for the privacy practices or content of such web sites.This site uses cookies to save login details and to collect statistical information about the numbers of visitors to the site.We use third-party advertising companies to serve ads when you visit our website. These companies may use information (not including your name, address, email address or telephone number) about your visits to this and other websites in order to provide advertisements about goods and services of interest to you. If you would like more information about this practice and would like to know your options in relation to•not having this information used by these companies, click hereThis site is suitable for all ages, but not knowingly collect personal information from children under 13 years old.This policy will be updated from time to time. If we make significant changes to this policy after that time a notice will be posted on the main pages of the website.

Download

frontline dispatches

25.4.12

Insecure websites to be named and shamed after checks

Companies that do not do enough to keep their websites secure are to be named and shamed to help improve security. The list of good and bad sites will be published regularly by the non-profit Trustworthy Internet Movement (TIM). A survey carried out to launch the group found that more than 52% of sites tested were using versions of security protocols known to be compromised. The group will test websites to see how well they have implemented basic security software. Security fundamentals The group has been set up by security experts and entrepreneurs frustrated by the slow pace of improvements in online safety. "We want to stimulate some initiatives and get something done," said TIM's founder Philippe Courtot, serial entrepreneur and chief executive of security firm Qualys. He has bankrolled the group with his own money. TIM has initially focused on a widely used technology known as the Secure Sockets Layer (SSL). Experts recruited to help with the initiative include SSL's inventor Dr Taher Elgamal; "white hat" hacker Moxie Marlinspike who has written extensively about attacking the protocol; and Michael Barrett, chief security officer at Paypal. Continue reading the main story “ Start Quote Everyone is now going to be able to see who has a good grade and who has a bad grade” Philippe Courtot Many websites use SSL to encrypt communications between them and their users. It is used to protect credit card numbers and other valuable data as it travels across the web. "SSL is one of the fundamental parts of the internet," said Mr Courtot. "It's what makes it trustworthy and right now it's not as secure as you think." Compromised certificates TIM plans a two-pronged attack on SSL. The first part would be to run automated tools against websites to test how well they had implemented SSL, said Mr Courtot. "We'll be making it public," he added. "Everyone is now going to be able to see who has a good grade and who has a bad grade." Early tests suggest that about 52% of sites checked ran a version of SSL known to be compromised. Companies who have done a bad job will be encouraged to improve and upgrade their implementations so it gets safer to use those sites. The second part of the initiative concerns the running of the bodies, known as certificate authorities, which guarantee that a website is what it claims to be. TIM said it would work with governments, industry bodies and companies to check that CAs are well run and had not been compromised. "It's a much more complex problem," said Mr Courtot. In 2011, two certificate authorities, DigiNotar and GlobalSign were found to have been compromised. In some cases this meant attackers eavesdropped on what should have been a secure communications channel. Steve Durbin, global vice president of the Information Security Forum which represents security specialists working in large corporations, said many of its members took responsibility for making sure sites were secure. "You cannot just say 'buyer beware'," he said. "That's not good enough anymore. They have a real a duty of care." He said corporations were also increasingly conscious of their reputation for providing safe and secure services to customers. Data breaches, hack attacks and poor security were all likely to hit share prices and could mean they lose customers, he noted.

0 comments:

Related Posts Plugin for WordPress, Blogger...

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites More