Experts Warn of a Weak Link in the Security of Web Sites
New York Times (08/13/10) Helft, Miguel
Web sites that rely on certificate authorities to guarantee their authenticity are a growing security threat, experts say. As the number of third-party authorities has grown, it has become increasingly difficult to trust those who issue the certificates. "It is becoming one of the weaker links that we have to worry about," says the Electronic Frontier Foundation's (EEF's) Peter Eckersley. There are more than 650 organizations that can issue certificates that will be accepted by Internet Explorer or Firefox, according to the EEF. One of the weak links is Etisalat, a wireless carrier in the United Arab Emirates that was involved in a dispute with BlackBerry's maker, Research In Motion, over encryption. Etisalat could issue fake certificates to itself for scores of Web sites, and "use those certificates to conduct virtually undetectable surveillance and attacks against those sites," Eckersley says. Other researchers also are concerned about the proliferation of certificate authorities. "It is a bad enough problem that it should be receiving a lot more attention and we should be trying to fix it," says Princeton University's Stephen Schultze.
Friday, August 13, 2010
Blog: Experts Warn of a Weak Link in the Security of Web Sites
Subscribe to:
Post Comments (Atom)
Blog Archive
-
►
2012
(35)
- ► April 2012 (13)
- ► March 2012 (16)
- ► February 2012 (3)
- ► January 2012 (3)
-
►
2011
(118)
- ► December 2011 (9)
- ► November 2011 (11)
- ► October 2011 (7)
- ► September 2011 (13)
- ► August 2011 (7)
- ► April 2011 (8)
- ► March 2011 (11)
- ► February 2011 (12)
- ► January 2011 (15)
-
▼
2010
(183)
- ► December 2010 (16)
- ► November 2010 (15)
- ► October 2010 (15)
- ► September 2010 (25)
-
▼
August 2010
(19)
- Blog: Solving an Earth-Sized Jigsaw Puzzle
- Blog: New View of Tectonic Plates
- Blog: MIT Builds Swimming, Oil-Eating Robots
- Blog: Sizing Samples
- Blog: W3C Launches Web Performance Working Group
- Blog: The biggest winner in health reform
- Blog: Research Paves the Way for Unselfish Compute...
- Blog: What Does 'P vs. NP' Mean for the Rest of Us?
- Blog: Researcher Cracks ReCAPTCHA
- Blog: Step 1: Post Elusive Proof. Step 2: Watch Fi...
- Blog: Experts Warn of a Weak Link in the Security ...
- Blog: Riders on a Swarm
- Blog: Teraflop Troubles: The Power of Graphics Pro...
- Blog: In a Video Game, Tackling the Complexities o...
- Blog: HP Researcher Claims to Crack Compsci Comple...
- Blog: New Paradigm for Scientific Publication and ...
- Blog: Virtual Walkers Lead the Way for Robots
- Blog: Speech Recognition Systems Must Get Smarter,...
- Blog: Team Releases Tools for Secure Cloud Computing
- ► April 2010 (21)
- ► March 2010 (7)
- ► February 2010 (6)
- ► January 2010 (6)
-
►
2009
(120)
- ► December 2009 (5)
- ► November 2009 (12)
- ► October 2009 (2)
- ► September 2009 (3)
- ► August 2009 (16)
- ► April 2009 (4)
- ► March 2009 (20)
- ► February 2009 (9)
- ► January 2009 (19)
-
►
2008
(139)
- ► December 2008 (15)
- ► November 2008 (16)
- ► October 2008 (17)
- ► September 2008 (2)
- ► August 2008 (2)
- ► April 2008 (12)
- ► March 2008 (25)
- ► February 2008 (16)
- ► January 2008 (6)
-
►
2007
(17)
- ► December 2007 (4)
- ► November 2007 (4)
- ► October 2007 (7)
Blog Labels
- research
- CSE
- security
- software
- web
- AI
- development
- hardware
- algorithm
- hackers
- medical
- machine learning
- robotics
- data-mining
- semantic web
- quantum computing
- Cloud computing
- cryptography
- network
- EMR
- search
- NP-complete
- linguistics
- complexity
- data clustering
- optimization
- parallel
- performance
- social network
- HIPAA
- accessibility
- biometrics
- connectionist
- cyber security
- passwords
- voting
- XML
- biological computing
- neural network
- user interface
- DNS
- access control
- firewall
- graph theory
- grid computing
- identity theft
- project management
- role-based
- HTML5
- NLP
- NoSQL
- Python
- cell phone
- database
- java
- open-source
- spam
- GENI
- Javascript
- SQL-Injection
- Wikipedia
- agile
- analog computing
- archives
- biological
- bots
- cellular automata
- computer tips
- crowdsourcing
- e-book
- equilibrium
- game theory
- genetic algorithm
- green tech
- mobile
- nonlinear
- p
- phone
- prediction
- privacy
- self-book publishing
- simulation
- testing
- virtual server
- visualization
- wireless
No comments:
Post a Comment