For many years, security pros and users alike have trusted SSL for Web security, but SSL breaches at Comodo Inc....
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
highlight the growing threats to SSL. Is there a more secure way to lock down Internet transactions? Do you have any predictions for what the next generation of online security might be?
While end users may have completely trusted SSL for Web security, contrary to common belief, not all security pros have always thought it quite so trustworthy. The belief that SSL is all anyone needs for Web security has been, in part, influenced by SSL Web security vendor marketing. With the introduction of extended validation (EV) certificates, this marketing increased in fervor. The Comodo breach was not a breach of the SSL protocol or of Web security, however, but a breach of one of the components of the x.509 public key infrastructure in use on the Internet. A delegated registration authority for Comodo was breached by a hacker who was using stolen account credentials.
So, is it worth investigating SSL alternatives? While EV certificates provide a more reliable binding of the organization requesting the certificate to the certificate than non-EV certificates, EV certificates do not provide comprehensive Web security. SSL certainly is important to providing Web security, but it is only one part of comprehensive strategy. Other components that should be included in Web security programs include secure Web programming languages and frameworks, secure programming practices, strong authentication, Web-application firewalls, strong Web-application security, and other technologies. The OWASP Top 10 is a good place to start when looking into Web security.
There has been some work done in trusted identities on the Internet, which are thought to provide some Web security, but, even so, they are still only one part of the process. The next generation of online security is most likely going to center around secure Web programming languages and frameworks, and secure programming practices, which might include ratings of third-party applications for trustworthiness by vendors in centralized marketplaces. This, however, doesn’t address the client-side vulnerabilities that hackers used to compromise Comodo in the first place
Dig Deeper on Web Application and Web 2.0 Threats
Related Q&A from Nick Lewis
MedSec and Muddy Waters Capital revealed serious flaws in IoT medical devices manufactured by St. Jude Medical. Expert Nick Lewis explains the ...continue reading
RIPPER malware has been found responsible for the theft of $378,000 from ATMs in Thailand. Expert Nick Lewis explains how this ATM malware works.continue reading
Researchers found that facial recognition systems can be bypassed with 3D models. Expert Nick Lewis explains how these spoofing attacks work and what...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.