SSL Padlock Not Enough for Web SecurityBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/20 17:37:24
2009/11/20 17:37:24
2009/11/20 15:43:34
2009/11/20 15:43:34
Our Partners
Downloads
Web Security : SSL Padlock Not Enough for Web Security
Posted by Max on 2008/3/7 16:36:26 (1234 reads)
Web Security

When a small padlock appears in the corner of your Web browser's address bar or the entire bar turns green, it seems like a powerful signal you're safe to proceed.

But experts say the SSL certificates those green lights signify — digital stamps of approval that Web sites buy to prove they're running a legitimate business and can send and receive encrypted data safely — don't provide the safety they seem to.

"They instill some sense of security, but that could be a dangerously false sense of security," said Paul Mutton, a researcher with UK-based security firm Netcraft Ltd.

Attacks are still possible because having an SSL certificate only indicates that a third party has verified the identity of the site's owner and set up an encrypted line of communication with the site.

The site itself could still be riddled with security holes for hackers to exploit. And the certificate could simply be bogus: Criminals have been forging them to get the padlock icon and dress up fraudulent sites.

In response, companies that sell the certificates began offering an enhanced version about a year ago, for which about 5,000 site owners worldwide have undergone an extra level of scrutiny that includes face-to-face visits.

But even those sites may contain malicious code. Researchers from Netcraft said last week they discovered vulnerabilities in four sites boasting Extended Validation SSL certificates.

Criminals could exploit the flaws to create programs to steal passwords and credit card numbers, for example. Data stolen by those malicious programs is siphoned off outside the encryption SSL provides, and thus is totally visible to hackers, Netcraft's Mutton said.

Security experts said Netcraft's report highlights the continued need for up-to-date antivirus protection and for users to be cautious about where they enter sensitive data.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.