Amazines Free Article Archive
www.amazines.com - Friday, April 19, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73855)
 Automotive (145712)
 Blogs (75614)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330638)
 Business News (426446)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241953)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20319)
 Dating (45908)
 EBooks (19703)
 E-Commerce (48258)
 Education (185521)
 Electronics (83524)
 Email (6438)
 Entertainment (159854)
 Environment (28970)
 Ezine (3040)
 Ezine Publishing (5453)
 Ezine Sites (1551)
 Family & Parenting (111007)
 Fashion & Cosmetics (196605)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310615)
 Fitness (106469)
 Food & Beverages (63045)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630137)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91657)
 Home Improvement (251211)
 Home Repair (46243)
 Humor (4723)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191031)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80506)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99316)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126700)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80350)
 Science & Technology (110290)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49311)
 Software (83033)
 Spiritual (23516)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308304)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11790)
 Website Design (56919)
 Website Promotion (36663)
 World News (1000+)
 Writing (35844)
Author Spotlight
ELLIOT CHANG

Financial analyst and author writing on economy and business. ...more
TAL BARNEA

Tal is an electrical engineer with over 25 years of expertise with hardware, software, mechanical an...more
MANMOHAN SINGH

Digital marketing professional with 8 years of experience. A good listner, Stratgist and fun loving ...more
LEMUEL ASIBAL

Lemuel Asibal is a web content writer who also ventures on writing articles and blog posts about any...more
TUSHAR BHATIA

Tushar Bhatia is the Founder President of EmpXtrack Inc with over 19 years of experience in the soft...more


Researchers propose tls extension to detect rogue ssl certificates - China Neon Rope Light by dedwf wefweg





Article Author Biography
Researchers propose tls extension to detect rogue ssl certificates - China Neon Rope Light by
Article Posted: 12/07/2012
Article Views: 72
Articles Written: 1942
Word Count: 593
Article Votes: 0
AddThis Social Bookmark Button

Researchers propose tls extension to detect rogue ssl certificates - China Neon Rope Light


 
Business,Business News,Business Opportunities
Called TACK, which is short for Trust Assertions for CertificateKeys, the extension was developed by security researchers Trevor Perrin and MoxieMarlinspike and was submitted for consideration to the InternetEngineering Task Force (IETF), the body in charge of TLS, onWednesday. TACK tries to resolve the trust-related problems with the publickey infrastructure that were highlighted by last year's securitybreaches at certificate authorities (CAs) Comodo and Diginotar. Both of those breaches resulted in SSL certificates for highprofile domains like google.com, hotmail.com or mail.yahoo.com,being issued fraudulently. In Diginotar's case, the certificateswere even employed in active attacks against Google users in Iran.

At the moment, Web browsers trust over 600 organizations fromaround the world to issue SSL certificates. These organizations areknown as certificate authorities and every one of them cantechnically issue a valid certificate for any domain on theInternet. Several proposals to improve the current CA-based system have beenput forward by Internet and security experts in the past 12 months,but there's no consensus regarding which one offers the bestsolution. In November 2011, security engineers from Google proposed an HTTP extension called "public key pinning" that would allow websites toeffectively tell browsers via an HTTP header which certificateauthorities should be trusted to issue SSL certificates for theirdomain names.

The browsers would then remember (pin) this information and refuseto establish the connection if they receive a certificate signed bya different CA in the future. A more static implementation of thissystem already exists in Google Chrome for particular domain names,including Google's. TACK is based on the same public key pinning concept, but insteadof pinning CA public keys to particular domain names, it pinspublic keys generated by the domain owners themselves. With TACK, the domain owner can generate a pair of private andpublic keys called TACK keys. The private key is used to sign theserver's TLS public key, which is currently used by browsers tovalidate SSL certificates.

The TACK public key is then shared withconnecting browsers and is used to validate the TACK-signed TLSpublic key. The browsers can pin a TACK public key to a domain name if theyreceive it from the server on several separate occasions. If anattacker attempts to use a rogue SSL certificate to spoof a secureconnection to a domain name that already has a TACK key pinned toit, the browser will not authorize it because the TACK validationwill fail. This creates a secondary protection layer, because in addition to afraudulently-obtained, CA-signed, SSL certificate, an attackerwould also need the domain owner's private TACK key in order topull off a successful attack. TACK is designed to be backward-compatible with both clients andservers that lack support for it.

In such situations, the HTTPSconnection gets negotiated according to the current CA-basedvalidation system. This aspect is particularly important given the slow adoption ofnew TLS versions by Web server owners. According to TrustworthyInternet Movement's SSL Pulse project , fewer than two percent of the Internet's top 200,000HTTPS-enabled websites support TLS 1.1 or 1.2, the latest versionsof the protocol. The vast majority of websites still support SSL 3.0, the precursorof TLS, and TLS version 1.0, which was designed in 1999. Over 30percent of them still support SSL 2.0, the first publicly availableand most insecure version of the protocol.

Under these conditions, it's hard to imagine TACK becoming widelyimplemented anytime soon, even if the extension ends up receivingapproval from the IETF.

The e-commerce company in China offers quality products such as China Neon Rope Light , China LED Illuminator, and more. For more , please visit Decorative String Lights today!

Related Articles - China Neon Rope Light, China LED Illuminator,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license