Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Experts Warn of a Weak Link in the Security of Web Sites

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
G_j Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 10:32 PM
Original message
Experts Warn of a Weak Link in the Security of Web Sites
http://www.nytimes.com/2010/08/14/technology/14encrypt.html?_r=1&ref=technology

Experts Warn of a Weak Link in the Security of Web Sites
By MIGUEL HELFT
Published: August 13, 2010


SAN FRANCISCO — Computer security researchers are raising alarms about vulnerabilities in some of the Web’s most secure corners: the banking, e-commerce and other sites that use encryption to communicate with their users.

Those sites, which are typically identified by a closed lock displayed somewhere in the Web browser, rely on a third-party organization to issue a certificate that guarantees to a user’s Web browser that the sites are authentic. But as the number of such third-party “certificate authorities” has proliferated into hundreds spread across the world, it has become increasingly difficult to trust that those who issue the certificates are not misusing them to eavesdrop on the activities of Internet users, the security experts say.

<snip>

According to the Electronic Frontier Foundation, more than 650 organizations can issue certificates that will be accepted by Microsoft’s Internet Explorer and Mozilla’s Firefox, the two most popular Web browsers. Some of these organizations are in countries like Russia and China, which are suspected of engaging in widespread surveillance of their citizens.

Mr. Eckersley said Exhibit No. 1 of the weak links in the chain is Etisalat, a wireless carrier in the United Arab Emirates that he said was involved in the dispute between the BlackBerry maker, Research In Motion, and that country over encryption. The U.A.E. threatened to discontinue some BlackBerry services because of R.I.M.’s refusal to offer a surveillance back door to its customers’ encrypted communications. Mr. Eckersley also said that Etisalat was found to have installed spyware on the handsets of some 100,000 BlackBerry subscribers last year. Research In Motion later issued patches to remove the malicious code.

..more..
Printer Friendly | Permalink |  | Top
Beam Me Up Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-16-10 02:56 AM
Response to Original message
1. Well, I'm so glad
there's no "widespread surveillance of citizens" going on in this country.



:\
Printer Friendly | Permalink |  | Top
 
Greyhound Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-16-10 03:39 AM
Response to Original message
2. K&R, but also duh.
I'm sure that "nobody's could've predicted" that "verifying authenticity" and shipping sensitive data to third-parties with no accountability, located in country's that are barely less hostile than our enemies, and that for practical purposes have no law beyond the authority of "we say so", might lead to some sort of problem.

Printer Friendly | Permalink |  | Top
 
dixiegrrrrl Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-16-10 04:58 AM
Response to Reply #2
3. Just as "no one could have imagined" that millions of online banking accounts
would inspire computer theft.
Printer Friendly | Permalink |  | Top
 
G_j Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-16-10 10:46 AM
Response to Reply #2
4. YEP
a very big DUH!
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 01st 2024, 05:44 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC