Subscribe:
Showing posts with label ssl-green-address-bar. Show all posts
Showing posts with label ssl-green-address-bar. Show all posts

Wednesday, 17 August 2011

Improper SSL Implementations Leave Websites Wide Open to Attack

Improper configuration is rendering SSL nearly useless as organizations are transmitting sensitive information online without any security.

Security researchers are buzzing about the flaws in the Secure Sockets Layer system and the fact that a significant portion of the Internet is vulnerable to attack. At the recent Black Hat security conference in Las Vegas, there were several reports and panels addressing various issues.

Based on the PKI (public key infrastructure), the SSL protocol has grown "organically" to become nearly ubiquitous within the world's largest organizations to keep Internet communications secure, Jeff Hudson, CEO of Venafi, told eWEEK.

However, less than a fifth of Websites claiming to have SSL deployed correctly redirect traffic, according to a report released by Qualys at Black Hat. Of the nearly 250,000 sites with SSL turned on that were surveyed, only 51,000 were properly redirecting to SSL for authentication, according to the report from the Qualys community project, SSL Labs. The remaining 80 percent of the sites may or may not redirect to SSL, making them vulnerable to a man-in-the middle attack from Firesheep and other tools.

Overall, there has not been a lot of improvement worldwide in how SSL has been deployed over the past few years, Philippe Courtot, chairman and CEO of Qualys, told eWEEK. Organizations are just rolling out SSL servers and not taking the time to ensure the servers are properly configured, the report found.
Courtot declined to specify any of the offenders, noting that the problem was widespread.

There were a number of configuration flaws, including the use of insecure cookies and mixing unsecure traffic with secured traffic on the same page. Websites using SSL have to redirect to SSL immediately, instead of encrypting only a portion of the page, as that opens the user to session hijacking attacks, Courtot said.

When users see a padlock on the Web browser or some other form of visual notification that the site has SSL deployed, they expect their log-in credentials are protected, Courtot said. However, it turns out many organizations made a conscious choice not to use SSL in authentication despite rolling out the security protocol, researchers found. Nearly 70 percent of the surveyed servers handled the log-in process in plain text, and a little over half the servers were transmitting passwords as plain text, making it easy for a malicious attacker to intercept the sensitive information, according to the report.

This is actually a significant problem in the mobile space, according to Julien Sobrier, a senior security researcher at Zscaler. There is no "UI element equivalent to the lock" on mobile browsers and no visibility into the URLs to tell if the traffic is going over HTTP and HTTPS, Sobrier wrote Aug. 11 on theZscaler Research Labs blog.

Citigroup learned the hard way that just having SSL on a Website doesn't keep data secure, as attackers exploited a weakness in the SSL connection on the financial giant's credit card Website and the Web browser to intercept sensitive information, Rainer Enders, CTO of NCP Engineering, told eWEEK.

While some companies, such as Google and Twitter, have taken steps to protect users by implementing HTTPS, all Websites where users log in should be encrypting traffic, as well as requiring HTTPS for all requests sent with a cookie, Sobrier said.

Qualys looked at how sites secured cookies and found that only six percent had properly configured session cookies, the report found. Even if the Websites are 100 percent encrypted, if the developer doesn't set a secure flag on the session cookies from within the application, a malicious third-party can sniff the contents of that cookie. This technique is very commonly used to force the browser to display session values stored on the insecure cookie.

Authenticity is important in the SSL system because it ensures that users are talking to the entity they intended to and that no one is listening, Chester Wisniewski, senior security advisor at Sophos, wrote on the Naked Security blog. The way the current system is set up, every major government in the world and many minor ones have the ability to sign any certificate they wish, Wisniewski said, speculating that the Department of Homeland Security could probably get a certificate claiming to be Google.

Security researcher Moxie Marlinspike presented an alternative system that bypasses certificate authorities and relies on a series of trusted notaries selected by the user, as opposed to relying on the 600 or so certificate authorities accepted by major Web browsers.

"CAs can be compromised and that major damage can result from related man-in-the-middle attacks," Hudson said, adding that Marlinspike's presentation should be a "wake-up call for better security and management of PKI and SSL."

NCP Engineering also released a white paper at Black Hat discussing "endemic vulnerabilities" in SSL, and by extension, SSL VPNs, which organizations often use to secure remote connections to the corporate severs. Enders said organizations should not just rely on SSL Certificate alone, but should layer it with IPSec to cover security weaknesses present in both technologies.

Qualys researchers also looked at how many sites were using HTTP Strict Transport Security, which defends against cookie-forcing attacks and Extended Validation SSL certificates in conjunction with standard SSL. The numbers were disheartening, as only 80 sites used HSTS and nine used EV SSL, Courtot said.

Tuesday, 16 August 2011

GlobalSign EV SSL Certificates Secure Leading World Wide Brands


FOR IMMEDIATE RELEASE
(Free-Press-Release.com) August 16, 2011 –

GlobalSign Ltd (www.globalsign.com), one of the longest established Certification Authorities (CA) and specialists in SSL Certificate security, has today announced that the range of companies choosing to adopt its Extended Validation (EV) SSL technology has expanded across numerous business sectors and continents within the last year. Increasing numbers of organizations with an online presence have realized the need to fully secure their websites, online transactions, web mail and other next generation online services using the strongest and most trusted level of SSL available in today’s market and EV SSL enables them to do exactly this, increasing customer trust and confidence leading to increased website visitor to consumer conversion rates.

During 2009 GlobalSign saw a dramatic uptake in the number of organizations large and small, switching to EV SSL. Companies including The City Bank Limited in Bangladesh, Zurich in China, METRO in Singapore, Virgin in the UK and Taylor University and BCS Engineering in the US, are some of the latest brands to benefit from GlobalSign Extended Validation (EV) SSL technology. EV SSL shows consumers that these organizations are firm in their commitment to online security and results in building higher levels of trust and confidence, which is a clear business differentiator during times of increasing competitiveness within today’s online markets.

EV SSL, perhaps the most significant advancement in how consumers view and understand security on the web, was more traditionally associated with the financial services sector. Companies across industries including health, governmental and educational have now adopted the EV solution to comply with the various security and confidentiality regulations specific to their industry.

Activating the Green Address Bar in the current generation of browsers such as IE7 & 8, Firefox, Opera, Google Chrome and Safari and clearly displaying advanced security and identity information, provides a clear visual assurance to consumers that the organization operating the website is legitimate. In a time of heightened phishing attacks, online fraud and identity theft, the adoption of EV SSL has become more widespread and sought after than ever before, as all types of organisations operating on the world wide web see the need to elevate their site image, protect their brand from copy cat websites and protect their customers’ accounts from phishing attacks whilst also increasing their web sales.

“As a world wide player in the SSL market, with a strong presence in the UK, EU, US and Asia, GlobalSign are delighted to see an ever growing number of websites upgrading to EV SSL across numerous business sectors,” said Paul Tourret, Managing Director, GlobalSign. “EV SSL Certificates are issued by publicly trusted Certification Authorities under much stricter guidelines than standard SSL. Companies adopting this standard of security are clearly illustrating their commitment to their website visitors and we are happy to be able to help such companies lead the way in protecting their brands online and their customers.”

WebTrust compliant for eight consecutive years and also recently awarded with the new WebTrust for EV accreditation, GlobalSign is highly focused on providing organizations with the strongest SSL security in the market. By offering a simplified, competitively priced, feature packed range of SSL, with free inclusion of Server Gated Cryptography (strong security), and promotional 3 for 1 server licensing, GlobalSign makes the strongest levels of SSL accessible to all online retailers, from small and medium enterprises to larger household brands. Organizations with existing non-EV SSL Certificates can easily upgrade to GlobalSign’s EV SSL and benefit from multi-year savings and promotional pricing.

For more information on EV SSL and to see the GlobalSign Extended SSL Certificate in operation please visit https://ev.globalsign.com

About EV SSL Certificates
The criteria for issuing EV Certificates (the EV Certificate Guidelines) are produced by the CA/Browser Forum, an organisation whose members include leading Certification Authorities and browser vendors, as well as representatives from the legal and audit sectors.