首页> 外文会议> >Lessons learned from security weaknesses in the Netscape World Wide Web browser
【24h】

Lessons learned from security weaknesses in the Netscape World Wide Web browser

机译:从Netscape万维网浏览器中的安全漏洞中学到的教训

获取原文

摘要

"The Net" is universally recognised as offering a revolution in communications way beyond the limited applications for which it is currently being used. The opportunities for business, commerce and finance are particularly exciting. The author discusses why the Internet is failing to live up to these expectations as a commercial medium. No private individual will trust their credit card numbers to an insecure network and big business has even more at stake. One of the first companies to try and address this problem seriously is Netscape Communications who attempted to build a "secure transactions protocol" into their Web browser. However, like many before them, they wrongly perceived the writing of a cryptographically secure system to be a straightforward task whereas in fact, it is a highly specialised one. As a direct result, their system was very publicly and embarrassingly "hacked". We describe by way of a detailed example of what can go wrong, the weaknesses in the design of the cryptographic "security" built into the Netscape browser which led to the algorithm being broken. Some important lessons to be learned from their experience are summarised and some recommendations made (together with associated problems) for the design of genuinely secure systems which will allow the commercial potential of the Internet to be realised to the full.
机译:“网络”被公认为在通信方式方面进行了一场革命,超越了当前正在使用的有限应用程序。商业,商业和金融机会特别令人兴奋。作者讨论了为什么Internet不能满足作为商业媒介的这些期望。没有一个私人会信任他们的信用卡号到一个不安全的网络,而大企业的风险甚至更大。 Netscape Communications是最早尝试认真解决此问题的公司之一,他试图在其Web浏览器中构建“安全交易协议”。但是,就像他们之前的许多人一样,他们错误地认为编写密码安全系统是一项简单的任务,而实际上,这是一个高度专业化的任务。直接的结果是,他们的系统非常公开且令人尴尬地“被黑”。我们将通过可能发生问题的详细示例来描述Netscape浏览器中内置的加密“安全性”设计中的弱点,该弱点导致算法被破解。总结了从他们的经验中学到的一些重要经验教训,并提出了一些建议(连同相关的问题),以设计真正安全的系统,这将使互联网的商业潜力得到充分发挥。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号