首页> 外文会议>IEE Colloquium on Public Uses of Cryptography >Lessons learned from security weaknesses in the Netscape World Wide Web browser
【24h】

Lessons learned from security weaknesses in the Netscape World Wide Web browser

机译:从Netscape万维网浏览器中的安全弱点汲取经验

获取原文

摘要

"The Net" is universally recognised as offering a revolution in communications way beyond the limited applications for which it is currently being used. The opportunities for business, commerce and finance are particularly exciting. The author discusses why the Internet is failing to live up to these expectations as a commercial medium. No private individual will trust their credit card numbers to an insecure network and big business has even more at stake. One of the first companies to try and address this problem seriously is Netscape Communications who attempted to build a "secure transactions protocol" into their Web browser. However, like many before them, they wrongly perceived the writing of a cryptographically secure system to be a straightforward task whereas in fact, it is a highly specialised one. As a direct result, their system was very publicly and embarrassingly "hacked". We describe by way of a detailed example of what can go wrong, the weaknesses in the design of the cryptographic "security" built into the Netscape browser which led to the algorithm being broken. Some important lessons to be learned from their experience are summarised and some recommendations made (together with associated problems) for the design of genuinely secure systems which will allow the commercial potential of the Internet to be realised to the full.
机译:“网络”普遍认为,以通信方式提供革命,超出目前正在使用的有限应用程序。商业,商业和金融的机会特别令人兴奋。作者讨论了互联网未能作为商业媒体达到这些期望的原因。没有私人将信任他们的信用卡号码到不安全的网络,大型企业更具危害。首批尝试和解决此问题的公司之一是尝试将“安全事务协议”建立到其Web浏览器中的Netscape通信。然而,与他们面前的许多人一样,他们错误地认为将一个加密保护系统的写作是一项简单的任务,而其实这是一个高度专业化的任务。作为直接结果,他们的系统非常公开,令人尴尬地“黑客”。我们通过一个关于可能出现问题的详细示例,内置于Netscape浏览器中的加密“安全性”设计的弱点,这导致了算法被打破。总结了一些重要的经验教训,并概述了一些建议(与相关问题一起制作的真正安全系统,这将使互联网的商业潜力实现为完整。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号