Perimeter
11/28/2011
12:46 PM
Taher Elgamal
Taher Elgamal
Commentary
50%
50%

SSL's Future

SSL will evolve to meet requirements for e-commerce and mobile

So what will happen to the current e-commerce world based on SSL and all of the new authentication methods under way?

SSL has been the target for a variety of attacks, many of which have been in the news lately. I believe that it will be extremely difficult to fundamentally change the models for e-commerce after 15 years of growth, despite the fraud and threats we know about. The appropriate way to manage fraud better is to work on the existing systems to improve how parties assure themselves of the identities of others involved in transactions.

There is actually more than one way that authentication can be supported within the SSL framework as it stands.

Any strong authentication can simply be used after the one-sided server authentication and encryption session has been established. At this point, the server can request any authentication information from the client, and the authentication can happen within the encrypted session. Each website can choose the authentication method it desires, as long as browser and client support can be established somehow.

Alternatively, the strong authentication method desired could be used to “unlock” a private key with a digital certificate on the client side that can be used to provide the client authentication requested by the SSL server.

Either way, the current infrastructure can, in fact, support multiple authentication methods that will help us mitigate the dependence on user passwords.

I wish that the technical community could collaborate on improving the existing e-commerce infrastructure. Many improvements are needed, for sure, but incremental improvements have always worked better than calling for a new infrastructure that would not be possible to actually put together.

My prediction is that SSL will grow with the e-commerce needs and that new versions and new implementations will meet the expectations for growing e-commerce and mobile commerce requirements.

Recognized in the industry as the "inventor of SSL," Dr. Taher Elgamal led the SSL efforts at Netscape. He also wrote the SSL patent and promoted SSL as the Internet security standard within standard committees and the industry. Dr. Elgamal invented several industry and government standards in data security and digital signatures area, including the DSS government standard for digital signatures. He holds a Ph.D. and M.S. in Computer Science from Stanford University.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8921
Published: 2015-03-01
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by c...

CVE-2014-9676
Published: 2015-02-27
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

CVE-2014-9682
Published: 2015-02-27
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CVE-2015-0655
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

CVE-2015-0884
Published: 2015-02-27
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.