Skip to main content

Insecure websites to be named and shamed after checks

Companies that do not do enough to keep their websites secure are to be named and shamed to help improve security. The list of good and bad sites will be published regularly by the non-profit Trustworthy Internet Movement (TIM). A survey carried out to launch the group found that more than 52% of sites tested were using versions of security protocols known to be compromised. The group will test websites to see how well they have implemented basic security software. Security fundamentals The group has been set up by security experts and entrepreneurs frustrated by the slow pace of improvements in online safety. "We want to stimulate some initiatives and get something done," said TIM's founder Philippe Courtot, serial entrepreneur and chief executive of security firm Qualys. He has bankrolled the group with his own money. TIM has initially focused on a widely used technology known as the Secure Sockets Layer (SSL). Experts recruited to help with the initiative include SSL's inventor Dr Taher Elgamal; "white hat" hacker Moxie Marlinspike who has written extensively about attacking the protocol; and Michael Barrett, chief security officer at Paypal. Continue reading the main story “ Start Quote Everyone is now going to be able to see who has a good grade and who has a bad grade” Philippe Courtot Many websites use SSL to encrypt communications between them and their users. It is used to protect credit card numbers and other valuable data as it travels across the web. "SSL is one of the fundamental parts of the internet," said Mr Courtot. "It's what makes it trustworthy and right now it's not as secure as you think." Compromised certificates TIM plans a two-pronged attack on SSL. The first part would be to run automated tools against websites to test how well they had implemented SSL, said Mr Courtot. "We'll be making it public," he added. "Everyone is now going to be able to see who has a good grade and who has a bad grade." Early tests suggest that about 52% of sites checked ran a version of SSL known to be compromised. Companies who have done a bad job will be encouraged to improve and upgrade their implementations so it gets safer to use those sites. The second part of the initiative concerns the running of the bodies, known as certificate authorities, which guarantee that a website is what it claims to be. TIM said it would work with governments, industry bodies and companies to check that CAs are well run and had not been compromised. "It's a much more complex problem," said Mr Courtot. In 2011, two certificate authorities, DigiNotar and GlobalSign were found to have been compromised. In some cases this meant attackers eavesdropped on what should have been a secure communications channel. Steve Durbin, global vice president of the Information Security Forum which represents security specialists working in large corporations, said many of its members took responsibility for making sure sites were secure. "You cannot just say 'buyer beware'," he said. "That's not good enough anymore. They have a real a duty of care." He said corporations were also increasingly conscious of their reputation for providing safe and secure services to customers. Data breaches, hack attacks and poor security were all likely to hit share prices and could mean they lose customers, he noted.

Comments

Popular posts from this blog

Daniel Bailey has been told to pay up £194,370 by a court. If he fails to hand over the money within six months, he will face a three-year jail term.

Daniel Bailey (35) avoided prison when he received a 26-week suspended sentence after pleading guilty to producing cannabis. But following a separate investigation into his finances by police, he has been told to pay up £194,370 by a court. If he fails to hand over the money within six months, he will face a three-year jail term.During a hearing brought by police under the Proceeds of Crime Act, Lincoln Crown Court was told officers swooped on Bailey's home, near Spalding, on August 5, 2005. They searched the property and found 22 cannabis plants growing among the flowers in his back garden.More cannabis seedlings were discovered in a shed, and two small lumps of the drug were seized in the house.Bailey was subsequently convicted of production of cannabis, which triggered the probe into his financial affairs.The further enquiries showed that in the six years before his arrest, Bailey had claimed incapacity benefit and income support to the tune of more than £21,000, to which he was...

Vanessa and Juan Bedoya, Meneses and Rodriguez-Jimenez are being held in DuPage County Jail in lieu of $1 million bond each.

Vanessa Bedoya, 37, and Juan Bedoya, 38, both of the 1400 block of Green Oak Trail, Aurora, were charged with possession of a controlled substance with intent to deliver.Juan Meneses, 32, and Gonzalo Rodriguez-Jimenez, 38, both of the 800 block of Amli Court, Aurora, were charged with unlawful delivery of a controlled substance, the Kane County state's attorney's office said.According to prosecutors, on March 25, Rodriguez-Jimenez and Meneses delivered more than 900 grams of cocaineto another unnamed person. Later, more than 900 grams of cocaine were recovered from Juan and Vanessa Bedoya, who are married. The cocaine was recovered at the home of Francisco Bedoya, 36, also of the 1400 block of Green Oak Trail, Aurora. In addition, more than 900 grams of cocaine was recovered in the home of Juan and Vanessa Bedoya, prosecutors said. Officers searched three Aurora homes Tuesday and found 15 kilograms of cocaine, worth about $4.5 million, along with $50,000 in cash and two vehicle...

Riaz Mohammed, used a string of front companies to ship the highly addictive narcotic from Turkey.

Riaz Mohammed, used a string of front companies to ship the highly addictive narcotic from Turkey.The Court heard the "sophisticated" operation involved hiding half-kilo packages of the Class A substance in the hollowed out struts of wooden pallets. But despite the gang's best efforts each of the three importations - two to Dover docks and one which arrived at Heathrow airport - were intercepted during an investigation by the Serious Organised Crime Agency (Soca).Altogether 24kg of the drug - with an estimated street value of £2.3 million - was seized. In the dock with Mohammed, 41, of Lancaster Road, Leytonstone, east London (25 years), were his lieutenant Ibrahim Janturk, 52, from Tottenham, north London (22 years), and "footsoldiers" Cetin Albar, 35, who lived in Clapton Common, east London, and Emircan Aytac, 48, of Boyson Road, Walworth, south-east London, who got 16 years each.Mohammed was convicted by a jury of three counts of conspiracy to import heroin ...