Skip to main content

Insecure websites to be named and shamed after checks

Companies that do not do enough to keep their websites secure are to be named and shamed to help improve security. The list of good and bad sites will be published regularly by the non-profit Trustworthy Internet Movement (TIM). A survey carried out to launch the group found that more than 52% of sites tested were using versions of security protocols known to be compromised. The group will test websites to see how well they have implemented basic security software. Security fundamentals The group has been set up by security experts and entrepreneurs frustrated by the slow pace of improvements in online safety. "We want to stimulate some initiatives and get something done," said TIM's founder Philippe Courtot, serial entrepreneur and chief executive of security firm Qualys. He has bankrolled the group with his own money. TIM has initially focused on a widely used technology known as the Secure Sockets Layer (SSL). Experts recruited to help with the initiative include SSL's inventor Dr Taher Elgamal; "white hat" hacker Moxie Marlinspike who has written extensively about attacking the protocol; and Michael Barrett, chief security officer at Paypal. Continue reading the main story “ Start Quote Everyone is now going to be able to see who has a good grade and who has a bad grade” Philippe Courtot Many websites use SSL to encrypt communications between them and their users. It is used to protect credit card numbers and other valuable data as it travels across the web. "SSL is one of the fundamental parts of the internet," said Mr Courtot. "It's what makes it trustworthy and right now it's not as secure as you think." Compromised certificates TIM plans a two-pronged attack on SSL. The first part would be to run automated tools against websites to test how well they had implemented SSL, said Mr Courtot. "We'll be making it public," he added. "Everyone is now going to be able to see who has a good grade and who has a bad grade." Early tests suggest that about 52% of sites checked ran a version of SSL known to be compromised. Companies who have done a bad job will be encouraged to improve and upgrade their implementations so it gets safer to use those sites. The second part of the initiative concerns the running of the bodies, known as certificate authorities, which guarantee that a website is what it claims to be. TIM said it would work with governments, industry bodies and companies to check that CAs are well run and had not been compromised. "It's a much more complex problem," said Mr Courtot. In 2011, two certificate authorities, DigiNotar and GlobalSign were found to have been compromised. In some cases this meant attackers eavesdropped on what should have been a secure communications channel. Steve Durbin, global vice president of the Information Security Forum which represents security specialists working in large corporations, said many of its members took responsibility for making sure sites were secure. "You cannot just say 'buyer beware'," he said. "That's not good enough anymore. They have a real a duty of care." He said corporations were also increasingly conscious of their reputation for providing safe and secure services to customers. Data breaches, hack attacks and poor security were all likely to hit share prices and could mean they lose customers, he noted.

Comments

Popular posts from this blog

Daniel Bailey has been told to pay up £194,370 by a court. If he fails to hand over the money within six months, he will face a three-year jail term.

Daniel Bailey (35) avoided prison when he received a 26-week suspended sentence after pleading guilty to producing cannabis. But following a separate investigation into his finances by police, he has been told to pay up £194,370 by a court. If he fails to hand over the money within six months, he will face a three-year jail term.During a hearing brought by police under the Proceeds of Crime Act, Lincoln Crown Court was told officers swooped on Bailey's home, near Spalding, on August 5, 2005. They searched the property and found 22 cannabis plants growing among the flowers in his back garden.More cannabis seedlings were discovered in a shed, and two small lumps of the drug were seized in the house.Bailey was subsequently convicted of production of cannabis, which triggered the probe into his financial affairs.The further enquiries showed that in the six years before his arrest, Bailey had claimed incapacity benefit and income support to the tune of more than £21,000, to which he was

Riaz Mohammed, used a string of front companies to ship the highly addictive narcotic from Turkey.

Riaz Mohammed, used a string of front companies to ship the highly addictive narcotic from Turkey.The Court heard the "sophisticated" operation involved hiding half-kilo packages of the Class A substance in the hollowed out struts of wooden pallets. But despite the gang's best efforts each of the three importations - two to Dover docks and one which arrived at Heathrow airport - were intercepted during an investigation by the Serious Organised Crime Agency (Soca).Altogether 24kg of the drug - with an estimated street value of £2.3 million - was seized. In the dock with Mohammed, 41, of Lancaster Road, Leytonstone, east London (25 years), were his lieutenant Ibrahim Janturk, 52, from Tottenham, north London (22 years), and "footsoldiers" Cetin Albar, 35, who lived in Clapton Common, east London, and Emircan Aytac, 48, of Boyson Road, Walworth, south-east London, who got 16 years each.Mohammed was convicted by a jury of three counts of conspiracy to import heroin

Angus McDonald has pointed the finger at three of the people he says were involved with him in a plot to import millions of pounds worth of drugs

Angus McDonald drug runner has pointed the finger at three of the people he says were involved with him in a plot to import millions of pounds worth of drugs into South Cumbria.Angus McDonald, 44, was the first prosecution witness in the trial of two men and a woman accused of helping to launder some of the £35m made from importing cannabis into Windermere.One of the men, John James “Jim” Nightingale, is also accused of being one of those who conspired to import the drug from Spain. Prosecution witness McDonald, of Craig Walk, Windermere, has already pleaded guilty to drugs conspiracy and money laundering charges.Yesterday he became the key witness in the Carlisle Crown Court trial of Nightingale, Sharon Ambrose, and Duncan William Maxwell, who he says were involved with him.The court heard how a gang – led by Liverpool-born George Tymoszycki, who lived in the Lake District for several years – arranged for huge amounts of cannabis to be shipped from Spain to a cash and carry warehouse