US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF
15 minutes ago by MLMRocketFuel on twitterZDNet is available in the following editions:
In order for HTTPS traffic to be secure, we need to know that the Web site we are visiting is the one we think it is. Here's a new standard that will elevate confidence.
In two previous articles "SSL/TLS Certificates: What You Need to Know" and "SSL/TLS Certificates: Perspectives Helps Authentication", I explained SSL/TLS certificates, why they are important to Internet users, and finally the inherent weaknesses of SSL/TLS certificates.
Having spread enough gloom and doom, I'd now like to discuss what many consider the real answer to the privacy and security concerns associated with SSL/TLS.
Existing SSL/TLS certificates
To recap, there are trusted (signed by a certificate authority (CA) and pre-installed on Web browsers) and untrusted (self-signed by Web site and not pre-installed on Web browsers) certificates.
The difference being that untrusted certificates require the Internet user to make a decision on whether it's authentic or not, and that can be a problem.
There's also a problem with trusted SSL/TLS certificates. The signing CAs aren't required to use any specific process to authenticate entities that are asking the CAs to sign their SSL/TLS certificates. There are some, like VeriSign or Entrust, that try to be diligent, but it's not required. Therefore, even malicious entities can get a trusted signing CA to sign a SSL/TLS certificate.
CA/Browser Forum
The signing CAs and Web browser developers decided something needed to be done, as Internet users need assurance that their online transactions are indeed private and secure. The result of this concern was the formation of a voluntary organization called Certification Authority Browser Forum (CA/Browser Forum).
Almost immediately, the forum members realized that they, the signing CAs, needed accountability. Therefore, the forum came up with the following requirements. Before a signing CA can join the forum, the CA must have a current and successful WebTrust for CAs audit, ETSI 102042 audit, or ETSI 101456 audit prepared by a qualified third-party source.
After passing the audit, the forum allows the signing CA to become a member of the forum and place a seal of assurance on its Web site similar to the one shown below:

This guarantees that the signing CA is abiding by the forum's requirements. In what I consider a good move, the forum also insists the auditing is ongoing and occurs every six months. I feel it is important to point out this internal process because it's the starting point of a traceable "chain of trust". Let's move on to what the forum is trying to accomplish.
The forum's two main goals are:
Created new standard
With that in mind, the CA/Browser Forum developed the Extended Validation (EV) SSL/TLS Certificate standard. The following is the forum's definition of an EV certificate:
"The Extended Validation (EV) SSL Certificate standard is intended to provide an improved level of authentication of entities that request digital certificates for securing transactions on their Web sites. The next generation of Internet browsers will display EV SSL-secured Web sites in a way that allows visitors to instantly ascertain that a given site is indeed secure and can be trusted. A new vetting format, which all issuing Certification Authorities (CAs) must comply with, ensures a uniform standard for certificate issuance. Consequently, visitors to EV SSL-secured Web sites can trust that the organization that operates the site has undergone and passed the rigorous EV SSL authentication process as defined by the CA/Browser Forum."
Thorough vetting
The information in the vetting process (per the CA/Browser Forum) is quite thorough, and some of the required components are listed below:
One can see that the entity verification process is much more involved now. Heck, what am I saying, there wasn't a process before, so it's a huge improvement. The above requirements and questions also apply to private organizations and government entities.
Actual EV certificate
Once an entity supplies the appropriate information and is approved by the signing CA, it receives a signed EV certificate. The requesting entity will then install the EV certificate on its Web server. Thereafter any Internet user requesting the entity's Web site will know that the site has a valid EV certificate, similar to what's shown below:


What's it mean?
Internet users will have a greater level of confidence when visiting Web sites displaying the green URL, just from knowing the Web site is authentic and the SSL/TLS connection secure.
Final thoughts
EV certificates may not be the "end all" answer, but they sure are an improvement over the other two options (trusted and self-signed). I just wish my bank and other important on-line transaction Web sites would start using EV certificates. Hopefully they will in the near future.
Michael Kassner has been involved with communications for 40 plus years, starting with amateur radio (K0PBX) and now as a network field engineer for Orange Business Services and consultant with MKassner Net. Current certifications include Cisco ESTQ Field Engineer, CWNA, and CWSP.
US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF
15 minutes ago by MLMRocketFuel on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4
19 minutes ago by greenexistence on twittergreat! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!
20 minutes ago by bestwinnernet on twitterShocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
23 minutes ago by mitchtan on twitterNon-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4
34 minutes ago by OutsourceMethod on twittersg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps
46 minutes ago by sashizoso on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD
47 minutes ago by BlissfulSeed on twitterNon-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4
1 hour 2 minutes ago by greentreats on topsyOh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
1 hour 15 minutes ago by danielgoh on twitter@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com
1 hour 40 minutes ago by t_phuck on twitterRT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY
1 hour 59 minutes ago by phyllis777loves on topsyRT @HazelHassan: Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh
2 hours 7 minutes ago by mnajem on twitterRT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...
2 hours 8 minutes ago by Zoomicon on twitterRT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa
2 hours 13 minutes ago by ellsetan on twitterFacebook led police to Philippine serial killer -- http://ow.ly/2iGnh
2 hours 15 minutes ago by hazelhassan on topsyS'pore marketeers not chirping to Twitter's tune: Marketing via Twitter has not picked up in Singapore, where it s... http://bit.ly/9GEDJS
3 hours 7 minutes ago by OurAwesomeWorld on twittergreat! S'pore marketeers not chirping to Twitter's tune http://bit.ly/dotZES Good day!
3 hours 7 minutes ago by bestwinnernet on twitterhttp://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs
4 hours 7 minutes ago by easytweeting on topsyin the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/
4 hours 38 minutes ago by findpdf on Researchers find workaround for Adobe PDF fixJust want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...
4 hours 46 minutes ago by winsource on Making the case for Filipino IT entrepreneurshipHi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks
Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...
2 days 44 minutes ago by yedwin on iPhone 4 shows prudence in procrastinationWhile I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...
2 days 56 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastinationThe online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)
2 days 54 minutes ago by mingnow on iPhone 4 to ring in Singapore on FridayAfter an awful silence, finally the prices are out..
2 days 49 minutes ago by melvinchia on iPhone 4 to ring in Singapore on FridayGlad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...
3 days 56 minutes ago by gnome_refugee on Smitten with Xfce 4yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...
3 days 54 minutes ago by ggolemg on Smitten with Xfce 4@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...
3 days 273624 seconds ago by fredericmuller on Taobao initiates Chinese open source revolutionGeez. I would think giving free books and getting kids to school would be a better place to start.
3 days 8 minutes ago by mingnow on India's US$35 tablet--how low can it go?I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...
4 days 54 minutes ago by mingnow on Taobao initiates Chinese open source revolutionhey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...
4 days 25 minutes ago by wendy on iPhone 4 shows prudence in procrastinationIt could be done without all these. Just use the opacity addon of Compiz.
4 days 48 minutes ago by hariks0 on How to get RGBA support in UbuntuStop Waiting Start Switching to Juniper
Free Gartner Report shows it reduces costs and increases efficiency
What makes a hospital a smart hospital?
Download your copy of 'The Smart Hospital' Resource Kit to learn more
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.