From revenue assurance to assurance

Peter Gutmann · 2012

In 1995, Netscape rolled out SSL, the application-level security protocol that's used to secure web browsing, email, FTP, instant messaging, VoIP, and in general anything that needs an encrypted pipe from A to B. SSL is rather crucially dependent for its security on certificates created by third-party CAs, but for the first 11/2 decades of its existence no-one had ever tried to measure how effectively these were being handled. When a volunteer-run project by the EFF did finally examine the situation, they found a chaotic mess that still hasn't been fully untangled.

Read the paper · More papers on PaperTik