How To Render Ssl Useless (Owasp Sweden)

Posted By: SecurityTube_Bot
Posted On: Mon 21 Feb 2011
Views: 3662
Share this video:
Share it on Facebook Share it on Twitter Share it on Reddit Share it on Digg Share it on Stumbleupon
Support SecurityTube:


Description:

This is the video of the presentation titled "How to Render SSL Useless" given by Ivan Ristic at OWASP Sweden this year.

He talks about the latest discovered threats in SSL and insecure deployment issues which include:

1. Inconsistent DNS configuration
2. Different sites on port 80 and 443
3. Self signed certificates
4. Not using EV certificates
5. Badly configured SSL servers
6. Using incomplete certificates
7. Mixing SSL and plain text on a site
8. Using SSL for important bits
9. Not using secure cookies
10. Mixed page content

The full presentation of his talk can be downloaded here.


Tags: basics ,


Comments (None)

Login to post a comment