Click here to Skip to main content
15,895,011 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
NewsGoogle, Microsoft and Netflix want DRM-like encryption in HTML5 Pin
Terrence Dorsey26-Feb-12 10:14
sitebuilderTerrence Dorsey26-Feb-12 10:14 
NewsWindows 8 Desktop UI Concept Pin
Terrence Dorsey26-Feb-12 10:13
sitebuilderTerrence Dorsey26-Feb-12 10:13 
NewsThe 6502 Processor Today Pin
Terrence Dorsey26-Feb-12 10:13
sitebuilderTerrence Dorsey26-Feb-12 10:13 
NewsThe Death Star Is a Surprisingly Cost-Effective Weapons System Pin
Terrence Dorsey26-Feb-12 10:12
sitebuilderTerrence Dorsey26-Feb-12 10:12 
NewsAlways remember to say thank you........... Pin
DaveAuld24-Feb-12 20:47
professionalDaveAuld24-Feb-12 20:47 
GeneralRe: Always remember to say thank you........... Pin
AspDotNetDev24-Feb-12 22:24
protectorAspDotNetDev24-Feb-12 22:24 
NewsEncrypt all web traffic? Pin
Slacker00724-Feb-12 1:25
professionalSlacker00724-Feb-12 1:25 
GeneralRe: Encrypt all web traffic? Pin
Randor 24-Feb-12 13:04
professional Randor 24-Feb-12 13:04 
Hi 007,

Sure HTTPS is faster and easier to implement. However the certification authority system is completely broken and many countries including Iran have wildcard (*) certificates that allow them to potentially implement MITM servers that read all HTTPS traffic. There are some browsers that will block or warn the user if the path does not match the certificate. However some web browsers will not warn the user at all.

These wildcard certificates must be easy to obtain. My previous employer had a wildcard certificate for 'protecting intellectual/secret property' although I heard it cost alot of money. I believe after I left they began using a self-signed certificate and just installed this certificate on all of the workstations with full trust.

In my opinion we need to replace the certification authority system because it is weak. However I don't really know what would be the best course of action for accomplishing this... perhaps it could be incorporated into the DNSSEC protocol. There are some other ideas out there such as Convergence but they all have strengths/weaknesses.

Best Wishes,
-David Delaune

P.S.
I am also currently behind a MITM https server and the staff members/administrators here can probably see the Via header on my https traffic.
NewsCommon mobile web design mistakes Pin
Terrence Dorsey23-Feb-12 10:43
sitebuilderTerrence Dorsey23-Feb-12 10:43 
NewsMajor and minor JavaScript pitfalls and ECMAScript 6 Pin
Terrence Dorsey23-Feb-12 10:43
sitebuilderTerrence Dorsey23-Feb-12 10:43 
NewsIntroducing the New Developer Experience for Visual Studio 11 Pin
Terrence Dorsey23-Feb-12 10:42
sitebuilderTerrence Dorsey23-Feb-12 10:42 
NewsGood Devs Don't Like Magic Pin
Terrence Dorsey23-Feb-12 10:42
sitebuilderTerrence Dorsey23-Feb-12 10:42 
NewsRetrocomputing Enigma 45 Pin
Terrence Dorsey23-Feb-12 10:41
sitebuilderTerrence Dorsey23-Feb-12 10:41 
NewsEveryone's Trying to Track What You Do on the Web: Here's How to Stop Them Pin
Terrence Dorsey23-Feb-12 10:41
sitebuilderTerrence Dorsey23-Feb-12 10:41 
NewsAdobe abandons Linux Pin
Terrence Dorsey23-Feb-12 10:40
sitebuilderTerrence Dorsey23-Feb-12 10:40 
NewsHow the Computer That Won 'Jeopardy!' Could Change Medicine Pin
Terrence Dorsey23-Feb-12 10:40
sitebuilderTerrence Dorsey23-Feb-12 10:40 
NewsWhy Do Some People Learn Faster? Pin
Terrence Dorsey23-Feb-12 10:39
sitebuilderTerrence Dorsey23-Feb-12 10:39 
NewsWhat Is The Spirit of Open Source? Pin
Terrence Dorsey23-Feb-12 10:39
sitebuilderTerrence Dorsey23-Feb-12 10:39 
NewsScientists Develop Biological Computer to Encrypt and Decipher Images Pin
kashif Atiq22-Feb-12 17:59
kashif Atiq22-Feb-12 17:59 
NewsA Coder Interview With Mike Ash Pin
Terrence Dorsey22-Feb-12 12:23
sitebuilderTerrence Dorsey22-Feb-12 12:23 
NewsThe Revenge of the IE Box Model? Pin
Terrence Dorsey22-Feb-12 12:23
sitebuilderTerrence Dorsey22-Feb-12 12:23 
NewsHow to do cheap backups Pin
Terrence Dorsey22-Feb-12 12:22
sitebuilderTerrence Dorsey22-Feb-12 12:22 
NewsSmall coding mistake led to big Internet voting system failure Pin
Terrence Dorsey22-Feb-12 12:22
sitebuilderTerrence Dorsey22-Feb-12 12:22 
NewsThe 7 habits of highly effective developers Pin
Terrence Dorsey22-Feb-12 12:21
sitebuilderTerrence Dorsey22-Feb-12 12:21 
News52 Things People Should Know To Do Cryptography Pin
Terrence Dorsey22-Feb-12 12:20
sitebuilderTerrence Dorsey22-Feb-12 12:20 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.