首页> 外文会议>IEEE Symposium on Security and Privacy >Does Certificate Transparency Break the Web? Measuring Adoption and Error Rate
【24h】

Does Certificate Transparency Break the Web? Measuring Adoption and Error Rate

机译:证书透明度是否打破了网?测量采用和错误率

获取原文

摘要

Certificate Transparency (CT) is an emerging system for enabling the rapid discovery of malicious or misissued certificates. Initially standardized in 2013, CT is now finally beginning to see widespread support. Although CT provides desirable security benefits, web browsers cannot begin requiring all websites to support CT at once, due to the risk of breaking large numbers of websites. We discuss challenges for deployment, analyze the adoption of CT on the web, and measure the error rates experienced by users of the Google Chrome web browser. We find that CT has so far been widely adopted with minimal breakage and warnings. Security researchers often struggle with the tradeoff between security and user frustration: rolling out new security requirements often causes breakage. We view CT as a case study for deploying ecosystem-wide change while trying to minimize end user impact. We discuss the design properties of CT that made its success possible, as well as draw lessons from its risks and pitfalls that could be avoided in future large-scale security deployments.
机译:证书透明度(CT)是一种新兴系统,可实现恶意或疏散证书的快速发现。最初在2013年标准化,CT目前最终开始看到广泛的支持。虽然CT提供了理想的安全福利,但由于打破大量网站的风险,Web浏览器无法开始一次支持CT的所有网站。我们讨论部署的挑战,分析了网络上的CT,并测量了Google Chrome Web浏览器的用户所遇到的错误率。我们发现迄今为止,CT已被广泛采用,最小的破碎和警告。安全研究人员经常与安全和用户挫折之间的权衡斗争:推出新的安全要求通常会导致破损。我们将CT视为部署生态系统范围变化的案例研究,同时尝试最大限度地减少最终用户的影响。我们讨论了CT的设计属性,使其成功成为可能,以及从未来的大规模安全部署中可以避免的风险和陷阱的课程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号