5 ways to implement HTTPS in an insufficient manner (and leak sensitive data)

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
HTTPS or SSL or TLS or whatever you want to call it can be a confusing beast. Some say it’s just about protecting your password and banking info whilst the packets are flying around the web but I’ve long said that SSL is not about encryption.

As an indication of how tricky the whole situation is, OWASP talks about insufficient transport layer security. Not “have you done it right” or “have you done it wrong”, rather have you considered all the little nuances that go into the correct implementation of this invaluable security feature.


Naturally, when this tweet from Mark Hemmings popped up on my timeline was a little intrigued:
Troy Hunt: 5 ways to implement HTTPS in an insufficient manner (and leak sensitive data)
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top