Popular online services graded on SSL implementation
Posted on 03 November 2010.
It seems that Firesheep has succeeded where similar tools have failed in the past: the issue of full end-to-end encryption for all websites - especially the most popular ones - is finally getting the attention it deserves.

And among those who view Firesheep's advent as the perfect excuse to point out - and keep pointing out - the need for SSL use is George Ou.

He plans to keep an online services report card that will keep track of the changes that Facebook, Twitter, Gmail.com, Google.com, Microsoft Hotmail, Ebay, Flickr, WordPress and its implementations, Yahoo and Amazon execute to implement full end-to-end encryption, and what generic protocols are deemed safe.

The current report card looks like this:


As you can see, only Gmail.com and Wordpress free hosting site (which does implement SSL) get an "A" and are fully impervious to partial and full sidejacking and full hijacking of HTTP sessions, while Facebook, Twitter and Microsoft's Hotmail e-mails service have a long way to go. Although, Microsoft is reportedly considering SSL implementation for some of their services.






Spotlight

The big picture of protecting and securing Big Data

Today almost every company is dealing with big data in one way or another – including customer data, tracking data, and behavioral marketing information – connecting every aspect of our lives. While this is a cutting edge use of technology, data monitoring can become dangerous when placed in the wrong hands.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Fri, Aug 28th
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //