What is the point of encryption if you don't know who for?
Dr. Colin D. Walter clarifies the need for authentication when performing encryption.
New York, 25th May 2005. Dr. Walter, Head of Cryptography for Comodo Inc. and chair of the Trusted Computing Group (TCG) Peripheral Working Group, has clarified the relationship between encryption and authentication. The blurred definition to date has split the Certificate Authority industry into two groups. Authorities such as Comodo and VeriSign compete head to head, to deliver high assurance digital certificates whilst other groups concentrate on the low assurance market.
Dr. Walter's white paper clarifies that domain only validation without entity authentication is literally "worthless" as a method of securing online transactions. In the paper 'What is the point of encryption if you don't know who for', Dr. Walter discusses the need for the encrypted transmission of confidential information and the technology unpinning it before highlighting the ruinous implications of the emergence of low assurance digital certificates for the future of e-commerce. "An SSL encrypted session between web browser and the web server provides a secure tunnel, but by default does not provide assurance in the identity of the end entity. Whilst a few high assurance providers continue to offer high assurance validation processes, many more low assurance providers are entering the market offering high speed, low value automated validation procedures. These low assurance products are not appropriate for encryption and do not provide either reliable privacy or trust. Enterprises have a responsibility to ensure that the use of high assurance SSL certificates provides customers with the identity assurance and confidence to make safe, secure on-line transactions."
Dr. Walter argues that the trust relationship between customers and merchants must be successfully transferred into the Internet age using the high assurance model of both domain and entity authentication. In failing to do this the future of a 'multitude of e-commerce ecosystems' is jeopardized and left at the continued mercy of online fraudsters. "Providers of low assurance SSL certificates do not perform all the necessary checks, choosing instead to offer a reduced cost, rapid fulfillment model. This is in direct conflict to accepted industry practice and serves as a source of distrust, confusion and fear for internet users."
Dr. Colin Walter is the Head of Cryptography at Comodo Inc., Chairman of Peripherals Working Group - Trusted Computing Group and Co-chair - Cryptographic Hardware and Embedded Systems.
http://www.securitydocs.com/library/3301
http://www.instantssl.com/ssl-certificate-products/encryption.html
About Comodo
Comodo is a leading global provider of Risk Alignment™ Services and Business Infrastructure Solutions differentiated by security and total cost of ownership. Comodo's web hosting automation and infrastructure solutions offer enterprise class digital e-commerce products and services. Leveraging from a broad range of security-centric solutions allows customers' telecommunications networks to become more intelligent, reliable, and secure. Maintaining an intense focus on customers who derive strategic value from their business infrastructures has paved the way for a diverse yet perfectly synergistic portfolio of security focused solutions and services. Comodo is the main driving force behind Establishing Trust™ initiatives for e-Business, curbing Phishing attacks and creating an Identity Assurance and Brand Protection framework.
Expertise with the life cycle management of Digital Certificates and creation of issuance tools enables Comodo to provide infinitely scaleable security deployment to individuals and enterprises alike. Comodo is the world's second largest and fastest growing High Assurance Certification Authority.
www.comodo.com | www.enterprisessl.com | www.trustfax.com | www.trustix.com
Comodo can be reached on (US) +1 800 772 5185 (Europe) +44 (0) 161 874 7070
Company:
Comodo
Related press releases
-
SSLGenie offers 256 bit encryption, a perfect solution to your security needs.
[2007-11-06 12:40:33]
SSLGenie is the standard security technology for creating an encrypted link between a web server and a web browser. The link ensures that all data passed between the web server and browser remains pri... -
Encryptafile 1.4 is now available
[2008-01-15 01:56:21]
New features include: Availability for export to other countries Encryption of text or string data that one can use to encrypt email or other standard text data Decryption of text Right-click Wind... -
Giveaway of Wondershare USB Drive Encryption: Protect your data from prying eyes
[2010-05-11 03:55:59]
May 13, 2010 - Wondershare Software will be together with Giveawayoftheday.com to provide free Wondershare USB Drive Encryption. This would be good news to those who intend to encrypt USB drives for t... -
Version 2.2 of Allatori Java Obfuscator is released.
[2008-07-10 16:12:41]
Allatori Java Obfuscator belongs to the second generation obfuscators' family and has all spectrum of opportunities on protection of your intellectual property. In the Allatori arsenal there are the f... -
ArtistScope Web Encrypt is released as a better html encryption option.
[2010-06-14 14:59:58]
ArtistScope Web Encrypt is released as a better html encryption option. ArtistScope Web Encrypt is an online page maker and encryption tool for installation onto any web site that has ASP and Acces... -
Dekart and Aiko provide a unified encryption workflow for Windows phone and Wind...
[2010-11-23 03:19:44]
London, UK and Chisinau, Moldova, November 17th, 2010 - Aiko Solutions Ltd, the developer of the mobile encryption and data sanitizing software, and Dekart SRL, the developer of data security and smar... -
Cryptic Disk 3.0: the state of the art in disk encryption software
[2010-08-25 01:00:38]
On August 23, 2010 EXLADE released Cryptic Disk 3.0, a new version of its disk encryption software for protecting any kind of secret: from personal correspondence and confidential information on home ... -
11 March 2011 - Hillstone Software releases version 1.3 of "HsCipherSDK" encrypt...
[2011-03-13 14:53:40]
Hillstone Software announces the release of the next version 1.3 of "HsCipherSDK" - an Encryption Library providing an API to a suite of symmetric key cryptographic algorithms and one way hash digital... -
FLEXCRYPT encrypts Hard Drive
[2009-09-21 07:49:18]
Flexcrypt is announcing a new release of their free encryption software. New feature this time is the option to encrypt the hard drive. With this addition, Flexcrypt has become a robust solution for p... -
Giveaway of Wondershare SafeLock: US Military-Level Privacy Guard
[2010-04-26 21:30:27]
April 28, 2010, Wondershare Software will be together with Giveawayoftheday.com to provide free Wondershare SafeLock. This would be good news to those who need to encrypt their sensitive files/folders...
English
German
French
Spanish
Russian
Romanian



