Economic Failures of HTTPS Encryption

  • 28 November 2014
  • 0 replies
  • 168 views

Userlevel 7
Badge +3
 
Interesting paper: "Security Collapse of the HTTPS Market." From the conclusion:
Recent breaches at CAs have exposed several systemic vulnerabilities and market failures inherent in the current HTTPS authentication model: the security of the entire ecosystem suffers if any of the hundreds of CAs is compromised (weakest link); browsers are unable to revoke trust in major CAs ("too big to fail"); CAs manage to conceal security incidents (information asymmetry); and ultimately customers and end users bear the liability and damages of security incidents (negative externalities).
 
 https://www.schneier.com/blog/archives/2014/11/economic_failur.html

0 replies

Be the first to reply!

Reply