All the latest UK technology news, reviews and analysis

Google unveils SSL security plans post Comodo attack

by Shaun Nichols

02 Apr 2011

Be the first to comment

  • Tweet this

Google has revealed its plans for securing Secure Sockets Layer (SSL) certificates, as the security industry attempts to move on from the Comodo security breach.

In a posting to the Google Online Security blog, security team engineer Ben Laurie outlined plans for two projects which the company hopes will help to prevent future security incidents and restore trust in online certificates.

The first is an online catalogue for certificates. Laurie explained that Google is using its web crawling software to pore over sites and gather information on security certificates.

The company plans to turn the collection into the Google Certificate Catalog, a database of SSL certificates allowing for connections to verify the authenticity of online certificate data.

Google will also work with the DNS-based Authentication of Named Entries working group which is building a platform that can specify and validate the signing of online certificates.

"In the wake of the recent Comodo fraud incident, there has been a great deal of speculation about how to improve the Public Key Infrastructure on which the security of the internet rests," Laurie wrote. "Unfortunately, this isn't a problem that will be fixed overnight."

Laurie was referring to the recent crisis with security firm Comodo in which a hacker was able to gain access to company data and generate fake security certificates.

A hacker from Iran later claimed responsibility for the attacks.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

10%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Flash Developer- actionscript, AJAX, JSON

Flash Developer- Actionscript 3.0, AJAX, JSON, computer...

Business Analyst, Risk platform, Equity Derivs, Investment Bank

Business Analyst - Risk platform - Equity Derivatives...

Java Developer - Algorithmic Trading - Global Trading Business

Java Developer - Algorithmic Trading - Global Trading...

Junior Treasury Project Manager, Tier One Investment Bank

Junior Middle Office Project Manager, Treasury, IB...

To send to more than one email address, simply separate each address with a comma.