Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
The meeting was arranged to discuss plans to combat the security risks posed by phishing, ageing encryption ciphers and inconsistent SSL certificate practice. Security developers from Microsoft, Mozilla/Firefox, Opera and Konqueror agreed on a number of points including plans to introduce stronger encryption protocols.
Linux-based K Desktop Environment (KDE) developer George Staikos, who hosted the meeting, said the availability of botnets and massively distributed computing meant current encryption standards "are showing their age."
"Prompted by Opera, we are moving towards the removal of SSLv2 from our [Konqueror] browsers," said Staikos. "IE will disable SSLv2 in version 7 and it has been completely removed in the KDE 4 source tree already.
He said that KDE will in future look to remove 40- and 56-bit ciphers, and work toward "preferring and enforcing stronger ciphers as testing shows that site compatibility is not adversely affected.
"In addition, we will encourage certificate authorities (CAs) to move toward 2048-bit or stronger keys for all new roots."
Staikos said stronger cryptography rules help to protect users from malicious cracking attempts. He said browser developers will aim to promote, encourage, and eventually enforce much stricter procedures for certificate signing authorities.
He said the present system meant that all CAs are considered equal, irrespective of their credentials and practices. He said that with a definition of a new "strongly verified" certificate, "we can give users a more prominent indicator of authentic high-profile sites, in contrast to the phishing sites that are becoming so prevalent today."
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.