TLS Report grades and reports on site security(TLS报告分级并报告网站安全)

Jesse Robbins Jesse Robbins 2008/06/09

My friend Ben Black just released TLS Report, a free (ad-supported) tool that evaluates SSL/TLS configurations across websites and assigns letter grades. In the example below, Facebook gets a D because it accepts several keys that are below 128-bits and relies on MD5:
facebook-tlsreport

Ben explains: Cryptography is arcane and complex. Cryptography is also the basis for the various protocols that secure online commerce, ensure privacy of communication, and provide for integrity of data. Transport Layer Security (TLS), formerly SSL, is the de-facto standard for secure communication on the web, and it, naturally, relies on some rather sophisticated cryptographic techniques. Properly implemented, TLS all but guarantees the security of the communication channel.

It's that properly implemented part that catches folks out. Whether from poor defaults in software, poor understanding of best practices, or a weak grasp on the various trade-offs between security and performance, TLS, as most often deployed on the web, is in a sorry state. We hope to change that.

The tls report delivers the tools, information, and visibility to reveal problems in TLS configurations and offer better alternatives so folks can improve their security posture and make sure it stays improved. Everybody wins.

Ben has received a few early complaints from sites getting low grades. This seems to be common with most new rating systems, and I think the discussion is often more important than the scores themselves. You can check out the top/bottom 20 sites, search, and add new ones to be included in the report.

翻译:xiaochong

我的朋友Ben Black刚刚发布了TLS报告,这是一个免费的(广告支持)工具,评估Web网站的SSL/TLS配置并且给出一个字母代表的级别。下面是一个例子,Facebook得了D,因为他们接受低于128位的密钥而且使用MD5。

Ben解释到:密码系统是晦涩而复杂的。它也是各种保证在线商业安全、确保通信隐私以及提供数据整合的协议的基础。TLS(从前的SSL)是Web上安全通信的事实标准,它依赖于一些复杂的密码技术。正确地实施TLS几乎可以确保通信渠道的安全。

要正确地实施部署TLS大家就参差不齐了。无论是因为软件粗陋的缺省配置,对实践经验的简单理解,或者是对于各种平衡安全性和性能的不恰当理解,TLS作为在Web上最常见的部署往往处于一个很难让人满意的状态。我们希望改变这一切。

TlS报告提供工具、信息和可见性来揭示TLS配置中的问题,从而提供更好的方案使大家提高安全状况并确保状态良好。大家都赢。

Ben已经从一些被评为较低级别的网站那里听到抱怨了。这对于新的评级系统很正常,我认为展开讨论远比得分本身重要得多。你可以看一下前/后20名网站 ,也可以搜索网站,还可以往报告里加入新网站

Discussion

Enter your comment (wiki syntax is allowed):
blog/jesse/tlsreport-grade-report-website-security.txt · 最后更改: 2008/09/08 由 radarman
O'Reilly Home | Privacy Policy ©2005-2009, O'Reilly Media, Inc.
All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners.