Jesse Robbins
2008/06/09
|
My friend Ben Black just released TLS Report, a free (ad-supported) tool that evaluates SSL/TLS configurations across websites and assigns letter grades. In the example below, Facebook gets a D because it accepts several keys that are below 128-bits and relies on MD5: Ben explains: Cryptography is arcane and complex. Cryptography is also the basis for the various protocols that secure online commerce, ensure privacy of communication, and provide for integrity of data. Transport Layer Security (TLS), formerly SSL, is the de-facto standard for secure communication on the web, and it, naturally, relies on some rather sophisticated cryptographic techniques. Properly implemented, TLS all but guarantees the security of the communication channel. Ben has received a few early complaints from sites getting low grades. This seems to be common with most new rating systems, and I think the discussion is often more important than the scores themselves. You can check out the top/bottom 20 sites, search, and add new ones to be included in the report. | 翻译:xiaochong 我的朋友Ben Black刚刚发布了TLS报告,这是一个免费的(广告支持)工具,评估Web网站的SSL/TLS配置并且给出一个字母代表的级别。下面是一个例子,Facebook得了D,因为他们接受低于128位的密钥而且使用MD5。
Ben已经从一些被评为较低级别的网站那里听到抱怨了。这对于新的评级系统很正常,我认为展开讨论远比得分本身重要得多。你可以看一下前/后20名网站 ,也可以搜索网站,还可以往报告里加入新网站。 |
Discussion