let s encrypt
play

LETS ENCRYPT Olivier Yiptong oyiptong@mozilla.com PRIVACY MATTERS - PowerPoint PPT Presentation

LETS ENCRYPT Olivier Yiptong oyiptong@mozilla.com PRIVACY MATTERS PRIVACY MATTERS: HTTPS Con fi dentiality Data Integrity Authentication NO PRIVACY: HTTP Public-only communication (Possibly?) Tampered messages Of


  1. LET’S ENCRYPT Olivier Yiptong oyiptong@mozilla.com

  2. PRIVACY MATTERS

  3. PRIVACY MATTERS: HTTPS • Con fi dentiality • Data Integrity • Authentication

  4. NO PRIVACY: HTTP • Public-only communication • (Possibly?) Tampered messages • Of dubious origin

  5. PUBLIC COMMUNICATIONS

  6. PUBLIC COMMUNICATIONS • Firesheep

  7. PUBLIC COMMUNICATIONS • Firesheep • Google

  8. PUBLIC COMMUNICATIONS • Firesheep • Google • AT&T

  9. TAMPERING

  10. TAMPERING • Verizon Perma-Cookies

  11. TAMPERING • Verizon Perma-Cookies

  12. TAMPERING • Verizon Perma-Cookies • Comcast ad injection

  13. TAMPERING • Verizon Perma-Cookies • Comcast ad injection • China - GitHub

  14. OF DUBIOUS ORIGIN

  15. OF DUBIOUS ORIGIN • Turk Telecom

  16. OF DUBIOUS ORIGIN • Turk Telecom • China Netcom

  17. OF DUBIOUS ORIGIN • Turk Telecom • China Netcom • AT&T

  18. PRIVACY MATTERS: HTTPS • Encryption (Private communication) • Data Integrity (Certainly untampered) • Authentication (Certain of origin)

  19. HTTPS FOR YOU • Remove industrial espionage vector • No customer hijacking • No impersonation

  20. HTTP DEPRECATION • Firefox: non-secure website won’t have access to new features • Chrome: display websites over HTTP as non- secure

  21. UPCOMING FUNCTIONALITY • HTTP/2 (TLS-only on Firefox, Chrome and IE) - bandwidth + latency gains • Advanced Caching (ServiceWorkers)

  22. POSSIBLE UPGRADE PATH • Referrer Policy 
 http://www.w3.org/TR/referrer-policy • Upgrade Insecure Requests 
 http://www.w3.org/TR/upgrade-insecure-requests/

  23. THANKS oyiptong@mozilla.com

Recommend


More recommend