Talking about SSL misconfiguration at OWASP AppSec Research 2010

My proposed talk, "The State of SSL in the World", was accepted for the OWASP AppSec Research 2010 conference in Stockholm, Sweden 23-24 June.


The talk will discuss how (tools and methods used) you quickly scan a large sample of the internet's HTTPS-servers and what, if any, conclusions could be made from the resulting data. The questions I try to find a answer for are:
  • How many of the Fortune 500 and Top 10'000 websites (according to Alexa) offer an HTTPS-enabled browser experience to their visitors?
  • How is the HTTPS-server configured in regards to SSL-protocols offered, key exchange and key lengths (bit-size)?
  • Are there any correlation between company size, industry or popularity and the HTTPS-enabled browsing experience and the HTTPS-configuration?
I hope to see you there, and if you register within the next 24 hours you still get the early bird price at a €50 discount (€300 instead of €350)!

0 comments:

Post a Comment