An Inquiry into the Nature and the Causes of Web Insecurity
draft-tschofenig-secure-the-web-04
Document | Type |
Expired Internet-Draft
(individual)
Expired & archived
|
|
---|---|---|---|
Authors | Hannes Tschofenig , Sean Turner , Mike Hanson | ||
Last updated | 2013-04-25 (Latest revision 2012-10-22) | ||
RFC stream | (None) | ||
Intended RFC status | (None) | ||
Formats | |||
Stream | Stream state | (No stream defined) | |
Consensus boilerplate | Unknown | ||
RFC Editor Note | (None) | ||
IESG | IESG state | Expired | |
Telechat date | (None) | ||
Responsible AD | (None) | ||
Send notices to | (None) |
This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:
Abstract
The year 2011 has been quite exciting from a Web security point of view: a number of high-profile security incidents have gotten a lot of press attention but also new initiatives, such as the National Strategy for Trusted Identities in Cyberspace (NSTIC), had been launched to improve the Web identity eco-system. The NSTIC strategy paper, for example, observes problems with Internet security due to the widespread usage of low-entropy passwords and the lack of widely deployed authentication and attribute assurance services. With this memorandum we try to develop a shared vision for how to deal with the most pressing Web security problems.
Authors
Hannes Tschofenig
Sean Turner
Mike Hanson
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)