4 ms·
Why not implement the crypto standard in Firefox/Chrome?
by allerratio 14y ago
Why not implement the crypto standard in Firefox/Chrome?
- saraid216 14y agoBecause they didn't exist yet?
- ibotty 14y agoi guess (s)he meant: why not implement that standard in firefox now. that would remove the lock-in to ie as well. (it might not be possible because of patents, etc. but the government should -of course- be able to fund it.)
- raverbashing 14y agoOr create a shin/adaptor, or even reverse engineer the darn thing and put it inside a Firefox plugin Or the alternative is better, wait until someone finds a flaw in this 'standard' (shouldn't be too hard) and have fun with it.
- yen223 14y agoThe correct thing to do would be to mandate that all "e-commerce sites" need to enforce a "reasonable level of security", where the quoted items are defined by some professional body.
- jordanthoms 14y agoWhy pass a law at all? Almost every e-commerce site uses TLS of their own free will.
- kijin 14y agoKoreans don't seem to think that way. As a matter of fact, in Korea, every e-commerce site is required by law to use TLS. Even if you don't sell anything online, you must use TLS if you're for-profit and you have any sort of login system. It's been the law since last August. CAs have been making a lot of money lately.
- Zak 14y agoKoreans don't seem to think that way That's interesting. As an American programmer, it seems obvious to me that merchants and credit card providers would find it in their interests to prevent fraud and credit card theft. Do you have any insight in to why Koreans feel differently about that? Is there something different about the legal system that makes civil liability for unauthorized card use an insufficient motivation to use reasonable security measures?
- kijin 14y agoMy first guess is that the ubiquity of ActiveX-based payment processing software makes TLS somewhat redundant. In Korea, nobody enters their card number into a web page, they always enter it into an ActiveX pop-up window. So the merchants might think: Why encrypt the whole page when all the money-related info will be sent through an encrypted side channel anyway? (Of course, the ActiveX control is being delivered through an insecure channel in the first place, but try explaining that to the average CEO.) The potential liability for not encrypting usernames and passwords is probably negligible compared to the liability for not encrypting payment details. So in the absence of government regulation, there's not enough financial incentive for merchants to encrypt non-money-related stuff.