| By Marketwire . | Article Rating: |
|
| November 12, 2009 09:01 AM EST | Reads: |
384 |
MOUNTAIN VIEW, CA -- (Marketwire) -- 11/12/09 -- A consortium of leading technology companies today announced the creation of the MashSSL Alliance, an organization dedicated to evangelizing the use of the MashSSL technology and specification. MashSSL is an innovative way to use the proven and trusted SSL protocol and trust infrastructure to solve the tricky and serious problem of trust establishment between web applications communicating through an end user at a browser. This is a hard problem as the web applications have to assume that the user in the middle could be a malicious hacker or a legitimate user with a malware infected browser.
The founding members of the Alliance include leading SSL certificate vendors Comodo, DigiCert, Entrust and VeriSign; leading providers of security technology and services Arcot, Cenzic, ChosenSecurity, Denim Group, OneHealthPort, QuoVadis, SafeMashups and Venafi; leading security research institutions Institute for Cyber Security, UTSA, MIT Kerberos Consortium and Secure Business Austria, and noted industry security experts.
"Having been both a vendor and security practitioner, what makes MashSSL such an innovative and elegant solution is the fact that it sits on top of SSL at the application layer and does not disrupt the existing ecosystem -- no new crypto protocols to analyze, no changes to the browser and no new types of credentials," said Lynn Terwoerds, Former Head of Security Architecture & Standards, Barclays GRCB, former Senior Security Strategist, Microsoft, and member of the Cloud Security Alliance. "The ability to significantly reduce the risk involved with online collaboration and transactions opens up a whole new realm of opportunities to both product developers and to security practitioners who need to live in a highly virtualized and cloud based world, where applications and data no longer reside in a single location."
"End users' Web experiences, be it in healthcare or any other vertical, are increasingly an aggregation of data and processing from cooperating Web applications that communicate wholly or partially through the user's browser," said Sue Merk, vice president of business development and product management at OneHealthPort, a coalition of health plans, physicians and hospitals that joined together to build a trusted community where business and clinical information could be shared securely. "Unfortunately, a malicious man-in-the-middle attack or a user infected with man-in-the-browser malware can easily subvert such communications. An open standard to solve this universal problem once, and not in a piece meal ad hoc fashion, has been a long time coming. That it is based on the trusted and familiar SSL certificate infrastructure is a bonus."
MashSSL, which was first developed by application authentication pioneer SafeMashups, has now become an open specification with an open source reference implementation, and is in the process of being standardized.
"Using different proprietary security methods and a multitude of quasi-trusted credentials to solve this fundamental problem is clearly inefficient and will lead to administrative errors which underlie many vulnerabilities," said Siddharth Bajaj, Principal in the Innovation Group at VeriSign and steering committee chair of both the MashSSL Alliance and W3C MashSSL XG. "MashSSL repurposes SSL to create a secure application layer pipe through which open protocols like OAuth, OpenID, OpenAJAX, etc., and proprietary applications like payment provider interfaces can flow in a more secure fashion while leveraging the already existing trust and credential infrastructure."
While MashSSL was originally developed for use with newer mashup technologies, it became rapidly apparent that the protocol can be used in any situation where two Web applications need to communicate through a user's browser, where the user may be malicious or the browser infected with malware. Consequently, the potential field of use for MashSSL is very broad, including potentially underlying identity federation protocols, payment button interfaces, etc.
The initial MashSSL specification and open source reference implementation have been made generally available at www.mashssl.org.
General Media Contact:
Elizabeth Safran
Looking Glass Public Relations for the MashSSL Alliance
+1.212.740.1037 (office)
+1.408.348.1214 (cell)
Email Contact
www.lookingglasspr.com
Published November 12, 2009 Reads 384
Copyright © 2009 Ulitzer, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Marketwire .
Copyright © 2009 Marketwire. All rights reserved. All the news releases provided by Market Wire are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.
- Everything Channel's CRN Unveils the 2010 Channel Chiefs
- New Business Win: Comodo Selects Callidus Software's Force.com Solution for Commissions Management
- Setefi (Gruppo Intesa Sanpaolo) ha scelto Gemalto per il lancio su vasta scala in Italia delle carte di pagamento senza contatto EMV PayPass™
- InterRail lancia due nuovi Pass
- Skype inaugura una nuova era nella comunicazione online "faccia a faccia": integrazione con i televisori di ultima generazione e videochiamate ad alta definizione su PC
- Multiplied Media annuncia la disponibilità della premiata applicazione di ricerca locale Poynt in Italia
- La prima società al mondo nel settore dell'intimo maschile: società australiana sviluppa intimo a partire dalle fibre del banano
- Pragmatic Web Services Security Today - Simple strategies for securing and monitoring Web services
- Comodo Releases NOC Monkey 2.0 Beta 2
- Comodo Drags Marketshare From Verisign
- Comodo Announces Launch Of Beta Version of Zero Touch Linux (ZTL)
- Comodo Unveils Zero Touch Linux (ZTL) For Back Office Automation
- Trustix Secure Linux Sees Download Growth
- Hushmail Teams Up with Comodo to Provide SSL Certificates
- Comodo Code Signing Certificate Supports Mozilla Standards
- Comodo Says Send Email, Not Postcards Scrawled in Pencil
- Abdulhayoglu: Avoiding Porn and Gambling Not Enough to Avoid Infection
- HP Offers Comodo Multi-Domain Certificates with Home Servers
- Comodo Users React to Conficker Virus with Confidence, Not Fear




























Ulitzer content is offered under Creative Commons "Attribution Non-Commercial No Derivatives" License.
For any reuse or distribution, you must make clear to others the license terms of this work.
The best way to do this is with a link to this web page.
Any of the above conditions can be waived if you get written permission from Ulitzer, Inc., the copyright holder.
Nothing in this license impairs or restricts the author's moral rights.