LETS ENCRYPT Olivier Yiptong oyiptong@mozilla.com PRIVACY MATTERS - - PowerPoint PPT Presentation

let s encrypt
SMART_READER_LITE
LIVE PREVIEW

LETS ENCRYPT Olivier Yiptong oyiptong@mozilla.com PRIVACY MATTERS - - PowerPoint PPT Presentation

LETS ENCRYPT Olivier Yiptong oyiptong@mozilla.com PRIVACY MATTERS PRIVACY MATTERS: HTTPS Con fi dentiality Data Integrity Authentication NO PRIVACY: HTTP Public-only communication (Possibly?) Tampered messages Of


slide-1
SLIDE 1

LET’S ENCRYPT

Olivier Yiptong

  • yiptong@mozilla.com
slide-2
SLIDE 2

PRIVACY MATTERS

slide-3
SLIDE 3

PRIVACY MATTERS: HTTPS

  • Confidentiality
  • Data Integrity
  • Authentication
slide-4
SLIDE 4

NO PRIVACY: HTTP

  • Public-only communication
  • (Possibly?) Tampered messages
  • Of dubious origin
slide-5
SLIDE 5

PUBLIC COMMUNICATIONS

slide-6
SLIDE 6

PUBLIC COMMUNICATIONS

  • Firesheep
slide-7
SLIDE 7

PUBLIC COMMUNICATIONS

  • Firesheep
  • Google
slide-8
SLIDE 8

PUBLIC COMMUNICATIONS

  • Firesheep
  • Google
  • AT&T
slide-9
SLIDE 9

TAMPERING

slide-10
SLIDE 10

TAMPERING

  • Verizon Perma-Cookies
slide-11
SLIDE 11

TAMPERING

  • Verizon Perma-Cookies
slide-12
SLIDE 12

TAMPERING

  • Verizon Perma-Cookies
  • Comcast ad injection
slide-13
SLIDE 13

TAMPERING

  • Verizon Perma-Cookies
  • Comcast ad injection
  • China - GitHub
slide-14
SLIDE 14

OF DUBIOUS ORIGIN

slide-15
SLIDE 15
  • Turk Telecom

OF DUBIOUS ORIGIN

slide-16
SLIDE 16
  • Turk Telecom
  • China Netcom

OF DUBIOUS ORIGIN

slide-17
SLIDE 17
  • Turk Telecom
  • China Netcom
  • AT&T

OF DUBIOUS ORIGIN

slide-18
SLIDE 18

PRIVACY MATTERS: HTTPS

  • Encryption (Private communication)
  • Data Integrity (Certainly untampered)
  • Authentication (Certain of origin)
slide-19
SLIDE 19

HTTPS FOR YOU

  • Remove industrial espionage vector
  • No customer hijacking
  • No impersonation
slide-20
SLIDE 20

HTTP DEPRECATION

  • Firefox: non-secure website won’t have access to

new features

  • Chrome: display websites over HTTP as non-

secure

slide-21
SLIDE 21

UPCOMING FUNCTIONALITY

  • HTTP/2 (TLS-only on Firefox, Chrome and IE)
  • bandwidth + latency gains
  • Advanced Caching (ServiceWorkers)
slide-22
SLIDE 22

POSSIBLE UPGRADE PATH

  • Referrer Policy


http://www.w3.org/TR/referrer-policy

  • Upgrade Insecure Requests


http://www.w3.org/TR/upgrade-insecure-requests/

slide-23
SLIDE 23

THANKS

  • yiptong@mozilla.com