SSL at Risk from Insecure Cookies | Internet News

SSL at Risk from Insecure Cookies

Aug 9, 2011
1 minute read

SSL certificates and encryption are supposed to protect websites and users, but there is a catch. For SSL (secure sockets layer) to work properly it needs to be properly configured. According to new research from security firm Qualys presented at the Black Hat security conference last week, the majority of SSL secured sites are not in fact fully secured. The new Qualys research builds on a study that Qualys did last year that found configuration issues with SSL certificates.

“Initially we enumerated all public SSL servers and we looked at how they were configured, but there was always something missing,” Ivan Ristic, security researcher at Qualys, told InternetNews.com. “That missing ‘thing’ was that we wanted to perform a deep analysis of how Web applications are implemented.”

Ristic noted that there are many things that can be done incorrectly at the Web application level to negate SSL security. As part of the Qualys study, Ristic analyzed the 300,000 most popular SSL secured sites in the world, looking for SSL related flaws and found a number of SSL flaws including the use of insecure cookies as well as mixing insecure traffic in with secured traffic.

 

Read the full story at eSecurityPlanet:
Most SSL Sites Vulnerable

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.