Full Program »
One Year of SSL Internet Measurement
To assess the quality of HTTPS servers in the wild, we enumerated HTTPS servers on the internet in July 2010 and July 2011. We sent several stimuli against the servers to gather detailed information. We then analysed some parameters of the collected data and looked at how they evolved. We also focused on two subsets of the TLS hosts within our measure: the trusted hosts (possessing a valid certificate at the time of the probing) and EV hosts (presenting a trusted, so-called Extended Validation certificate). Our contributions rely on this methodology: the stimuli we sent, the criteria we studied and the subsets we focused on.
Even if EV servers present a somewhat improved certificate quality over the TLS hosts, we show they do not offer overall high quality sessions, which could and should be improved.
Author(s):
Olivier Levillain
French Network and Information Security Agency (ANSSI)
France
Arnaud Ébalard
French Network and Information Security Agency (ANSSI)
France
Benjamin Morin
French Network and Information Security Agency (ANSSI)
France
Hervé Debar
Télécom Sud Paris
France