Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Privacy » Secure/Encrypted Transactions

Secure/Encrypted Transactions

Category: Privacy
Published: 12/05/2006, 17:21  
Editor: Security Software Zone
 
Print article
Send to a friend
Search in reviews
When you use an encryption method, information submitted  using Web fill-in forms, including user names, passwords,adress, phone and other confidential information, can be transmitted securely to and from the Web server.

A wide range of proposed and/or partially implemented encrypt solutions for the Web exist, but most are not ready for prime time. Of the several methods, only the Secure HTTP (S-HTTP) and Secure Socket Layer (SSL) protocols have emerged in anything like full-blown form. Unfortunately, the two are implemented mutually exclusively, though compatibility is possible. Worse, Web browsers and servers that support oneof this  method don't support the other, so you can reliably use one or the other only if you carefully match your Web server and customers' browsers.

S-HTTP
Secure HTTP was developed by Enterprise Integration Technologies and RSA Data Security, and the public S-HTTP standards are now managed by CommerceNet, a not-for-profit consortium that is conducting the first large-scale market trial of technologies and business processes to support electronic commerce over the Internet. S-HTTP is a modified version of the current HTTP protocol. It supports the following:

-User and Web server authentication using digital signatures, and signature keys using both the RSA and MD5 algorithms
-Privacy of transactions, using several different key-based encryption methods
-Generation of key certificates for server authentication
-As with SSL, you must have a compatible Web server and browser that both support S-HTTP transactions in order to use this technology. IIS 1.0 supports only SSL.

SSL
S-HTTP seems to have been engulfed in the 1995 Netscape tidal wave. Unwilling to wait for widely accepted HTTP security standards to evolve (as it was with HTML as well), Netscape Communications Corporation developed its own Secure Sockets Layer encryption mechanism. SSL occupies a spot on the ISO seven-layer network reference below that of the HTTP protocol, which operates at the application layer. (See Table 10.1.) Rather than developing a completely new protocol to replace HTTP, SSL sits between HTTP and the underlying TCP/IP network protocols and can intervene to create secure transactions. Netscape makes the technical details of SSL publicly available. In addition, C-language source code for a reference implementation of SSL is freely available for non-commercial use. Microsoft includes SSL support in both IIS and Internet Explorer.


Bookmark to:
Add 'Secure/Encrypted Transactions' to Del.icio.us Add 'Secure/Encrypted Transactions' to digg Add 'Secure/Encrypted Transactions' to FURL Add 'Secure/Encrypted Transactions' to reddit Add 'Secure/Encrypted Transactions' to Technorati Add 'Secure/Encrypted Transactions' to Yahoo My Web Add 'Secure/Encrypted Transactions' to Stumble Upon Add 'Secure/Encrypted Transactions' to Google Bookmarks Add 'Secure/Encrypted Transactions' to RawSugar Add 'Secure/Encrypted Transactions' to Squidoo Add 'Secure/Encrypted Transactions' to Spurl Add 'Secure/Encrypted Transactions' to Netvouz Add 'Secure/Encrypted Transactions' to Rojo Add 'Secure/Encrypted Transactions' to Bloglines Add 'Secure/Encrypted Transactions' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Secure/Encrypted Transactions
 

Keeping top secret files
 Everyone wants to stay secure, to keep his privacy.
Read More >
12/18/2006, 13:39
 

freeIDENTITYprotect.com Was Launched
  Launched today, freeIDENTITYprotect.com provide customers the first free comprehensive resource for identity theft protection. This service consolidates the best-of-breed services available to consumers today in one location - providing a one-stop-shop for identity theft prevention.
Read More >
02/27/2008, 12:22
 

Protect Sensitive Cardholder Information and Prevent Credit Card Fraud
 The provider of hosted and premise-based IVR and VoIP systems, Voxeo, announced compliance to PCI DSS- the Payment Card Industry Data Security Standard developed to protect sensitive cardholder information and prevent credit card fraud.
Read More >
05/02/2007, 14:19
 

Solutions for Mutual Customers Integrated by IBBS and RR Enterprises LTD.
 The technology leader providing the Broadband Explorer (BBX) diagnostics and provisioning software, Integrated BroadBand Services, LLC, and RR Enterprises LTD, today announced the successful integration of BBX with the RR SmartLink Internet Module (Subscriber Management and Billing System) for their mutual customers.
Read More >
04/01/2008, 14:23
 

SEcureCard from StoneEagle Selected by Innovative Aftermarket Systems (IAS)
 The StoneEagle Group (StoneEagle) announced today that the leading provider of revolutionary F&I selling software and superior aftermarket programs, Innovative Aftermarket Systems (IAS), has selected SEcureCard to automate the claims management process for its R.O.A.D. InTire program.
Read More >
03/05/2008, 18:34

Sponsored