The History of SSL

Secure Sockets Layer, or SSL, technology is one method for protecting Internet users from malicious groups or software. It is currently used in Web browsers, instant messaging programs, email clients and other software. You most likely use, or have used, several applications that depend on SSL to secure communications between you and another computer that you are connecting to, such as an email server.

  1. Invention

    • The Netscape company created the SSL protocol in 1994. This technology allowed secure transmissions between computer applications on a remote server and the client's computer; however, it was never released to the public domain. SSL "provides privacy and integrity of the data that client and server applications exchange," according to IBM.

    Version 3.0

    • Netscape continued to develop SSL technology for several years. However, SSL version 2.0 contained numerous vulnerabilities. Adam Shostack, the author of "The New School of Information Security," released an article in 1995 that addressed some of the weaknesses of SSL 2.0, including that SSL is ineffective at protecting a user once his host's server is compromised. This leaves the server open to exploitation, possibly including hacking or virus infection.

      In 1996, Netscape released SSL 3.0 to address the vulnerabilities of the previous version. One of the improvements in SSL 3.0 over the previous version is the inability for outsiders to alter secure data during transmission. SSL 3.0 relies on message authentication codes, or MACs, that are encrypted at 128 bits, a significant increase from SSL 2.0's 40-bit keys. Tighter security around authentication keys makes SSL 3.0 less vulnerable to attacks such as hacking attempts.

    SSL Certificates

    • During the development of SSL 3.0, programmers were also creating SSL certificates. These certificates validate the genuineness of a website where, before, there was no way to guarantee that a harmful website or application wasn't impersonating a well-known name.

      SSL certificates protected consumers when making transactions with online businesses or logging into secure applications.

    Transport Layer Security

    • According to Microsoft, "the Internet Engineering Task Force (IETF) began work to develop a standard protocol that provided the same functionality [as SSL]. They used SSL 3.0 as the basis for that work, which became the TLS protocol." TLS 1.0 emerged in 1999 as an upgrade to SSL 3.0. Currently, SSL remains at version 3.0 while programmers have continued to develop TLS. In 2008, version 1.2 of TLS emerged.

      Computer specialists frequently refer to these combined protocols as "TLS/SSL" because they are similar, but the differences are notable. TLS includes more alert messages than its predecessor. These alerts are more specific and better explain problems that either session endpoint (user or server) detects during secure transmissions.

    Extended Validation SSL Certificates

    • SSL certificates received an update on June 12, 2007, after the Certification Authority/Browser Forum, or CA/Browser Forum, began investigating ways to improve them. The culmination of this time and effort are the current Extended Validation SSL certificates that you see occasionally in your Web browser or email client when you access secure pages.

      Your browser recognizes when you browse a secure Web page. For example, the address bar in Internet Explorer 7 and above will appear green and will display the name of the organization responsible for the website. Your browser extracts this information from the Extended Validation SSL certificate.

      In Firefox, authenticated sites will display a small lock icon in the status bar. Most other browsers alerts users of a secure connection with a similar lock icon, either in the status or the address bar.

Related Searches:

References

Resources

Comments

You May Also Like

  • History of SSL Encryption

    Secure socket layer (SSL) technology was developed by Netscape as a way to secure communication lines between networks over the Internet. The...

  • What Is SSL 2?

    Netscape released the first and second versions of the protocol called Secure Sockets Layer, or SSL for short, in 1994. The second...

  • Explain SSL

    Secure Sockets Layer (SSL) is a security protocol encountered on the Internet. It establishes an encrypted link between the server and browser...

  • SSL 3 Protocol

    The third version of the SSL, or Secure Sockets Layer, protocol is widely abbreviated SSL 3. Designed in 1995, SSL 3 is...

  • The Relationship Between SSL & TLS

    The SSL and TLS protocols are two separate sets of rules designed to make online transmissions more secure. The abbreviation SSL stands...

  • The History of Computer Technology

    Computer technology has advanced very quickly over the years. The term computer originally referred to people. It was a job title for...

  • What Is the Difference Between SSL & TLS?

    The Secure Sockets Layer and Transport Layer Security protocols are often abbreviated SSL and TLS, respectively. The SSL protocol preceded TLS, which...

  • Secure Socket Tunneling Protocol

    Tunneling is the process of hiding one packet inside another. Often this is done so that the contained packet can be entirely...

  • SSL Certificate Definition

    Secure socket layer (SSL) is a protocol for encrypting and sending data in a secure manner between two destinations. SSL also plays...

  • Examples of SSL Sockets

    Examples of SSL Sockets. SSL, or Secure Socket Layer, is a protocol designed to promote secure data transmission across a Web browser...

  • The Advantages of SSL

    An SSL stands for Secure Socket Layer. SSL was created by Netscape. The purpose of SSL is to transmit sensitive data over...

  • How Do I Know If I Have an SSL Certificate on My Website?

    An SSL certificate protects the incoming and outgoing flow of data from your website. It enables encryption of all the sensitive information...

  • The SSL V3 Protocol

    The secure socket layer (SSL) was developed by Netscape Communications Corporation as part of its hypertext transfer protocols, secure (HTTPS) protocols. It...

  • Advantages & Disadvantages of SSL

    Many website visitors are now savvy enough to recognize when a webpage is encrypted and protected by SSL technology. All a user...

  • The History of Hypertext Transfer Protocol

    HTTP, which stands for Hypertext Transfer Protocol, is a set of standards detailing how distributed information systems communicate. It is the way...

  • Netscape Navigator Features

    Netscape Navigator Features. Netscape Navigator was a popular Internet browser launched in 1994 by Netscape Communications. Netscape Navigator was a direct competitor...

  • How to Cause the SSL Handshake Failure

    SSL (Secure Socket Layer) is the primary encryption-protocol algorithm used on the Internet to secure websites and prevent eavesdropping. SSL requires several...

  • Safety Hazards of LED Lights

    LEDs are used in many households and industries as a source of lighting for both optical signals as well as standard lighting...

Related Ads

Featured