Startup proposes a safer Internet locale via a '.secure' domain

Security researcher envisions a top-level domain designed with security in mind for safer Web browsing.

Researchers behind Artemis are working on creating a safer place on the Internet.

A security startup called Artemis Internet has proposed a new ".secure" top-level domain that would require Web sites using the domain to maintain stringent security practices.

The goal is to offer a place on the Web where sites have higher security standards and Web surfers can have more faith that their data and communications will stay out of the hands of malicious hackers and criminals.

Stamos also is working on new Internet domain standards, dubbed the Domain Policy Framework, designed to bring advanced security features to browsers and Web communications and which can be used by any top-level domain.

The .Secure registry will require registrants to submit identity documentation and will take steps to verify identities. Registrants will have to agree to a code of conduct and meet strict security standards, including using beefed up authentication and encryption with Domain Name System Security Extensions (DNSSEC) and Transport Layer Security for all HTTP sessions and between e-mail servers. The .Secure registry will also scan sites to see if they are hosting malware or phishing attacks.

"There will be sites that get hacked in .secure and we'll have to deal with that," Stamos said. "But when that happens it won't be because of something simple.... If you have a SQL injection vulnerability on your front page we'll give you a reasonable timeframe to remove it or your site will disappear."

"Man-in-the-middle attacks will be very difficult even if a stolen certificate is used. A limited number of Certificate Authorities will be allowed to create .Secure certificates," he said. Meanwhile, "there will be no typo squatting, nobody pretending to be who they aren't."

"As bad as Certificate Authorities are, DNS-based security mechanisms like DANE and DNSSEC are worse," he wrote in an e-mail. "They are the ultimate expression of a lack of agility. If we sign up to trust the organizations who manage that infrastructure, we're signing up to trust them forever; without any opportunity to change our minds in the future, and without any incentives for them to continue warranting our trust."

To put the power into the hands of Web surfers themselves, Marlinspike has developed a Firefox plug-in called Convergence that is designed to allow people to browse safely.

See the original post:
Startup proposes a safer Internet locale via a '.secure' domain

Related Posts

Comments are closed.