secure letterhead

36
© 2004 VeriSign, Inc. Secure Letterhead Phillip Hallam-Baker Principal Scientist VeriSign Inc.

Upload: ethan-strickland

Post on 31-Dec-2015

54 views

Category:

Documents


0 download

DESCRIPTION

Secure Letterhead. Phillip Hallam-Baker Principal Scientist VeriSign Inc. We are not in Kansas any more. Their Goal. Our Goal. We do not have to find a silver bullet. 20% reduction. Make your problem their problem. Phishing:. The use of social engineering to steal access credentials. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Secure Letterhead

© 2004 VeriSign, Inc.

Secure LetterheadPhillip Hallam-Baker

Principal Scientist

VeriSign Inc.

Page 2: Secure Letterhead

2

We are not in Kansas any more

Page 3: Secure Letterhead

3

Their Goal

Page 4: Secure Letterhead

4

Our Goal

Page 5: Secure Letterhead

5

We do not have to find a silver bullet

Page 6: Secure Letterhead

6

20% reduction

Page 7: Secure Letterhead

7

Makeyour problemtheir problem

Page 8: Secure Letterhead

8

Phishing:The use of social engineering to

steal access credentials

Page 9: Secure Letterhead

9

Approach 1Respond to Attacks

Page 10: Secure Letterhead

10

Approach 2Deploy Strong

Credentials

Page 11: Secure Letterhead

11

Approach 2Disrupt the Social

Engineering Attack

Page 12: Secure Letterhead

12

User Education

Page 13: Secure Letterhead

13

The Real End-to-End Security Story

Page 14: Secure Letterhead

14

We must take multiple approaches

Page 15: Secure Letterhead

15

Which is Best?

Page 16: Secure Letterhead

16

All of them.

Page 17: Secure Letterhead

17

Strong Inbound Authentication+

Fraud Detection+

Capture Site Take Down+

Strong Outbound Authentication

Page 18: Secure Letterhead

18

Secure Letterhead:How to know a

message is authentic

Page 19: Secure Letterhead

20

before the next horse…

Page 20: Secure Letterhead

22

How does a user identify a site today?

Page 21: Secure Letterhead

23

What was the DNS designed to do?

Page 22: Secure Letterhead

24

A location service should be permissive

+ Where do I find The dotFuture Manifesto on the Web?+ www.thedotfuturemanifesto.com+ www.the-dotfuture-manifesto.com+ www.thedotfuturemanifesto.org+ dotfuturemanifesto.blogspot.com

Page 23: Secure Letterhead

25

An authentication service should be

restrictive

Page 24: Secure Letterhead

26

Solution:Separate the

authentication channel

Page 25: Secure Letterhead

27

How do we deploy?

Page 26: Secure Letterhead

28

Solution:Leverage the SSL Certificate Market

Page 27: Secure Letterhead

29

First Generation SSL Certs:

Accountability

Page 28: Secure Letterhead

30

Secure Letterhead

Page 29: Secure Letterhead

31

Page 30: Secure Letterhead

32

Who Guards the Guardians?

Page 31: Secure Letterhead

33

Accountability

Page 32: Secure Letterhead

34

The Trust Brand on the Line

Page 33: Secure Letterhead

35

What is missing?

Page 34: Secure Letterhead

36

Browser Support

Page 35: Secure Letterhead

37

LOGOTYPE Certificate Issuers

Page 36: Secure Letterhead

© 2004 VeriSign, Inc.

Thank Youwww.verisign.com/antiphishing

dotcrimemanifesto.blogspot.com