Visible to the public POSTER: Re-Thinking Risks and Rewards for Trusted Third Parties

TitlePOSTER: Re-Thinking Risks and Rewards for Trusted Third Parties
Publication TypeConference Paper
Year of Publication2016
AuthorsMalchow, Jan-Ole, Güldenring, Benjamin, Roth, Volker
Conference NameProceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4139-4
Keywordscertificate authorities, connection insurances, HTTPs, Human Behavior, Metrics, pubcrawl, Resiliency, scalabilty, SSL, SSL Trust Models, TLS, transaction insurances, trusted third parties
AbstractCommercial trusted third parties (TTPs) may increase their bottom line by watering down their validation procedures because they assume no liability for lapses of judgement. Consumers bear the risk of misplaced trust. Reputation loss is a weak deterrent for TTPs because consumers do not choose them - web shops and browser vendors do. At the same time, consumers are the source of income of these parties. Hence, risks and rewards are not well-aligned. Towards a better alignment, we explore the brokering of connection insurances and transaction insurances, where consumers get to choose their insurer. We lay out the principal idea how such a brokerage might work at a technical level with minimal interference with existing protocols and mechanisms, we analyze the security requirements and we propose techniques to meet these requirements.
URLhttp://doi.acm.org/10.1145/2976749.2989060
DOI10.1145/2976749.2989060
Citation Keymalchow_poster:_2016