English

Secure by default - the case of TLS

Cryptography and Security 2017-08-28 v1

Abstract

Default configuration of various software applications often neglects security objectives. We tested the default configuration of TLS in dozen web and application servers. The results show that "secure by default" principle should be adopted more broadly by developers and package maintainers. In addition, system administrators cannot rely blindly on default security options.

Keywords

Cite

@article{arxiv.1708.07569,
  title  = {Secure by default - the case of TLS},
  author = {Martin Stanek},
  journal= {arXiv preprint arXiv:1708.07569},
  year   = {2017}
}

Comments

5 pages

R2 v1 2026-06-22T21:23:08.164Z