Secure by default - the case of TLS
Cryptography and Security
2017-08-28 v1
Abstract
Default configuration of various software applications often neglects security objectives. We tested the default configuration of TLS in dozen web and application servers. The results show that "secure by default" principle should be adopted more broadly by developers and package maintainers. In addition, system administrators cannot rely blindly on default security options.
Keywords
Cite
@article{arxiv.1708.07569,
title = {Secure by default - the case of TLS},
author = {Martin Stanek},
journal= {arXiv preprint arXiv:1708.07569},
year = {2017}
}
Comments
5 pages