TLS in the wild

an internet-wide analysis of TLS-based protocols for electronic communication

Ralph Holz, Johanna Amann, Olivier Mehani, Matthias Wachs, Mohamed Ali Kâafar

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contribution

Abstract

Email and chat still constitute the majority of electronic communication on the Internet. The standardisation and acceptance of protocols such as SMTP, IMAP, POP3, XMPP, and IRC has allowed to deploy servers for email and chat in a
decentralised and interoperable fashion. These protocols can be secured by providing encryption with TLS—directly or via the STARTTLS extension. X.509 PKIs and ad hoc methods can be leveraged to authenticate communication peers. However, secure configuration is not straight-forward and many combinations
of encryption and authentication mechanisms lead to insecure deployments and potentially compromise of data in transit. In this paper, we present the largest study to date that investigates the security of our email and chat infrastructures. We used active Internet-wide scans to determine the amount of secure service
deployments, and employed passive monitoring to investigate to which degree user agents actually choose secure mechanisms for their communication. We addressed both client-to-server interactions as well as server-to-server forwarding. Apart from the authentication and encryption mechanisms that the investigated protocols offer on the transport layer, we also investigated the
methods for client authentication in use on the application layer. Our findings shed light on an insofar unexplored area of the Internet. Our results, in a nutshell, are a mix of both positive and negative findings. While large providers offer good security for their users, most of our communication is poorly secured in transit, with weaknesses in the cryptographic setup and especially in the choice of authentication mechanisms. We present a list of actionable changes to improve the situation.
Original languageEnglish
Title of host publicationNDSS 2016
Subtitle of host publication23rd Annual Network and Distributed System Security Symposium
Pages1-15
Number of pages15
DOIs
Publication statusPublished - 2016
Externally publishedYes
EventNetwork and Distributed System Security Symposium 2016 - San Diego, United States
Duration: 21 Feb 201624 Feb 2016
http://www.ndss-symposium.org/ndss2016/

Conference

ConferenceNetwork and Distributed System Security Symposium 2016
Abbreviated titleNDSS'16
CountryUnited States
CitySan Diego
Period21/02/1624/02/16
Internet address

Fingerprint Dive into the research topics of 'TLS in the wild: an internet-wide analysis of TLS-based protocols for electronic communication'. Together they form a unique fingerprint.

Cite this