Over the past three years, we have conducted several experiments observing IT professionals interacting with TLS certificates. The two most prominent of these experiments took place at DevConf.CZ 2017 and DevConf.CZ 2018. We investigated the usability of OpenSSL (as of 2019, the most common library for manipulating X.509 certificates), the developers’ understanding of multiple certificate issues and the trust they have to such flawed certificates. Conclusions based on these observations can help us produce an environment that is more usable for IT professionals resulting in fewer vulnerabilities in developed products.
Speaker: Martin Ukrop
Find more at the official website - https://research.redhat.com/research-...