SlideShare a Scribd company logo
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 1
How to Be Trusted in 2017
Three Big Questions to Address, Now
Dean Coclin
Chairman Emeritus,
CA/Browser Forum
Jeff Barto
Trust Strategist & Web
Security Advocate, Symantec
Tips for Your Success
•  The live webinar is being recorded for on-demand access. We’ll
provide webinar slides as an attachment to download.
•  Submit questions during the live webinar and we’ll respond
during the live Q&A segment.
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 2
Contribute to and follow the conversation on
Twitter with this hashtag; we’re listening:
#BeTrusted2017
Agenda
•  Introductions
•  Three Big Questions:
1.  What browser changes start rolling out in January 2017?
2.  Why are these browser changes happening?
3.  How do we prepare now to be trusted in 2017?
•  Q&A
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 3
Today’s Presenters
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 4
Jeff Barto
Trust Strategist & Web Security
Advocate, Symantec
Dean Coclin
Chairman Emeritus, CA/
Browser Forum, Symantec
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 5
What browser changes start
rolling out in January 2017?
in January 2017 with browser changes?
#1
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 6
Starting January 2017, Browsers Will Warn
Users of Non-HTTPS Connections
Chrome plans to warn users when
pages are insecure (non-https),
and will warn if an insecure page
asks for a password or credit card
with words “Not Secure”
Firefox plans a similar warning
for sites requiring passwords
Both will quickly transition to a more
noticeable red triangle and “Not Secure”
warnings for ALL non-https websites
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 7
Chrome Warnings and User Experience
Treatment of HTTP pages with
password or credit card form fields:
Current (Chrome 53) login.example.com
Jan. 2017 (Chrome 56) login.example.comNot secure
Source: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 8
Firefox Warnings and User Experience
When passwords are requested over http:
http-password.badssl.com
DevEdition 46+
http-password.badssl.com
DevEdition 45
Source: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 9
HTTPS Coming to a Domain Near You
CA Security Blog Post, Nov. 21, 2016:
https://casecurity.org/2016/11/21/the-
web-is-moving-from-http-to-https/
Gov.UK website:
https://www.gov.uk/service-manual/
technology/using-https
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 10
Powerful Features Only with HTTPS
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 11
Why are these browser
changes happening?
#2
Cybercriminals Are Hurting Businesses and
Consumers Worldwide
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 12
Source: Symantec Website Security Threat Report, 2016
https://www.symantec.com/security-center/threat-report
Trust Indicators Need to Become More Intuitive
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 13
Symbols That Are Consistent, Universal, Global
No Learning Curve!
Inconsistency Across Browsers
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 14
People Want Simple, Trustworthy User
Experiences that Convey “It’s Safe Here”
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 15
Excerpt from ‘Why Website Security That’s Good Enough Soon Won’t Be’
is available to download at Go.Symantec.com/Be-Trusted
Related Predictions
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 16
Certificate usage will continue to
grow! 9 - 12 Million in 12 months
Fueled by https initiatives (search ranks,
powerful features, negative browser UI)
SNI servers will show
increased growth
SHA-1 usage will
decline dramatically
(and so will XP!)
Phishing using DV certs
will continue to increase
Chrome will be on the
bleeding edge of changes
and enforcements
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 17
How do we prepare now
to be trusted in 2017?
#3
Apply Our ‘Be Trusted Framework’
Credibility Control Performance
Elevate your search
ranking with a more
trustworthy presence via
site-wide HTTPS
encryption
Maintain user experience
control by preventing ISPs
and Wi-Fi hot spots from
inserting ads on your web
pages
Ad injections are not
optimized for load time
which will slow down HTTP
sites
Demonstrate your
organization’s legitimacy by
using OV & EV certificates
Eliminate vulnerabilities,
malware, and other breach
risks
Get HTTP2’s performance
enhancements – only
available to secured
websites
Give consumers more
confidence with the Norton
Secure seal – on the first
and every page your
visitors see
Maintain brand reputation
and convey digital business
trustworthiness
Deploy certificates which
use ECC algorithm – to
mitigate and lessen
computational overhead
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 18
Start with Encryption …
•  On every page requiring a
password or allowing payments:
–  Invoke HTTPS
–  Deploy SSL on servers delivering
those pages and content
•  Form and embark on your plan to
move to SSL/HTTPS site-wide
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 19
… then Go Beyond
Encryption
Authentication
Validation
Be
Trusted
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 20
Simple Website Security Math
Make the Right Choice
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 21
Excerpt from ‘Why Website Security That’s Good Enough Soon Won’t Be’
is available for download at Go.Symantec.com/Be-Trusted
Research Illustrates the Value of Trust
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 22
23#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted
https://go.symantec.com/be-trusted
Let’s Answer Your Questions
Visit Our Content Hub
#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 24
https://go.symantec.com/be-trusted
•  Get complimentary best
practices and How-To info
•  Participate in live
discussions and webinars
•  Read and share blogs from
our website security experts
•  Choose and purchase SSL/
TLS certificates that are
right for your organization

More Related Content

PPTX
Clickjacking DevCon2011
PPT
Top Ten Web Hacking Techniques – 2008
PDF
Which plugins rule the world?
PPTX
Link Reclamation Strategies
PDF
ResellerClub Ctrl+F5 - WordPress Security session
PPTX
JSFoo Chennai 2012
PDF
Sucuri Webinar: How to identify and clean a hacked Joomla! website
PPT
Why wordpress is not completely safe
Clickjacking DevCon2011
Top Ten Web Hacking Techniques – 2008
Which plugins rule the world?
Link Reclamation Strategies
ResellerClub Ctrl+F5 - WordPress Security session
JSFoo Chennai 2012
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Why wordpress is not completely safe

What's hot (16)

PPTX
Html5 security
PPT
StartPad Countdown 2 - Startup Security: Hacking and Compliance in a Web 2.0 ...
PPTX
Sucuri Webinar: How Websites Get Hacked
PPTX
Chrome and Flash
PPTX
Understanding word press security wwc-4-7-17
PDF
Sucuri Webinar: Impacts of a website compromise
PPT
Website Backup
PPTX
Webmatrix 2 beta
PPTX
Top Ten Web Hacking Techniques of 2012
PDF
Introduction to Optimizing WordPress for Website Speed
PPTX
WebSockets On Fire
PPTX
Azure web sites
PPT
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
PPTX
Sucuri Webinar: What is SEO Spam and How to Fight It
PDF
Safer browsing
PDF
Introduction to WordPress Security
Html5 security
StartPad Countdown 2 - Startup Security: Hacking and Compliance in a Web 2.0 ...
Sucuri Webinar: How Websites Get Hacked
Chrome and Flash
Understanding word press security wwc-4-7-17
Sucuri Webinar: Impacts of a website compromise
Website Backup
Webmatrix 2 beta
Top Ten Web Hacking Techniques of 2012
Introduction to Optimizing WordPress for Website Speed
WebSockets On Fire
Azure web sites
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
Sucuri Webinar: What is SEO Spam and How to Fight It
Safer browsing
Introduction to WordPress Security
Ad

Similar to How to be trusted in 2017 (20)

PDF
WordCamp US: Delivering the news over HTTPS
PPTX
SEO benefits | ssl certificate | Learn SEO
PPTX
Speed & Uptime with Wordpress
PPTX
Creating Secure Web Apps: What Every Developer Needs to Know About HTTPS Today
PDF
Webinar - How and Why Your Library Should Move to HTTPS 2018-07-17
PPTX
WordCamp Raleigh 2017 - Move from HTTP to HTTPS or become irrelevant - Peter ...
PPTX
SEO Considerations When Migrating to HTTPS by Kenneth Sytian
PPTX
Migrating Your WordPress Site to HTTPS - Getting it right the first time Word...
PDF
NICAR delivering the news over HTTPS
PPTX
SSL and Wordpress
PPTX
The Notorious 9: Is Your Data Secure in the Cloud?
PPT
Adwebtech ssl presentation_beyond_https
PDF
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
PPTX
Why Security is the New Go Faster Stripe | Crystal Carter | Brighton SEO
PDF
E-commerce Lab work
PDF
Website Security Certification The Key to Keeping Your Website Safe
PDF
HTTPS Site Migration | SearchLondon
PDF
Bp101-Can Domino Be Hacked
PPTX
Steps to Keep Your Site Clean
PDF
Secure Web hosting provider - KTCHost
WordCamp US: Delivering the news over HTTPS
SEO benefits | ssl certificate | Learn SEO
Speed & Uptime with Wordpress
Creating Secure Web Apps: What Every Developer Needs to Know About HTTPS Today
Webinar - How and Why Your Library Should Move to HTTPS 2018-07-17
WordCamp Raleigh 2017 - Move from HTTP to HTTPS or become irrelevant - Peter ...
SEO Considerations When Migrating to HTTPS by Kenneth Sytian
Migrating Your WordPress Site to HTTPS - Getting it right the first time Word...
NICAR delivering the news over HTTPS
SSL and Wordpress
The Notorious 9: Is Your Data Secure in the Cloud?
Adwebtech ssl presentation_beyond_https
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
Why Security is the New Go Faster Stripe | Crystal Carter | Brighton SEO
E-commerce Lab work
Website Security Certification The Key to Keeping Your Website Safe
HTTPS Site Migration | SearchLondon
Bp101-Can Domino Be Hacked
Steps to Keep Your Site Clean
Secure Web hosting provider - KTCHost
Ad

More from Zeev Shetach (11)

PDF
חמש שיטות לתעדוף משימות פיתוח
PPTX
Online Digital Signature Portal
PPTX
פורטל חתימות אונליין - החתימו לקוחות, עובדים, חברי צוות ועוד- מכל מקום
PPTX
Digital Signatures solution by ComsignTrust
PPT
פרשיית דלף מידע ברשתות חברתיות ובסלולר - משרד הביטחון
PDF
Electronic Signatures Guidance - by BEIS
PPSX
פתרונות ביומטריים - רשיונות נהיגה ביומטריים | קומדע
PDF
Rsa authentication manager 8.2 presentation
PPSX
Comsign & Trust
PDF
המדריך לחסכון ארגוני באמצעות טכנולוגיה
PPTX
ComsignTrust Overview
חמש שיטות לתעדוף משימות פיתוח
Online Digital Signature Portal
פורטל חתימות אונליין - החתימו לקוחות, עובדים, חברי צוות ועוד- מכל מקום
Digital Signatures solution by ComsignTrust
פרשיית דלף מידע ברשתות חברתיות ובסלולר - משרד הביטחון
Electronic Signatures Guidance - by BEIS
פתרונות ביומטריים - רשיונות נהיגה ביומטריים | קומדע
Rsa authentication manager 8.2 presentation
Comsign & Trust
המדריך לחסכון ארגוני באמצעות טכנולוגיה
ComsignTrust Overview

Recently uploaded (20)

PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PPTX
Internet___Basics___Styled_ presentation
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
DOCX
Unit-3 cyber security network security of internet system
PPTX
artificial intelligence overview of it and more
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PPTX
522797556-Unit-2-Temperature-measurement-1-1.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PPTX
Funds Management Learning Material for Beg
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
An introduction to the IFRS (ISSB) Stndards.pdf
PPT
tcp ip networks nd ip layering assotred slides
PPTX
innovation process that make everything different.pptx
PPT
Ethics in Information System - Management Information System
Unit-1 introduction to cyber security discuss about how to secure a system
Internet___Basics___Styled_ presentation
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
Paper PDF World Game (s) Great Redesign.pdf
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
Job_Card_System_Styled_lorem_ipsum_.pptx
Unit-3 cyber security network security of internet system
artificial intelligence overview of it and more
The New Creative Director: How AI Tools for Social Media Content Creation Are...
Module 1 - Cyber Law and Ethics 101.pptx
522797556-Unit-2-Temperature-measurement-1-1.pptx
international classification of diseases ICD-10 review PPT.pptx
Funds Management Learning Material for Beg
introduction about ICD -10 & ICD-11 ppt.pptx
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
An introduction to the IFRS (ISSB) Stndards.pdf
tcp ip networks nd ip layering assotred slides
innovation process that make everything different.pptx
Ethics in Information System - Management Information System

How to be trusted in 2017

  • 1. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 1 How to Be Trusted in 2017 Three Big Questions to Address, Now Dean Coclin Chairman Emeritus, CA/Browser Forum Jeff Barto Trust Strategist & Web Security Advocate, Symantec
  • 2. Tips for Your Success •  The live webinar is being recorded for on-demand access. We’ll provide webinar slides as an attachment to download. •  Submit questions during the live webinar and we’ll respond during the live Q&A segment. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 2 Contribute to and follow the conversation on Twitter with this hashtag; we’re listening: #BeTrusted2017
  • 3. Agenda •  Introductions •  Three Big Questions: 1.  What browser changes start rolling out in January 2017? 2.  Why are these browser changes happening? 3.  How do we prepare now to be trusted in 2017? •  Q&A #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 3
  • 4. Today’s Presenters #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 4 Jeff Barto Trust Strategist & Web Security Advocate, Symantec Dean Coclin Chairman Emeritus, CA/ Browser Forum, Symantec
  • 5. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 5 What browser changes start rolling out in January 2017? in January 2017 with browser changes? #1
  • 6. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 6 Starting January 2017, Browsers Will Warn Users of Non-HTTPS Connections Chrome plans to warn users when pages are insecure (non-https), and will warn if an insecure page asks for a password or credit card with words “Not Secure” Firefox plans a similar warning for sites requiring passwords Both will quickly transition to a more noticeable red triangle and “Not Secure” warnings for ALL non-https websites
  • 7. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 7 Chrome Warnings and User Experience Treatment of HTTP pages with password or credit card form fields: Current (Chrome 53) login.example.com Jan. 2017 (Chrome 56) login.example.comNot secure Source: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
  • 8. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 8 Firefox Warnings and User Experience When passwords are requested over http: http-password.badssl.com DevEdition 46+ http-password.badssl.com DevEdition 45 Source: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please
  • 9. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 9 HTTPS Coming to a Domain Near You CA Security Blog Post, Nov. 21, 2016: https://casecurity.org/2016/11/21/the- web-is-moving-from-http-to-https/ Gov.UK website: https://www.gov.uk/service-manual/ technology/using-https
  • 10. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 10 Powerful Features Only with HTTPS
  • 11. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 11 Why are these browser changes happening? #2
  • 12. Cybercriminals Are Hurting Businesses and Consumers Worldwide #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 12 Source: Symantec Website Security Threat Report, 2016 https://www.symantec.com/security-center/threat-report
  • 13. Trust Indicators Need to Become More Intuitive #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 13 Symbols That Are Consistent, Universal, Global No Learning Curve!
  • 14. Inconsistency Across Browsers #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 14
  • 15. People Want Simple, Trustworthy User Experiences that Convey “It’s Safe Here” #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 15 Excerpt from ‘Why Website Security That’s Good Enough Soon Won’t Be’ is available to download at Go.Symantec.com/Be-Trusted
  • 16. Related Predictions #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 16 Certificate usage will continue to grow! 9 - 12 Million in 12 months Fueled by https initiatives (search ranks, powerful features, negative browser UI) SNI servers will show increased growth SHA-1 usage will decline dramatically (and so will XP!) Phishing using DV certs will continue to increase Chrome will be on the bleeding edge of changes and enforcements
  • 17. #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 17 How do we prepare now to be trusted in 2017? #3
  • 18. Apply Our ‘Be Trusted Framework’ Credibility Control Performance Elevate your search ranking with a more trustworthy presence via site-wide HTTPS encryption Maintain user experience control by preventing ISPs and Wi-Fi hot spots from inserting ads on your web pages Ad injections are not optimized for load time which will slow down HTTP sites Demonstrate your organization’s legitimacy by using OV & EV certificates Eliminate vulnerabilities, malware, and other breach risks Get HTTP2’s performance enhancements – only available to secured websites Give consumers more confidence with the Norton Secure seal – on the first and every page your visitors see Maintain brand reputation and convey digital business trustworthiness Deploy certificates which use ECC algorithm – to mitigate and lessen computational overhead #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 18
  • 19. Start with Encryption … •  On every page requiring a password or allowing payments: –  Invoke HTTPS –  Deploy SSL on servers delivering those pages and content •  Form and embark on your plan to move to SSL/HTTPS site-wide #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 19
  • 20. … then Go Beyond Encryption Authentication Validation Be Trusted #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 20 Simple Website Security Math
  • 21. Make the Right Choice #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 21 Excerpt from ‘Why Website Security That’s Good Enough Soon Won’t Be’ is available for download at Go.Symantec.com/Be-Trusted
  • 22. Research Illustrates the Value of Trust #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 22
  • 23. 23#BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted https://go.symantec.com/be-trusted Let’s Answer Your Questions
  • 24. Visit Our Content Hub #BeTrusted2017 | More Resources: https://go.symantec.com/be-trusted 24 https://go.symantec.com/be-trusted •  Get complimentary best practices and How-To info •  Participate in live discussions and webinars •  Read and share blogs from our website security experts •  Choose and purchase SSL/ TLS certificates that are right for your organization