A new internet browser, Comodo Dragon, reports that more than half of the world's valid SSL certificates are unsafe.
Comodo Dragon is based on the open source Chromium project, but includes additional security and privacy features. In particular, when a user browses to a site that uses a domain-validated SSL certificate, Comodo Dragon will warn the user that the site may not have undergone trusted third-party validation.
Users are presented with buttons to "Proceed anyway", or go "Back to safety". The warning message explains why such a site is deemed to be unsafe:
The security (or SSL) certificate for this website indicates that the organization operating it may not have undergone trusted third-party validation that it is a legitimate business. Although the information passed between you and this website will be encrypted, you have no assurance of who you are actually exchanging information with, and many websites connected to cyber-crimes use this type of security certificate. Prior to exchanging sensitive information including login/password, personal identity information, or financial details such as credit card numbers with any website that generates this warning, you should find some alternative method of validating this business or consider abandoning the transaction.
Mainstream adoption of this behaviour would have a huge impact on e-commerce — more than half of the SSL certificates in use on the web are domain-validated, and this market continues to show strong growth due to the generally lower costs and ease of issuance when compared with organisation and extended validation certificates.
However, none of the popular browsers provides an explicit warning when browsing to a domain-validated site. With such widespread use of domain-validated certificates, it would undoubtedly lead to uproar if any of these browsers were to display warnings when users browse to domain-validated sites.
Although Comodo states that many websites connected to cyber-crimes use domain-validated certificates, Netcraft's phishing site feed shows that only 0.3% of reported phishing sites use HTTPS, including those running on compromised servers with SSL certificates already in place.
Netcraft found 683,563 valid domain-validated certificates in its March 2010 survey. Go Daddy has issued more than half of these, which it currently sells at $29.99 per year for new purchases.
Comodo itself is also a sizable player in the domain-validated SSL market, accounting for 7.6% of all domain-validated certificates. Ironically, domain-validated certificates signed by Comodo are also reported as being potentially unsafe, including those sold via hosting companies such as DreamHost.
DreamHost's CTO, Dallas Kashuba, told Netcraft: "I think the information being presented about the nature of the SSL certificate is useful, but the approach Comodo has taken to present the information is heavy-handed and seems a bit too close to "crying wolf". I worry that users of the browser will see that warning so frequently that they will become desensitized to all warnings."
Last year, DreamHost launched an amusing tirade against certificate authorities, criticising the "entirely automated" process of issuing domain-validated certificates. To prove a point, DreamHost then began offering domain-validated certificates to existing customers for only $15, stating: "...we're not making anything on them because we feel the whole business is a scam!"
DreamHost's Kashuba also told Netcraft: "I think Extended Validation SSL certificates are a good way to reduce the impact of phishing and other similar nefarious activities, but is not a necessary expense for most secure websites."
There is no doubt that upsetting the current level of trust in domain-validated certificates would cause problems: Many FDIC members continue to use domain-validated certificates for their banking sites, including Bank of the Sierra, Bank of Hawaii, TierOne Bank and Great Western Bank.
For additional information or details on how to order the Netcraft SSL Survey, please contact us at sales@netcraft.com.
| Rank | Company site | OS | Outage hh:mm:ss |
Failed Req% |
DNS | Connect | First byte |
Total |
|---|---|---|---|---|---|---|---|---|
| 1 | www.navisite.com | Linux | 0.000 | 0.779 | 0.033 | 0.552 | 0.656 | |
| 2 | DataPipe | FreeBSD | 0:00:00 | 0.005 | 0.397 | 0.035 | 0.061 | 0.091 |
| 3 | INetU | unknown | 0:00:00 | 0.005 | 0.524 | 0.050 | 0.106 | 0.186 |
| 4 | Hosting 4 Less | Linux | 0:00:00 | 0.011 | 0.428 | 0.105 | 0.220 | 0.560 |
| 5 | www.singlehop.com | Linux | 0:00:00 | 0.016 | 0.205 | 0.052 | 0.342 | 0.570 |
| 6 | www.dinahosting.com | Linux | 0:00:00 | 0.016 | 0.115 | 0.089 | 0.182 | 0.182 |
| 7 | New York Internet | FreeBSD | 0:00:00 | 0.021 | 0.054 | 0.031 | 0.070 | 0.195 |
| 8 | Virtual Internet | Linux | 0:00:00 | 0.021 | 0.617 | 0.078 | 0.210 | 0.443 |
| 9 | www.memset.com | Linux | 0:00:00 | 0.021 | 0.616 | 0.080 | 0.160 | 0.160 |
| 10 | Hostbasket | Windows Server 2008 | 0:00:00 | 0.021 | 0.377 | 0.083 | 0.177 | 0.177 |
NaviSite had the most reliable hosting company site in February, responding to all of Netcraft's requests.
NaviSite, providers of managed hosting and application management solutions, sold its Lawson/Kronos Managed Application Service business this month in order to "focus on providing Enterprise-class cloud computing for large organisations with complex environments". NaviSite uses Apache on CentOS to run its own website.
The second most reliable hosting company site in February was DataPipe, responding to all but one of Netcraft's requests.
DataPipe provides custom managed hosting solutions for businesses with complex Internet facing infrastructures with over 1,000 customers in seven data centres across the United States, Europe and China. DataPipe use Apache on FreeBSD to run their own website.
Six of the top ten in February were identified as running Linux, two as running FreeBSD and one running Windows Server 2008.
Netcraft measures and makes available the response times of around forty leading hosting providers' sites. The performance measurements are made at fifteen minute intervals from separate points around the internet, and averages are calculated over the immediately preceding 24 hour period.
From a customer's point of view, the percentage of failed requests is more pertinent than outages on hosting companies' own sites, as this gives a pointer to reliability of routing, and this is why we choose to rank our table by fewest failed requests, rather than shortest periods of outage.
Further information on the measurement process and current measurements are available.
In the February 2010 survey we received responses from 207,316,960 sites.
The biggest change of the month belongs to Apache with a 1.6M increase in hostnames. It was closely followed by Microsoft which saw a growth of 1.1M.
After a year long consistent rise nginx is experiencing a loss for a second month in a row as inactive weblogs on WordPress and 163.com are expired out of the survey. This month nginx had a decrease of 1.5M hostnames, which brings its total down to the number of hostnames it had in October.
China Internet Network Information Center has recently announced a change in the .cn domain name registration regulations. Since December 14th individuals can no longer register .cn domains and a paper application has to be submitted to register one along with photocopies of the company business license and registrant ID. While this has reduced the frequency of .cn domains in spam, it does not seem to have affected the growth of the domain. Netcraft has discovered 49k new hostnames in .cn this month, compared to 37k in December, 59k in November and 39k in October.
August 1995 - February 2010
August 1995 - February 2010
| Developer | January 2010 | Percent | February 2010 | Percent | Change |
|---|---|---|---|---|---|
| Apache | 111,307,941 | 53.84% | 112,903,926 | 54.46% | 0.62 |
| Microsoft | 49,792,844 | 24.08% | 50,928,226 | 24.57% | 0.48 |
| 14,550,011 | 7.04% | 14,315,464 | 6.91% | -0.13 | |
| nginx | 15,568,224 | 7.53% | 13,978,719 | 6.74% | -0.79 |
| lighttpd | 955,146 | 0.46% | 1,097,685 | 0.53% | 0.07 |
| Rank | Company site | OS | Outage hh:mm:ss |
Failed Req% |
DNS | Connect | First byte |
Total |
|---|---|---|---|---|---|---|---|---|
| 1 | www.theplanet.com | Windows Server 2003 | 0:00:00 | 0.005 | 0.687 | 0.074 | 0.218 | 0.602 |
| 2 | Hosting 4 Less | Linux | 0:00:00 | 0.005 | 0.130 | 0.090 | 0.189 | 0.498 |
| 3 | www.navisite.com | Linux | 0:00:00 | 0.010 | 0.773 | 0.034 | 0.528 | 0.631 |
| 4 | DataPipe | unknown | 0:00:00 | 0.010 | 0.294 | 0.036 | 0.053 | 0.070 |
| 5 | INetU | unknown | 0:00:00 | 0.014 | 0.233 | 0.036 | 0.089 | 0.135 |
| 6 | Pair Networks | FreeBSD | 0:00:00 | 0.014 | 0.278 | 0.045 | 0.093 | 0.223 |
| 7 | New York Internet | FreeBSD | 0:00:00 | 0.019 | 0.069 | 0.032 | 0.070 | 0.186 |
| 8 | Swishmail | FreeBSD | 0:00:00 | 0.024 | 0.558 | 0.033 | 0.068 | 0.173 |
| 9 | www.memset.com | Linux | 0:00:00 | 0.024 | 0.658 | 0.081 | 0.164 | 0.164 |
| 10 | Verio | Linux | 0:00:00 | 0.024 | 0.186 | 0.098 | 0.196 | 0.196 |
The first month of 2010 saw The Planet and Hosting 4 Less have the most reliable hosting company sites. Both sites responded to all but one of Netcraft's requests in January.
The Planet provides dedicated servers, managed hosting and colocation services to more than 20,000 businesses. The company has more than 10 million websites in Netcraft's Hosting Provider Analysis and uses Windows Server 2003 to run its own website.
Hosting 4 Less offers a 99.9% uptime guarantee, with its own OC48 Sonet Ring connecting their secure data center to the internet. Hosting 4 Less has been running since 1998 and currently uses Apache on Linux to serve its own website.
Four of the most reliable hosting company sites in January were identified as running Linux, while three were using FreeBSD and one was using Windows Server 2003.
Netcraft measures and makes available the response times of fifty leading hosting providers' sites. The performance measurements are made at fifteen minute intervals from separate points around the internet, and averages are calculated over the immediately preceding 24 hour period.
From a customer's point of view, the percentage of failed requests is more pertinent than outages on hosting companies' own sites, as this gives a pointer to reliability of routing, and this is why we choose to rank our table by fewest failed requests, rather than shortest periods of outage.
Further information on the measurement process and current measurements are available.
In the January 2010 survey we received responses from 206,741,990 sites.
The biggest change this month is that 30M hostnames at qq.com expired from the survey. Last year all qq.com blogs were made public, leading to a large number of hostnames being added to the survey in February 2009. However, in the last 6 months qq.com have from time to time made all blogs private again, and have also stopped reporting blog activity to well known syndication points, so Netcraft can no longer tell how many accounts are active.
The market share for all the other major web servers has increased. Apache gained approximately 3M hostnames compared to the December 2009 survey, bringing their total to 111.3M. In second place comes Microsoft with a 600k increase. nginx lost hostnames this month but grew substantially in active sites, gaining 2.7M.
| Developer | December 2009 | Percent | January 2010 | Percent | Change |
|---|---|---|---|---|---|
| Apache | 108,953,838 | 46.59% | 111,307,941 | 53.84% | 7.25 |
| Microsoft | 49,184,244 | 21.03% | 49,792,844 | 24.08% | 3.05 |
| nginx | 16,249,950 | 6.95% | 15,568,224 | 7.53% | 0.58 |
| 14,110,280 | 6.03% | 14,550,011 | 7.04% | 1.00 | |
| lighttpd | 840,654 | 0.36% | 955,146 | 0.46% | 0.10 |
Advertisers Directory
| Rackspace Managed Hosting - Web Hosting - Hosting | Swishmail.com Business Email Hosting | Compare the Best Web Hosting Companies |
| INetU Managed Hosting - Dedicated Servers | Windows Dedicated Servers from Server Intellect | Reseller hosting Managed dedicated server Ahosting |
| Business Web Hosting Services - webhosting.uk.com | Web Hosting - Dedicated Servers & VPS Hosting | Managed Hosting - PCI Compliance by NeoSpire |
| SEO: Free SEO Analysis From SEO Consult | Search Engine Optimization : Results Based SEO |
Digg
Slashdot
Reddit
StumbleUpon
Delicious
Technorati