This account is pending registration confirmation. Please click on the link within the confirmation email previously sent you to complete registration.
Need a new registration confirmation email? Click here
Stocks Under $10 with 50-100% upside potential - 14 days FREE!

The Digital Skeptic: Amateurs Are Taking Over, and Risking, Web Security

SAN FRANCISCO(TheStreet) -- Ben Wilson tries hard not to show it. But he's worried. Really worried.

"If somebody gets a hold of one these things, it's not just one site that gets taken out," said Wilson, the senior vice president and general counsel for DigiCert, a Lindon, Utah, Internet security firm, over a hip hotel burger lunch.

"It's, you know, hundreds. Thousands of sites. Heck, maybe more," Wilson said.

The "thing" Wilson is sweating is called a certificate authority -- or CA in geek speak. That's the hidden, but critical, Web security organ that enables parts of secure Web transactions when say, shopping at Amazon (AMZN) or giving your tax ID to IRS.gov or buying and selling stock online at E*Trade (ETFC).

"The volume CAs handle can be a major fraction of total Web traffic," said David Rockvam, senior vice president for certificate services at Entrust, a Dallas security firm. Entrust and DigiCert are among a half-dozen certificate authorities that control about 90% of the certificate authority market.

"Keeping them secure is critical," Rockvam said.

Wilson and Rockvam had invited me away from the crazy-busy RSA Conference, the computer security nerd Lollapalooza hosted by the security division of drive-maker EMC (EMC). Here in the relative quiet, the two gave me the lowdown on the new dangers for CAs, away from the hordes gawking at big, sexy security companies such as VeriSign (VRSN), ZixCorp, Symantec (SYMC), StrikeForce Technologies (SFOR) and dozens of well-funded start-ups.

What makes Wilson and Rockvam so jittery is how -- not unlike publishing, movies and financial services -- the barriers to entry to becoming a CA, albeit a small one, have dropped to the point where Wilson estimates there are 60 to several hundred active certificate authorities.

"And if you are your own CA, you can do whatever you want," Rockvam explained. "Until you are discovered."

That makes CAs awfully attractive targets.

Just last month, a Turkish CA called TurkTrust began issuing insecure digital security certificates to the point where major traffic hubs Google (GOOG), Microsoft (MSFT) and Mozilla refused to honor its Web transactions. The company publicly said its bogus certificates were a simple mistake. But it is far from the only example of a crumbling CA security infrastructure.

1 of 2

Select the service that is right for you!

COMPARE ALL SERVICES
Action Alerts PLUS
Try it NOW

Jim Cramer and Stephanie Link actively manage a real portfolio and reveal their money management tactics while giving advanced notice before every trade.

Product Features:
  • $2.5+ million portfolio
  • Large-cap and dividend focus
  • Intraday trade alerts from Cramer
  • Weekly roundups
TheStreet Quant Ratings
Try it NOW
Only $49.95/yr

Access the tool that DOMINATES the Russell 2000 and the S&P 500.

Product Features:
  • Buy, hold, or sell recommendations for over 4,300 stocks
  • Unlimited research reports on your favorite stocks
  • A custom stock screener
  • Upgrade/downgrade alerts
Stocks Under $10
Try it NOW

David Peltier, uncovers low dollar stocks with extraordinary upside potential that are flying under Wall Street's radar.

Product Features:
  • Model portfolio
  • Stocks trading below $10
  • Intraday trade alerts
  • Weekly roundups
Dividend Stock Advisor
Try it NOW

Jim Cramer's protege, David Peltier, identifies the best of breed dividend stocks that will pay a reliable AND significant income stream.

Product Features:
  • Diversified model portfolio of dividend stocks
  • Alerts when market news affect the portfolio
  • Bi-weekly updates with exact steps to take - BUY, HOLD, SELL
Real Money Pro
Try it NOW

All of Real Money, plus 15 more of Wall Street's sharpest minds delivering actionable trading ideas, a comprehensive look at the market, and fundamental and technical analysis.

Product Features:
  • Real Money + Doug Kass Plus 15 more Wall Street Pros
  • Intraday commentary & news
  • Ultra-actionable trading ideas
Options Profits
Try it NOW

Our options trading pros provide daily market commentary and over 100 monthly option trading ideas and strategies to help you become a well-seasoned trader.

Product Features:
  • 100+ monthly options trading ideas
  • Actionable options commentary & news
  • Real-time trading community
  • Options TV
To begin commenting right away, you can log in below using your Disqus, Facebook, Twitter, OpenID or Yahoo login credentials. Alternatively, you can post a comment as a "guest" just by entering an email address. Your use of the commenting tool is subject to multiple terms of service/use and privacy policies - see here for more details.
Submit an article to us!
DOW 16,880.36 -31.75 -0.19%
S&P 500 1,970.07 +0.12 0.01%
NASDAQ 4,462.9020 +20.2040 0.45%

Brokerage Partners

Rates from Bankrate.com

  • Mortgage
  • Credit Cards
  • Auto

Free Newsletters from TheStreet

My Subscriptions:

After the Bell

Before the Bell

Booyah! Newsletter

Midday Bell

TheStreet Top 10 Stories

Winners & Losers

Register for Newsletters
Top Rated Stocks Top Rated Funds Top Rated ETFs