2000 character limit reached
Secure by default - the case of TLS (1708.07569v1)
Published 24 Aug 2017 in cs.CR
Abstract: Default configuration of various software applications often neglects security objectives. We tested the default configuration of TLS in dozen web and application servers. The results show that "secure by default" principle should be adopted more broadly by developers and package maintainers. In addition, system administrators cannot rely blindly on default security options.