Buying Options
Web Security, Privacy & Commerce, Second Edition
Print $44.95
Add to Cart
Safari Books Online
Add to Cart
What is this?
Print £34.50
Add to Cart
What is this?
Description
This much expanded new edition explores web security risks and how to minimize them. Aimed at web users, administrators, and content providers, Web Security, Privacy & Commerce covers cryptography, SSL, the Public Key Infrastructure, digital signatures, digital certificates, privacy threats (cookies, log files, web logs, web bugs), hostile mobile code, and web publishing (intellectual property, P3P, digital payments, client-side digital signatures, code signing, PICS).
Full Description
Table of Contents
  1. Web Technology

    1. Chapter 1 The Web Security Landscape

      1. The Web Security Problem
      2. Risk Analysis and Best Practices
    2. Chapter 2 The Architecture of the World Wide Web

      1. History and Terminology
      2. A Packet's Tour of the Web
      3. Who Owns the Internet?
    3. Chapter 3 Cryptography Basics

      1. Understanding Cryptography
      2. Symmetric Key Algorithms
      3. Public Key Algorithms
      4. Message Digest Functions
    4. Chapter 4 Cryptography and the Web

      1. Cryptography and Web Security
      2. Working Cryptographic Systems and Protocols
      3. What Cryptography Can't Do
      4. Legal Restrictions on Cryptography
    5. Chapter 5 Understanding SSL and TLS

      1. What Is SSL?
      2. SSL: The User's Point of View
    6. Chapter 6 Digital Identification I: Passwords, Biometrics, and Digital Signatures

      1. Physical Identification
      2. Using Public Keys for Identification
      3. Real-World Public Key Examples
    7. Chapter 7 Digital Identification II: Digital Certificates, CAs, and PKI

      1. Understanding Digital Certificates with PGP
      2. Certification Authorities: Third-Party Registrars
      3. Public Key Infrastructure
      4. Open Policy Issues
  2. Privacy and Security for Users

    1. Chapter 8 The Web's War on Your Privacy

      1. Understanding Privacy
      2. User-Provided Information
      3. Log Files
      4. Understanding Cookies
      5. Web Bugs
      6. Conclusion
    2. Chapter 9 Privacy-Protecting Techniques

      1. Choosing a Good Service Provider
      2. Picking a Great Password
      3. Cleaning Up After Yourself
      4. Avoiding Spam and Junk Email
      5. Identity Theft
    3. Chapter 10 Privacy-Protecting Technologies

      1. Blocking Ads and Crushing Cookies
      2. Anonymous Browsing
      3. Secure Email
    4. Chapter 11 Backups and Antitheft

      1. Using Backups to Protect Your Data
      2. Preventing Theft
    5. Chapter 12 Mobile Code I: Plug-Ins, ActiveX,and Visual Basic

      1. When Good Browsers Go Bad
      2. Helper Applications and Plug-ins
      3. Microsoft's ActiveX
      4. The Risks of Downloaded Code
      5. Conclusion
    6. Chapter 13 Mobile Code II: Java, JavaScript, Flash, and Shockwave

      1. Java
      2. JavaScript
      3. Flash and Shockwave
      4. Conclusion
  3. Web Server Security

    1. Chapter 14 Physical Security for Servers

      1. Planning for the Forgotten Threats
      2. Protecting Computer Hardware
      3. Protecting Your Data
      4. Personnel
      5. Story: A Failed Site Inspection
    2. Chapter 15 Host Security for Servers

      1. Current Host Security Problems
      2. Securing the Host Computer
      3. Minimizing Risk by Minimizing Services
      4. Operating Securely
      5. Secure Remote Access and Content Updating
      6. Firewalls and the Web
      7. Conclusion
    3. Chapter 16 Securing Web Applications

      1. A Legacy of Extensibility and Risk
      2. Rules to Code By
      3. Securely Using Fields, Hidden Fields, and Cookies
      4. Rules for Programming Languages
      5. Using PHP Securely
      6. Writing Scripts That Run with Additional Privileges
      7. Connecting to Databases
      8. Conclusion
    4. Chapter 17 Deploying SSL Server Certificates

      1. Planning for Your SSL Server
      2. Creating SSL Servers with FreeBSD
      3. Installing an SSL Certificate on Microsoft IIS
      4. Obtaining a Certificate from a Commercial CA
      5. When Things Go Wrong
    5. Chapter 18 Securing Your Web Service

      1. Protecting Via Redundancy
      2. Protecting Your DNS
      3. Protecting Your Domain Registration
    6. Chapter 19 Computer Crime

      1. Your Legal Options After a Break-In
      2. Criminal Hazards
      3. Criminal Subject Matter
  4. Security for Content Providers

    1. Chapter 20 Controlling Access to Your Web Content

      1. Access Control Strategies
      2. Controlling Access with Apache
      3. Controlling Access with Microsoft IIS
    2. Chapter 21 Client-Side Digital Certificates

      1. Client Certificates
      2. A Tour of the VeriSign Digital ID Center
    3. Chapter 22 Code Signing and Microsoft's Authenticode

      1. Why Code Signing?
      2. Microsoft's Authenticode Technology
      3. Obtaining a Software Publishing Certificate
      4. Other Code Signing Methods
    4. Chapter 23 Pornography, Filtering Software, and Censorship

      1. Pornography Filtering
      2. PICS
      3. RSACi
      4. Conclusion
    5. Chapter 24 Privacy Policies, Legislation, and P3P

      1. Policies That Protect Privacy and Privacy Policies
      2. Children's Online Privacy Protection Act
      3. P3P
      4. Conclusion
    6. Chapter 25 Digital Payments

      1. Charga-Plates, Diners Club, and Credit Cards
      2. Internet-Based Payment Systems
      3. How to Evaluate a Credit Card Payment System
    7. Chapter 26 Intellectual Property and Actionable Content

      1. Copyright
      2. Patents
      3. Trademarks
      4. Actionable Content
  5. Appendixes

    1. Appendix A Lessons from Vineyard.NET

      1. In the Beginning
      2. Planning and Preparation
      3. IP Connectivity
      4. Commercial Start-Up
      5. Ongoing Operations
      6. Redundancy and Wireless
      7. The Big Cash-Out
      8. Conclusion
    2. Appendix B The SSL/TLS Protocol

      1. History
      2. TLS Record Layer
      3. SSL/TLS Protocols
      4. SSL 3.0/TLS Handshake
    3. Appendix C P3P: The Platform for Privacy Preferences Project

      1. How P3P Works
      2. Deploying P3P
      3. Simple P3P-Enabled Web Site Example
    4. Appendix D The PICS Specification

      1. Rating Services
      2. PICS Labels
    5. Appendix E References

      1. Electronic References
      2. Paper References
  1. Colophon

View Full Table of Contents
Product Details
Title:
Web Security, Privacy & Commerce, Second Edition
By:
Simson Garfinkel, Gene Spafford
Publisher:
O'Reilly Media
Formats:
  • Print
  • Safari Books Online
Print Release:
November 2001
Pages:
786
Print ISBN:
978-0-596-00045-5
| ISBN 10:
0-596-00045-6
Customer Reviews
About the Authors
  1. Simson Garfinkel

    Simson Garfinkel, CISSP, is a journalist, entrepreneur, and international authority on computer security. Garfinkel is chief technology officer at Sandstorm Enterprises, a Boston-based firm that develops state-of-the-art computer security tools. Garfinkel is also a columnist for Technology Review Magazine and has written for more than 50 publications, including Computerworld, Forbes, and The New York Times. He is also the author of Database Nation; Web Security, Privacy, and Commerce; PGP: Pretty Good Privacy; and seven other books. Garfinkel earned a master's degree in journalism at Columbia University in 1988 and holds three undergraduate degrees from MIT. He is currently working on his doctorate at MIT's Laboratory for Computer Science.

    View Simson Garfinkel's full profile page.

  2. Gene Spafford

    Gene Spafford, Ph.D., CISSP, is an internationally renowned scientist and educator who has been working in information security, policy, cybercrime, and software engineering for nearly two decades. He is a professor at Purdue University and is the director of CERIAS, the world's premier multidisciplinary academic center for information security and assurance. Professor Spafford and his students have pioneered a number of technologies and concepts well-known in security today, including the COPS and Tripwire tools, two-stage firewalls, and vulnerability databases. Spaf, as he is widely known, has achieved numerous professional honors recognizing his teaching, his research, and his professional service. These include being named a fellow of the AAAS, the ACM, and the IEEE; receiving the National Computer Systems Security Award; receiving the William Hugh Murray Medal of the NCISSE; election to the ISSA Hall of Fame; and receiving the Charles Murphy Award at Purdue. He was named a CISSP, honoris causa in 2000. In addition to over 100 technical reports and articles on his research, Spaf is also the coauthor of Web Security, Privacy, and Commerce, and was the consulting editor for Computer Crime: A Crimefighters Handbook (both from O'Reilly).

    View Gene Spafford's full profile page.

Colophon

Our look is the result of reader comments, our own experimentation, and feedback from distribution channels. Distinctive covers complement our distinctive approach to technical topics, breathing personality and life into potentially dry subjects. The animal on the cover of Web Security, Privacy & Commerce, Second Edition is a whale shark. Sharks have lived on the Earth for over 300 million years, and populate all the oceans of the world (as well as some freshwater lakes and rivers). They are related to skates and rays, differing from ordinary bony fish in having a cartilaginous skeleton that makes their bodies unusually flexible. Unlike bony fish, sharks give birth to live young, in small litters.

A common misconception about sharks is that they need to keep swimming at all times. While they do need to move their fins constantly in order to stay afloat, many species of sharks like to rest on the bottom of the ocean floor.

Sharks make excellent predators because of their well-developed sensory system (not to mention their big, sharp teeth). They have excellent eyesight and an unusually keen sense of smell; they are known to be able to locate prey from a single drop of blood. Sharks can also sense electrical currents in the water indicating the presence of other fish. They retain several rows of teeth, which roll outward to replace those that are lost.

The whale shark, on the other hand, is a kinder, gentler shark. Whale sharks (Rhinocodon typus) have a large flat head, a wide mouth, and tiny teeth. As a filter feeder, they feed primarily on plankton and small fish. They have distinctive spotted markings on their fins and dorsal sides. Whale sharks are so named because of their size: they may weigh more than 18 metric tons and measure up to 60 feet long. They are the largest species of fish alive today.

Whale sharks live in tropical and temperate seas. They pose little or no risk to humans. In fact, whale sharks are considered a particular treat to divers, since they are impressive in size but are slow-moving and not aggressive. Colleen Gorman was the production editor and the copyeditor for Web Security, Privacy & Commerce, Second Edition. Melanie Wang and Sue Willing were the proofreaders. Matt Hutchinson provided quality control. Mary Brady, Phil Dangler, Maureen Dempsey, Derek Di Matteo, Catherine Morris, and Edie Shapiro provided production support. John Bickelhaupt wrote the index.

Edie Freedman designed the cover of this book. The cover image is a 19th-century engraving from the Dover Pictorial Archive. Emma Colby produced the cover layout with QuarkXPress 4.1 using Adobe's ITC Garamond font.

David Futato designed the interior layout. Neil Walls updated the files to FrameMaker 5.5.6 using tools created by Mike Sierra. The text font is Linotype Birka; the heading font is Adobe Myriad Condensed; and the code font is Lucas-Font's TheSans Mono Condensed. The illustrations that appear in the book were produced by Robert Romano and Jessamyn Read using Macromedia FreeHand 9 and Adobe Photoshop 6. The tip and warning icons were drawn by Christopher Bing. This colophon was written by Linda Mui.

Whenever possible, our books use a durable and flexible lay-flat binding. If the page count exceeds this binding's limit, perfect binding is used.

  • Book cover of Web Security, Privacy & Commerce