Secure shopping

The Review began by asking Dr Elgamal how the web has changed in terms of eCommerce transactions, compared to when he was doing his pioneering work with SSL.

At the beginning of the eCommerce industry in the mid-90s, we realized that the highest risk lay in the open nature of the Internet,” he says.

“SSL was designed and implemented by the Netscape team [that he was part of], alongside several industry experts, to prevent unauthorized access to communications on the net.

SSL was not in fact designed to solve all security issues, but focused on the communication aspect. In essence, eCommerce would be probably a very different industry if we were starting now.

There is no reason to change the thinking about how SSL is designed, even today,” he continues. “But, knowing what we know today, we would have implemented SSL as a step towards achieving secure electronic transactions, rather than believing that SSL is the only measure to use.”
 

<< Back to: Overview    Next: In the clouds >>