Online Trust Audit Finds Better Email Authentication and Encryption; Worse Privacy Statement Scores
Do you know how – or even if – your favorite retailer, or your bank, or your ISP is working to protect you? The Online Trust Alliance recognizes excellence in consumer protection, data security and responsible privacy practices. Today, we released the 10th annual Online Trust Audit & Honor Roll, covering more than 1,200 predominantly consumer-facing websites, and found that 70% of the websites we analyzed qualified for the Honor Roll. That’s the highest proportion ever, driven primarily by improvements in email authentication and session encryption.
Highlights
Overall, we found a strong move toward encryption, with 93% of sites encrypting all web sessions. Email authentication is also at record highs; 76% use both SPF and DKIM (which prevent spoofed/forged emails) and 50% have a DMARC record (which provides instruction on how to handle messages that fail authentication).
It’s not all good news, though. We also found that only 11% of organizations use mechanisms for vulnerability reporting, which allows users to report bugs and security problems. Only 6% use Certificate Authority Authorization, which limits certificate abuse. And overall privacy scores dropped compared to last year, primarily due to more stringent scoring in light of the E.U.’s General Continue reading
Japan's telecom regulator also imposed a condition that effectively bans Chinese vendors Huawei and...
The Wall Street Journal reported that the investigation included a raid on Ericsson’s offices in...
Google is saying we're OK with being your No. 2 choice — for now. While Amazon and Microsoft...
The products insecurely store authentication and/or session cookies, giving hackers access to a...



