{"title":"Case Study: On the Security of Key Storage on PCs","authors":"R. Gallo, Henrique Kawakami, R. Dahab","doi":"10.1109/TrustCom.2013.203","DOIUrl":null,"url":null,"abstract":"In this work we review the security of the industry standard, software-based, cryptographic services providers Mozilla NSS Softoken and Microsoft CAPI CSPs. We also provide practical measurements of the user experienced security level. We found that this security level is much lower than expected and some service providers should be avoided.","PeriodicalId":206739,"journal":{"name":"2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications","volume":"7 4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TrustCom.2013.203","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
In this work we review the security of the industry standard, software-based, cryptographic services providers Mozilla NSS Softoken and Microsoft CAPI CSPs. We also provide practical measurements of the user experienced security level. We found that this security level is much lower than expected and some service providers should be avoided.