{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T11:00:26Z","timestamp":1743073226480,"version":"3.40.3"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319489643"},{"type":"electronic","value":"9783319489650"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-48965-0_12","type":"book-chapter","created":{"date-parts":[[2016,10,27]],"date-time":"2016-10-27T13:55:25Z","timestamp":1477576525000},"page":"192-207","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Implementation State of HSTS and HPKP in Both Browsers and Servers"],"prefix":"10.1007","author":[{"given":"Sergio","family":"de los Santos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carmen","family":"Torrano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yaiza","family":"Rubio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"F\u00e9lix","family":"Brezo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,28]]},"reference":[{"key":"12_CR1","unstructured":"Rizzo, J., Duong, T.: BEAST. Ekoparty (2011)"},{"key":"12_CR2","unstructured":"Mller, B., Duong, T., Kotowicz, K.: This POODLE bites: exploiting the SSL 3.0 fallback (2014). https:\/\/www.openssl.org\/~bodo\/ssl-poodle.pdf. REPASAR"},{"key":"12_CR3","unstructured":"Rizzo, J., Duong, T.: The CRIME Attack. Ekoparty (2012)"},{"key":"12_CR4","unstructured":"Codenomicon: The Heartbleed Bug. Ekoparty (2014)"},{"key":"12_CR5","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., Strub, P.: Triple handshakes and cookie cutters: breaking and fixing authentication over TLS. In: IEEE Symposium on Security and Privacy (2014)","DOI":"10.1109\/SP.2014.14"},{"key":"12_CR6","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1016\/j.cose.2015.07.004","volume":"55","author":"Y Jia","year":"2015","unstructured":"Jia, Y., Chen, Y., Dong, X., Saxena, P., Mao, J., Liang, Z.: Man-in-the-browser-cache: persisting HTTPS attacks via browser cache poisoning. Comput. Secur. 55, 62\u201380 (2015)","journal-title":"Comput. Secur."},{"key":"12_CR7","unstructured":"Marlinspike, M.: New Tricks for Defeating SSL in Practice. BlackHat (2009). http:\/\/www.thoughtcrime.org\/software\/sslstrip\/"},{"key":"12_CR8","unstructured":"Paul, I.: Firefox Add-on Firesheep Brings Hacking to the Masses. PCWorld (2010)"},{"key":"12_CR9","unstructured":"Mandalia, R.: Security Breach in CA Networks - Comodo, DigiNotar, GlobalSign. $$ISC^2$$ Blog (2012). http:\/\/blog.isc2.org\/isc2_blog\/2012\/04\/test.html"},{"key":"12_CR10","unstructured":"Langley, A.: Further improving digital certificate security. Google Security Blog (2013). https:\/\/security.googleblog.com\/2013\/12\/further-improving-digital-certificate.html"},{"key":"12_CR11","unstructured":"Langley, A.: Maintaining digital certificate security. Google Security Blog (2014). https:\/\/security.googleblog.com\/2014\/07\/maintaining-digital-certificate-security.html"},{"key":"12_CR12","unstructured":"Hoffman, P.: The DNS-Based Authentication of Named Entities (DANE). Transport Layer Security (TLS) Protocol: TLSA. https:\/\/www.rfc-editor.org\/rfc\/rfc6698.txt"},{"key":"12_CR13","unstructured":"Marlinspike, M., Perrin, T.: Tacks. http:\/\/tack.io\/draft.html"},{"key":"12_CR14","unstructured":"Loesch, C.: Certificate Patrol. https:\/\/addons.mozilla.org\/es\/firefox\/addon\/certificate-patrol\/"},{"key":"12_CR15","unstructured":"Wendlandt, D., Andersen, D., Perrig, A.: Perspectives: Improving SSH-style Host Authentication with Multi-Path Probing (2008). http:\/\/static.usenix.org\/event\/usenix08\/tech\/full_papers\/wendlandt\/wendlandt_html\/"},{"key":"12_CR16","unstructured":"Marlinspike, M.: Convergence (2011). http:\/\/convergence.io\/"},{"key":"12_CR17","unstructured":"Yan: Weird New Tricks for Browser Fingerprinting (2015). https:\/\/zyan.scripts.mit.edu\/presentations\/toorcon2015.pdf"},{"key":"12_CR18","unstructured":"Internet Engineering Task Force (IETF): HTTP Strict Transport Security (HSTS). RFC 6797(2012). https:\/\/tools.ietf.org\/html\/rfc6797"},{"key":"12_CR19","unstructured":"Internet Engineering Task Force (IETF): Public Key Pinning Extension for HTTP. RFC 7469(2015). https:\/\/tools.ietf.org\/html\/rfc7469"},{"key":"12_CR20","unstructured":"Internet Engineering Task Force (IETF): Certificate Transparency (2013). https:\/\/tools.ietf.org\/html\/rfc6962"},{"key":"12_CR21","unstructured":"Garron, L., Bortz, A., Boneh, D.: The State of HSTS Deployment: A Survey and Common Pitfalls (2014)"},{"key":"12_CR22","doi-asserted-by":"crossref","unstructured":"Kranch, M., Bonneau, J.: Upgrading HTTPS in mid-air: an empirical study of strict transport security and key pinning. In: Network and Distributed System Security Symposium (NDSS) (2015)","DOI":"10.14722\/ndss.2015.23162"},{"key":"12_CR23","unstructured":"Selvi, J.: Bypassing HTTP Strict Transport Security. BlackHat Europe (2014)"},{"key":"12_CR24","unstructured":"IETF: IETF. https:\/\/www.ietf.org\/"},{"key":"12_CR25","unstructured":"Shodan: Shodan. http:\/\/www.shodan.io"},{"key":"12_CR26","unstructured":"Alexa internet Inc: Alexa. http:\/\/www.alexa.com\/"},{"key":"12_CR27","unstructured":"Deveria, A.: Can I use Strict Transport Security? (2016). http:\/\/caniuse.com\/#feat=stricttransportsecurity"},{"key":"12_CR28","unstructured":"Monica: Firefox 32 supports Public Key Pinning (2014). http:\/\/monica-at-mozilla.blogspot.de\/2014\/08\/firefox-32-supports-public-key-pinning.html"},{"key":"12_CR29","unstructured":"Bugzilla: Bugzilla@Mozilla (2014). https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=775370"},{"key":"12_CR30","unstructured":"Mozilla: Mozilla Code (2014). https:\/\/dxr.mozilla.org\/comm-central\/source\/mozilla\/security\/manager\/ssl\/nsSiteSecurityService.h"},{"key":"12_CR31","unstructured":"ElevenPaths: PinPatro. https:\/\/addons.mozilla.org\/es\/firefox\/addon\/pinpatrol\/"},{"key":"12_CR32","unstructured":"Deveria, A.: Can I Use Public Key Pinning (2015). http:\/\/caniuse.com\/#feat=publickeypinning"},{"key":"12_CR33","unstructured":"Deveria, A.: Can I use HSTS? (2015). http:\/\/caniuse.com\/#search=HSTS"},{"key":"12_CR34","unstructured":"Nishimura, M.: Appended period to hostnames can bypass HPKP and HSTS protections. https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2015-13\/"}],"container-title":["Lecture Notes in Computer Science","Cryptology and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-48965-0_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T15:19:48Z","timestamp":1710170388000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-48965-0_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319489643","9783319489650"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-48965-0_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"28 October 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CANS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 November 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 November 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cans2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/cans2016.di.unimi.it\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}