{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:16:00Z","timestamp":1783098960439,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":23,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,10,16]],"date-time":"2012-10-16T00:00:00Z","timestamp":1350345600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,10,16]]},"DOI":"10.1145\/2382196.2382204","type":"proceedings-article","created":{"date-parts":[[2012,10,15]],"date-time":"2012-10-15T17:13:12Z","timestamp":1350321192000},"page":"38-49","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":301,"title":["The most dangerous code in the world"],"prefix":"10.1145","author":[{"given":"Martin","family":"Georgiev","sequence":"first","affiliation":[{"name":"The University of Texas at Austin, Austin, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Subodh","family":"Iyengar","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Suman","family":"Jana","sequence":"additional","affiliation":[{"name":"The University of Texas at Austin, Austin, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rishita","family":"Anubhai","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dan","family":"Boneh","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vitaly","family":"Shmatikov","sequence":"additional","affiliation":[{"name":"The University of Texas at Austin, Austin, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"https should check CN of x509 cert. https:\/\/issues.apache.org\/jira\/browse\/HTTPCLIENT-613.  https should check CN of x509 cert. https:\/\/issues.apache.org\/jira\/browse\/HTTPCLIENT-613."},{"key":"e_1_3_2_1_2_1","volume-title":"USENIX Security","author":"Brumley D.","year":"2003","unstructured":"D. Brumley and D. Boneh . Remote timing attacks are practical . In USENIX Security , 2003 . D. Brumley and D. Boneh. Remote timing attacks are practical. In USENIX Security, 2003."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.12"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.20"},{"key":"e_1_3_2_1_5_1","volume-title":"http:\/\/www.comodo.com\/Comodo-Fraud-Incident-2011-03-23.html","author":"Comodo","year":"2011","unstructured":"Comodo report of incident. http:\/\/www.comodo.com\/Comodo-Fraud-Incident-2011-03-23.html , 2011 . Comodo report of incident. http:\/\/www.comodo.com\/Comodo-Fraud-Incident-2011-03-23.html, 2011."},{"key":"e_1_3_2_1_6_1","volume-title":"http:\/\/www.theinquirer.net\/inquirer\/news\/2105321\/ diginotar-issues-dodgy-ssl-certificates-google-services-break","author":"Diginotar","year":"2011","unstructured":"Diginotar issues dodgy SSL certificates for Google services after break-in. http:\/\/www.theinquirer.net\/inquirer\/news\/2105321\/ diginotar-issues-dodgy-ssl-certificates-google-services-break , 2011 . Diginotar issues dodgy SSL certificates for Google services after break-in. http:\/\/www.theinquirer.net\/inquirer\/news\/2105321\/ diginotar-issues-dodgy-ssl-certificates-google-services-break, 2011."},{"key":"e_1_3_2_1_7_1","volume-title":"DEFCON","author":"Eckersley P.","year":"2010","unstructured":"P. Eckersley and J. Burns . An observatory for the SSLiverse . In DEFCON , 2010 . P. Eckersley and J. Burns. An observatory for the SSLiverse. In DEFCON, 2010."},{"key":"e_1_3_2_1_8_1","unstructured":"C. Evans and C. Palmer. Certificate pinning extension for HSTS. http:\/\/www.ietf.org\/mail-archive\/web\/websec\/current\/pdfnSTRd9kYcY.pdf 2011.  C. Evans and C. Palmer. Certificate pinning extension for HSTS. http:\/\/www.ietf.org\/mail-archive\/web\/websec\/current\/pdfnSTRd9kYcY.pdf 2011."},{"key":"e_1_3_2_1_9_1","unstructured":"Fiddler - Web debugging proxy. http:\/\/fiddler2.com\/fiddler2\/.  Fiddler - Web debugging proxy. http:\/\/fiddler2.com\/fiddler2\/."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14577-3_22"},{"key":"e_1_3_2_1_11_1","unstructured":"Moxie Marlinspike. IE SSL vulnerability. http:\/\/www.thoughtcrime.org\/ie-ssl-chain.txt 2002.  Moxie Marlinspike. IE SSL vulnerability. http:\/\/www.thoughtcrime.org\/ie-ssl-chain.txt 2002."},{"key":"e_1_3_2_1_12_1","unstructured":"Moxie Marlinspike. Null prefix attacks against SSL\/TLS certificates. http:\/\/www.thoughtcrime.org\/papers\/null-prefix-attacks.pdf 2009.  Moxie Marlinspike. Null prefix attacks against SSL\/TLS certificates. http:\/\/www.thoughtcrime.org\/papers\/null-prefix-attacks.pdf 2009."},{"key":"e_1_3_2_1_13_1","volume-title":"http:\/\/www.ietf.org\/rfc\/rfc2527.txt","author":"Internet","year":"1999","unstructured":"Internet X.509 public key infrastructure certificate policy and certification practices framework. http:\/\/www.ietf.org\/rfc\/rfc2527.txt , 1999 . Internet X.509 public key infrastructure certificate policy and certification practices framework. http:\/\/www.ietf.org\/rfc\/rfc2527.txt, 1999."},{"key":"e_1_3_2_1_14_1","volume-title":"http:\/\/www.ietf.org\/rfc\/rfc2818.txt","author":"HTTP","year":"2000","unstructured":"HTTP over TLS. http:\/\/www.ietf.org\/rfc\/rfc2818.txt , 2000 . HTTP over TLS. http:\/\/www.ietf.org\/rfc\/rfc2818.txt, 2000."},{"key":"e_1_3_2_1_15_1","volume-title":"http:\/\/tools.ietf.org\/html\/rfc5280","author":"Internet","year":"2008","unstructured":"Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. http:\/\/tools.ietf.org\/html\/rfc5280 , 2008 . Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. http:\/\/tools.ietf.org\/html\/rfc5280, 2008."},{"key":"e_1_3_2_1_16_1","volume-title":"http:\/\/tools.ietf.org\/html\/rfc6101","author":"Sockets The Secure","year":"2011","unstructured":"The Secure Sockets Layer (SSL) protocol version 3.0. http:\/\/tools.ietf.org\/html\/rfc6101 , 2011 . The Secure Sockets Layer (SSL) protocol version 3.0. http:\/\/tools.ietf.org\/html\/rfc6101, 2011."},{"key":"e_1_3_2_1_17_1","volume-title":"http:\/\/tools.ietf.org\/html\/rfc6125","author":"Transport Layer Representation","year":"2011","unstructured":"Representation and verification of domain-based application service identity within Internet public key infrastructure using X.509 (PKIX) certificates in the context of Transport Layer Security (TLS). http:\/\/tools.ietf.org\/html\/rfc6125 , 2011 . Representation and verification of domain-based application service identity within Internet public key infrastructure using X.509 (PKIX) certificates in the context of Transport Layer Security (TLS). http:\/\/tools.ietf.org\/html\/rfc6125, 2011."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_4"},{"key":"e_1_3_2_1_19_1","volume-title":"S&P","author":"Sun Q.","year":"2002","unstructured":"Q. Sun , D. Simon , Y.-M. Wang , W. Russell , V. Padmanabhan , and L. Qiu . Statistical identification of encrypted Web browsing traffic . In S&P , 2002 . Q. Sun, D. Simon, Y.-M. Wang, W. Russell, V. Padmanabhan, and L. Qiu. Statistical identification of encrypted Web browsing traffic. In S&P, 2002."},{"key":"e_1_3_2_1_20_1","volume-title":"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-4831","year":"2009","unstructured":"CVE-2009-4831. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-4831 , 2009 . CVE-2009-4831. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-4831, 2009."},{"key":"e_1_3_2_1_21_1","volume-title":"Secure Programming Cookbook for C and C++","author":"Viega J.","year":"2007","unstructured":"J. Viega and M. Messier . Secure Programming Cookbook for C and C++ . O'Reilly Media , 2007 . J. Viega and M. Messier. Secure Programming Cookbook for C and C++. O'Reilly Media, 2007."},{"key":"e_1_3_2_1_22_1","volume-title":"WEIS","author":"Vratonjic N.","year":"2011","unstructured":"N. Vratonjic , J. Freudiger , V. Bindschaedler , and J.-P. Hubaux . The inconvenient truth about Web certificates . In WEIS , 2011 . N. Vratonjic, J. Freudiger, V. Bindschaedler, and J.-P. Hubaux. The inconvenient truth about Web certificates. In WEIS, 2011."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.26"}],"event":{"name":"CCS'12: the ACM Conference on Computer and Communications Security","location":"Raleigh North Carolina USA","acronym":"CCS'12","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2012 ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382196.2382204","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2382196.2382204","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:34:42Z","timestamp":1750239282000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382196.2382204"}},"subtitle":["validating SSL certificates in non-browser software"],"short-title":[],"issued":{"date-parts":[[2012,10,16]]},"references-count":23,"alternative-id":["10.1145\/2382196.2382204","10.1145\/2382196"],"URL":"https:\/\/doi.org\/10.1145\/2382196.2382204","relation":{},"subject":[],"published":{"date-parts":[[2012,10,16]]},"assertion":[{"value":"2012-10-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}