Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048...

8
Web Service Self-Assessment Tools Robert Riemann IT Policy Hands-On Exercise DPO Day 12 December 2018

Transcript of Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048...

Page 1: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Web Service

Self-Assessment

Tools

Robert RiemannIT Policy

Hands-On ExerciseDPO Day

12 December 2018

Page 2: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Don’t wait until a future

wave catches you!

Page 3: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation
Page 4: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Browser Developer Toolbar

• easily available: integrated in all modern browsers

• press in browser:Ctrl+Shift+I

• displays browser storage (cookies) and all data traffic in real-time

• Firefox: https://developer.mozilla.org/en-US/docs/Tools

• Chrome: https://developers.google.com/web/tools/chrome-devtools/

Page 5: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Online Service webbkoll

• service gathers evidence, e.g.cookies, HTTPS

• provides privacy assessment

• assessment is automated and not EUI specific

https://webbkoll.dataskydd.net/en

Page 6: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Online Service PrivacyScore

• inspired by webbkoll

• evidence and assessment

• curated lists with assessment of EU institutions

• assessment is automated and not EUI specific

https://privacyscore.org

Page 7: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Browser-Plugin Ghostery

• plug-in to block and report on tracking and advertising of web services

• for all browsers• easy to use

https://www.ghostery.com/

Page 8: Web Service Self-Assessment Tools site works only in browsers with SNI support. Certificate RSA 2048 bits (SHA256withRSA) Server Key and Certificate #1 Title PowerPoint Presentation

Online Service Qualys SSL Labs

• online service to assess HTTPS configuration

• tests for known vulnerabilities

• easy to use• traffic light

feedback

https://www.ssllabs.com/ssltest/

Alternative open source software: https://testssl.sh/