ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Baltimore's death spells gloom for PKI

Matt Loney ZDNet.co.uk

Published: 28 Nov 2003 13:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The meeting of Baltimore Technologies' shareholders on Friday signals more than just the demise of a European software powerhouse, with a valuation at the height of the dot-com boom of £7bn, to a shell whose only assets are £25m in cash. It also embodies the general failure of PKI technology to match the hype that it generated over the past few years, say analysts.

At the extraordinary general meeting in Dublin, shareholders are expected to approve the sale of Baltimore's Public Key Infrastructure (PKI) technology to US-based beTrusted, the company formed by PricewaterhouseCoopers. The meeting is seen by many as merely a formality to dispose of Blatimore's one remaining software asset, in the shape of its core security software business: the UniCert PKI software.

Baltimore may have made many mistakes over the past years, but it has also been a victim of the almost complete failure of PKI technology to take off. A public key infrastructure is a framework that provides security services to an organisation using public-key cryptography. These services are managed using certificates which are issued from a central certificate authority.

"The promise of PKI hasn't happened," said Ovum principal analyst Graham Titterington. "And I don't think it will. It is expensive and costly to implement. Businesses have felt it is just not worth the expense. The whole thing turned out to be pie in the sky -- that's why Baltimore collapsed and why others have had lean times. Entrust, Verisign and RSA have had tough times too, but they had greater revenues and other revenue streams so they have survived and Baltimore hasn't because it failed to diversify."

Part of the problem with PKI in a public environment, said Titterington, is one of trust. "Who do you trust to issue the certificates? Even if the organisation issuing the certificates is trusted, what process have they been through before issuing each one? How do you know how much diligence they have been through?"

In March 2001, VeriSign, which acts as a certificate authority, issued two digital certificates to an individual who fraudulently claimed to be a Microsoft employee. The mistake led Microsoft to release a software update for all Windows releases dating back to 1995.

"It is conceivable that government-issued certificates could still happen," said Titterington, "but the jury is still out on that." Indeed, Spain and Belgium have taken a lead in this area, with the governments there issuing digital certificates to citizens, but even governments face the problem of making sure that when they authenticate a person, they know with absolute certainty that that person is who they say they are.

"You have to go to great lengths to verify who is applying for a certificate," said Titterington. "Also, if anyone can issue forged certificate in any way then the whole operation becomes debased. If 1 percent of certificates were forgeries and 99 percent genuine, the trust of that 99 percent of certificates would drop through the floor."

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
129 out of 236 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Business Analyst Cash Equities Tier 1 Investment Bank London

Business Analyst Cash Equities Tier 1 Investment Bank London. One of Orgtel's leading clients a niche investment bank currently require a highly ...

Business Analyst Cash Equities Trading Operations London City

Working with the Equities business and at board level a Business Analyst is required to join the Cash Equity team and own components of the You will ...

RF / DSP Failure Analysis Engineer - Tewkesbury - URGENT !!! SC ?

Purpose of this Position Failure Analysis of Product to System, unit and component level in order to implement both corrective and preventative ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec