Enigform
Encyclopedia
Enigform is a Mozilla Firefox extension authored by Arturo 'Buanzo' Busleiman which uses GnuPG
GNU Privacy Guard
GNU Privacy Guard is a GPL Licensed alternative to the PGP suite of cryptographic software. GnuPG is compliant with RFC 4880, which is the current IETF standards track specification of OpenPGP...

 to implement OpenPGP-signed HTTP requests. OpenPGP encryption began to be implemented in 2007. Some people believe it to be an alternative for the Secure Sockets Layer
Transport Layer Security
Transport Layer Security and its predecessor, Secure Sockets Layer , are cryptographic protocols that provide communication security over the Internet...

 method for encrypting Hypertext Transfer Protocol
Hypertext Transfer Protocol
The Hypertext Transfer Protocol is a networking protocol for distributed, collaborative, hypermedia information systems. HTTP is the foundation of data communication for the World Wide Web....

 (or HTTP) connections. However, the author never had such an intention in his mind. Guaranteeing the identity of a requester and the integrity of the request is Enigform's primary goal, through the use of digital signature
Digital signature
A digital signature or digital signature scheme is a mathematical scheme for demonstrating the authenticity of a digital message or document. A valid digital signature gives a recipient reason to believe that the message was created by a known sender, and that it was not altered in transit...

s. In this instance, requests are form
Form (web)
A webform on a web page allows a user to enter data that is sent to a server for processing. Webforms resemble paper or database forms because internet users fill out the forms using checkboxes, radio buttons, or text fields...

 submissions to web servers. Apache HTTP Server
Apache HTTP Server
The Apache HTTP Server, commonly referred to as Apache , is web server software notable for playing a key role in the initial growth of the World Wide Web. In 2009 it became the first web server software to surpass the 100 million website milestone...

 support via the mod openpgp module currently supports request verification.

The project got its initial funding from OWASP
OWASP
The Open Web Application Security Project is an open-source application security project. The OWASP community includes corporations, educational organizations, and individuals from around the world. This community works to create freely-available articles, methodologies, documentation, tools, and...

 in 2007. A secure instant messaging system based on Enigform and HTTPS has been announced during the OWASP Ibero-American Web-Application Security Conference was announced in 2010.

Vinton Cerf
Vint Cerf
Vinton Gray "Vint" Cerf is an American computer scientist, who is recognized as one of "the fathers of the Internet", sharing this title with American computer scientist Bob Kahn...

has said that Enigform and mod_openpgp "[this] strikes me as a really interesting idea and I hope you (Buanzo) will pursue it with the W3C" (February 18, 2008).

Enigform was granted the Trusted status on the Mozilla Add-ons website in 2008.

On March 9, 2009, Buanzo committed to the mod_openpgp Subversion repository a Wordpress plugin (wp-enigform-authentication) that enables Enigform-based login to a Wordpress blog admin/user interface.

On April 23, 2009, Enigform was declared a Finalist in the Security category of Les Trophees du Libre, and was awarded the second prize.

Currently, the author has not received the prize money from the Les Trophees du Libre parent company, Cetril, and it seems that the company has vanished.

External links

The source of this article is wikipedia, the free encyclopedia.  The text of this article is licensed under the GFDL.
 
x
OK