Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-02-2011, 07:07 PM
Jeff Liebermann
Guest
 
Posts: n/a
Default Re: Hotspot Security, How safe is SSL?

On Sun, 2 Oct 2011 18:50:13 +0000 (UTC), Justaguy
<Justaguy@Use-Author-Supplied-Address.invalid> wrote:

>Can a hotspot be set up as a honey pot that can infiltrate
>computers despite users using SSL for critical data
>transfers?


No. They would need to have successfully forged the SSL certificate
of the destination server. That's not going to happen unless the user
elects to ignore certificate errors.

There is a risk with badly designed web pages. It is possible to view
a mix of encrypted and unencrypted components of a web page. You'll
see an error message something like "You have requested an encrypted
page that contains some unencrypted information. Information that you
see or enter on this page could easily be read by a third party." The
way around this is to force ALL such traffic to be SSL encrypted.
<https://addons.mozilla.org/en-US/firefox/addon/force-tls/>

>Seems to me a hotspot could inject viruses, trojans or worms
>though a man in the middle attack, take control of your
>computer and fork SSL connections through their computers?


SSL is one way. There's no way anything can be "injected" backwards
into your computah.

>Unless ALL of your traffic is encrypted I think there is a
>big risk using hotspots or am I wrong?


With SSL, all the traffic is encrypted.
<http://www.verisign.com/ssl/ssl-information-center/how-ssl-security-works/>

--
Jeff Liebermann jeffl@cruzio.com
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558

Reply With Quote
  #2 (permalink)  
Old 10-02-2011, 07:29 PM
alexd
Guest
 
Posts: n/a
Default Re: Hotspot Security, How safe is SSL?

Jeff Liebermann (for it is he) wrote:

> On Sun, 2 Oct 2011 18:50:13 +0000 (UTC), Justaguy
> <Justaguy@Use-Author-Supplied-Address.invalid> wrote:
>
>>Can a hotspot be set up as a honey pot that can infiltrate
>>computers despite users using SSL for critical data
>>transfers?

>
> No. They would need to have successfully forged the SSL certificate
> of the destination server. That's not going to happen unless the user
> elects to ignore certificate errors.


Well there are other ways that an attacker can end up with forged
certificates - just ask Comodo and DigiNotar.

http://arstechnica.com/security/news...cker-i-hacked-
diginotar-too-other-cas-breached.ars

Just have a look at how many Certificate Authorities you "trust" in your
browser. How many of those authorities that you supposedly trust have you
even heard of?

> SSL is one way. There's no way anything can be "injected" backwards
> into your computah.


Hey they're working on it:

https://threatpost.com/en_us/blogs/n...tiality-model-
ssl-allows-theft-encrypted-cookies-091911


--
<http://ale.cx/> (AIM:troffasky) (UnSoEsNpEaTm@ale.cx)
20:18:22 up 16 days, 1:31, 6 users, load average: 0.01, 0.03, 0.08
"People believe any quote they read on the internet
if it fits their preconceived notions." - Martin Luther King


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
USENIX Security '09 Call For Papers Deadline Approaching Lionel Garth Jones comp.security.misc 0 01-20-2009 11:44 PM
CFP: The 2009 International Conference on Security and Management(SAM'09), USA, July 13-16, 2009 A. M. G. Solo comp.security.misc 0 01-04-2009 08:28 AM
Issue 18 of The ISO 27000 Newsletter Released Sue Thomas alt.computer.security 0 05-15-2008 06:59 PM
Security Vulnerability in ... Security Alert comp.security.misc 0 01-26-2007 10:40 AM
Call for Papers for the 16th USENIX Security Symposium Lionel Garth Jones comp.security.misc 0 10-02-2006 09:01 PM


All times are GMT. The time now is 02:02 PM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45