Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-27-2007, 09:24 PM
Joan Battaglia
Guest
 
Posts: n/a
Default Re: How safe is Tor for logging into http (nont https) web sites

On Fri, 26 Oct 2007 03:35:03 -0500, VanguardLH wrote:

> you have to trust the proxy doesn't intercept your SSL
> request and won't pretend to be the target site.


I routinely accept those "certificate" things.
Even when I "view" them, I don't know what I'm viewing.
Is there something to look for to ensure it's the mail site's certificate
and not the rogue Tor's certificate?

WHat would I look for as a clue that the certificate is bad?





>> When I log into an https email web page, I assume my password is
>> protected from snoopers on the Tor network itself.
>> But - what about if I have to log into a web page that does
>> not have an https encrypted login method? Is Tor now compromised?
>> Am I now sending my password in the clear to a Tor server
>> Is my password still secure when logging into an http account with
>> Tor/Privoxy running?

>
> Since you are now using a proxy, and because the proxy can pretend to
> be the target site, and because the proxy could establish the SSL
> connect with you and then an SSL connect to the target site (so both
> use SSL but not directly to each other), now you have to trust the
> proxy doesn't intercept your SSL request and won't pretend to be the
> target site. Do you really trust Tor with you bank login? Do you
> know what Tor proxy you are using and who operates it? Anything
> between you and the target site can be an interceptor SSL proxy but
> there's less chance it will be your ISP or the backbone that they use.
> With Tor, well, who knows who is running each of its peer hosts. The
> Tor servers are ran by volunteers, not by your ISP or your bank. As I
> recall, a bluecoat proxy can do SSL interception.
>
> http://arstechnica.com/news.ars/post...passwords.html
>
> It suggests using encryption (SSL); however, that still doesn't
> prevent the Tor server user from intercepting. You get anonymity, not
> necessarily security, with P2P networks. However, even if there were
> no such interception, using SSL means the target knows the source.
> With P2P, there are more unknown hosts you pass through, more chances
> for man-in-the-middle attacks.
>
> http://xiandos.info/Tor


Reply With Quote
  #2 (permalink)  
Old 10-28-2007, 06:07 PM
Ari
Guest
 
Posts: n/a
Default Re: How safe is Tor for logging into http (nont https) web sites

On Sat, 27 Oct 2007 14:24:17 -0700, Joan Battaglia wrote:

> I routinely accept those "certificate" things.
> Even when I "view" them, I don't know what I'm viewing.
> Is there something to look for to ensure it's the mail site's certificate
> and not the rogue Tor's certificate?
>
> WHat would I look for as a clue that the certificate is bad?


Anyone else care to explain how relaible Tor, HTTPS or any other
protocols, routing procedures or other such "security" and "anonymity"
is in *real world sitchs*?

Joan, Honey,

www.cotse.com

Turn it over to Stephen and the Cotse crew.
--
"You can't trust code that you did not totally create yourself"
Ken Thompson "Reflections on Trusting Trust"
http://www.acm.org/classics/sep95/

Reply With Quote
  #3 (permalink)  
Old 10-28-2007, 10:03 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How safe is Tor for logging into http (nont https) web sites

Ari wrote:

> On Sat, 27 Oct 2007 14:24:17 -0700, Joan Battaglia wrote:
>
>> I routinely accept those "certificate" things.
>> Even when I "view" them, I don't know what I'm viewing.
>> Is there something to look for to ensure it's the mail site's certificate
>> and not the rogue Tor's certificate?
>>
>> WHat would I look for as a clue that the certificate is bad?

>
> Anyone else care to explain how relaible Tor, HTTPS or any other
> protocols, routing procedures or other such "security" and "anonymity"
> is in *real world sitchs*?



Typically it's a PEBKAC problem. If the software asks you "Are you sure?"
and you're simply not sure, then be honest and click "No.". Might be that
the intended process stop working then, but don't use it an excuse to pres
"Yes" next time.

At any rate, a research team of Berkeley found that phishing attacks works
so well and defense against works so bad because most people aren't even
reading the URLs. Yes, exactly, they have no clue where they're browsing,
blinding assuming that website designs couldn't be copied and thus
identifying websites by design. It's purely a PEBKAC problem, since the
users decided to ignore the minimum required knowledge, fully accepting the
possibility that they would be unable to make judged decisions.

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: How safe is Tor for logging into http (nont https) web sites Joan Battaglia comp.security.misc 46 11-02-2007 05:57 PM
Re: How safe is Tor for logging into http (nont https) web sites Joan Battaglia comp.security.misc 0 10-26-2007 12:57 PM
Sex Story,Free Erotic Sex Letter Stories From Anal Bitch Porn List Dildos Hot sex udshfu7fw37ifue@yahoo.com alt.cellular.cingular 0 07-12-2007 06:07 AM
LIVE LESBIAN SEX SHOWS lesbian sex chat lesbian sex toys lesbian porn sex jamaican lesbian sdfiuhsdejkds8dsj@yahoo.com alt.cellular.cingular 0 07-07-2007 04:56 AM


All times are GMT. The time now is 05:09 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45