4 ms·
You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's
by mjs 11y ago
You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.
- nickodell 11y agoWell, what if the host you're connecting to is a Juniper firewall?
- toyg 11y agoYeah, because illegitimate / spoofed certificates will never happen...
- andreyf 11y agoI think we're well on our way to a point where certificates can be mostly trusted. Of course certs can be stolen, but I would bet that "spoofed" certificates will soon be an occurrence of the past.
- Ao7bei3s 11y agoWith certificate transparency, at least we'll know about it - afterwards, at least.
- marcosdumay 11y agoWell, afterwards, if the attack stops (software does not need to stop) in a timeframe short enough for your computer to no clear its history.
- hcf 11y agoMany https sites use RC4, I wouldn't be so sure.
- netheril96 11y agoThen use a browser that rejects RC4 (like latest Chrome).
- deleted 11y ago[deleted]
- Robin_Message 11y agoThe private key is used to negotiate a session key, which is then used as the symmetric key for RC4 or whatever stream or block cipher you are using. Those session keys are ephemeral and per-session, so leaking them is only a problem for those sessions. (Also, since it's a stream cipher, it can't use the same key ever again, else you can xor those ciphertexts to get 2 xored plaintexts, which are much easier to crack.)
- jlgaddis 11y agoI get where you're coming from and I want to agree with you but... While that used to be true, based upon recent history we, unfortunately, can't blindly trust HTTPS to always be "secure" 100% of the time anymore -- whether due to things like Heartbleed, fake certs signed by a root CA, protocol attacks, or some other vulnerability that hasn't even been discovered yet.