4 ms·
They're also leaving themselves open to MITM attacks, where an attacker could change all of the tor addresses.
by bweitzman 10y ago
They're also leaving themselves open to MITM attacks, where an attacker could change all of the tor addresses.
- chime 10y agoEven SSL sites are not immune. On corporate networks, the clients trust the company cert, which is used to proxy all traffic (including HSTS and HPKP/pinned sites) for filtering/logging.
- Spivak 10y agoIf you don't trust the machine you're currently on then it's already game over from a security perspective.
- jakelazaroff 10y agoIsn't the actual content of the page signed by the the site's certificate though? And they can't just serve a different certificate because your browser can tell whether or not it was issued by a trusted CA. How does the attack work in this case? Edit: Nevermind — I assume you're referring to this scenario[1], in which the company installs a root certificate onto your actual computer that allows them to sign certificates for other sites. [1] http://security.stackexchange.com/a/63306 http://security.stackexchange.com/a/63306
- tracker1 10y agoA lot of corporate computers have at least an additional CA authority on each computer that they use... if you're using a corporate computer, it's really easy for them to MITM any request, just relaying requests to the public resource, then proxying and using their CA signed cert in the proxy. From there, everything can be tracked.
- organsnyder 10y agoIf you have a corporate computer, you shouldn't rely on any expectation of privacy. There's nothing stopping them from installing other monitoring software—screen grabbers, keyloggers, etc.—whenever they please.
- Forbo 10y agoThat's where something like Tails comes in handy. :)
- infinite8s 10y agoI don't think Tails would work because a corporate proxy would likely block any outgoing connections. Also most corporate IT policies would probably disallow running something like Tails.
- EdHominem 10y agoThat's working. If it fails secure it's keeping you alive.
- CapacitorSet 10y agoMonitoring hardware, then.
- garrettr_ 10y ago(SecureDrop developer here) That's why we created https://securedrop.org/directory https://securedrop.org/directory (HTTPS, HSTS, preloaded, .onion available, etc.). Use that instead! Also, we have strong recommendations for the news organization's "landing pages" (e.g. https://theintercept.com/securedrop/ https://theintercept.com/securedrop/), including requiring HTTPS, to prevent this and other obvious security issues.