4 ms·
No, underneath the bad writing it appears there is a real problem here. If you go to his simple walkthrough page you get a better understanding: https://leakyx.
by mdeeks 9y ago
No, underneath the bad writing it appears there is a real problem here. If you go to his simple walkthrough page you get a better understanding: https://leakyx.com/info.php https://leakyx.com/info.php
Credentials are sent BEFORE prompting the user to accept a self signed cert. So it sounds like an attacker can harvest credentials on a rogue wifi by spoofing DNS and using a self-signed cert. I don't have an iOS device so I can't test.
- mirashii 9y agoCan't edit to correct, but if what you say is true, I agree. Also no iOS device to test. It's really difficult to tell that's what's happening in the midst of all the incorrect statements and conclusions even up to that point, and with the B section being even more absurd. It's quite possible that the reporting to vendors would also miss the legitimate vulnerability through the rest of the noise.
- DiThi 9y agoThat link explains the problem much better than TFA.
- willstrafach 9y ago> Credentials are sent BEFORE prompting the user to accept a self signed cert. So it sounds like an attacker can harvest credentials on a rogue wifi by spoofing DNS and using a self-signed cert. I don't have an iOS device so I can't test. This does not appear to be the case (Tested on an iOS 10.3.3 device and an iOS 11 device).
- mdeeks 9y agoThanks for confirming. So then there is nothing at all of substance in this article.