4 ms·
I love how Chrome tells me that this link is insecure (something wrong with SSL). Oh coincidences... Besides that, I don't quite understand what separates this
by zbanks 16y ago
I love how Chrome tells me that this link is insecure (something wrong with SSL). Oh coincidences...
Besides that, I don't quite understand what separates this from any other IM platform..?
- xtacy 16y agoIn IM clients like Pidgin, you can enable TLS for connecting to a Jabber chat server (provided the server supports it). Chat should be encrypted; I wonder why it wasn't the case with Kik.
- pluies 16y agoWell... secure.grepular.com uses an unsigned certificate, that makes most browser squeak. It is important to understand that albeit it's not proper https, this is still an encrypted connection that will make eavesdropping impossible. Being signed by an actual authority is only necessary to ensure the website we're talking to is actually secure.grepular.com, and not a man-in-the-middle that would intercept our queries and forge answers. "Unfortunately", both ideas of security and authentication are part of https, and having one without the other is going to pop big scary messages. This sort of https is still more secure than plain http. His point about transmitting the password in plain sight is a very good one. Firesheep showed how bad it is to transmit your cookies in plaintext, but sending your login/pass is even worse.
- MichaelGG 16y agoMaking browsers squeak is a fundamental part of the SSL security model. Invalidly signed HTTPS is only slightly more secure than HTTP. Let's look at the open WiFi scenario. If you login to ServiceX over HTTPS but ignore certificate warnings, I can just mount a man-in-the-middle attack and relay all your traffic to ServiceX. It's more involved than just sniffing your cookies, but its still quite practical. The only place where ignoring certificates is OK is if you know that an attacker can _read_ your network, but cannot write anything to it.
- deleted 16y ago[deleted]
- cheald 16y agoExplain this to me, because one of us is misunderstanding https. As I understand it, the danger of a self-signed certificate is that you don't know if it was issued by the site owner. You don't get the certificate authority's trust by proxy, but if the certificate is genuine, it's as secure as any level 3 ssl certificate. The only thing a CA certificate is guaranteed to get you is the ca's rubber stamp that they issued it.
- MichaelGG 16y agoYou said it yourself: "the danger of a self-signed certificate is that you don't know if it was issued by the site owner". In the case of someone attacking you on WiFi, that self-signed certificate wasn't issued by the site owner. It was issued by the attacker. If you happily ignore warnings, your browser will just setup a "secure" connection to the attacker. Then the attacker just creates another HTTPS connection to your actual destination, and proxies the content back and forth. Now, if the attacker can only read packets, then yes, the actual encryption is still secure. But in many places where an attacker can sniff (WiFi, on your Ethernet), they can also inject. There are lots of problems with CAs and the crappy verification that goes into most certificates. But having a CA cert for SSL still significantly raises the bar and limits the extent of an attack. (If one did get a signed cert for PayPal or Facebook, they couldn't just go and publish it in a program like Firesheep, as it'd get revoked pretty quickly.)
- chrisbolt 16y agoIt is important to understand that albeit it's not proper https, this is still an encrypted connection that will make eavesdropping impossible. If it's a self signed certificate, how can you tell between a certificate self signed by the website owner and a certificate self signed by the eavesdropper?
- toolate 16y agoTo view this page in Firefox I have to add an exception for the certificate. Firefox now displays a hint that this is a secure connection (http://imgur.com/d9kEd http://imgur.com/d9kEd). It's up to me to remember that this specific site uses a self generated certificate and that I shouldn't place the same level of trust in this certificate as I do with others. If this guy wants to use SSL he should do it properly.
- cheald 16y agoBy accepting the certificate, you've indicated that you trust that the certificate is genuine. At that point, it's as good as any CA-signed certificate. The only difference is that you made a decision to trust the certificate, rather than trusting a CA to verify its authenticity.
- mike-cardwell 16y agoThe certificate isn't unsigned. It is signed by cacert.org. I finally decided to stop paying CA's for something which should be free a few weeks ago. Hopefully they'll get their root cert in the major browsers in the not too distant future, but I'm willing to put up with people seeing the browser warnings until then. My website is primarily read by geeks anyway, who should know what it means. If you want to install cacert.org's root certificate in your browser, visit here: https://www.cacert.org/index.php?id=3 https://www.cacert.org/index.php?id=3 Kik.com has over a million users transmitting login credentials and private conversations. secure.grepular.com doesn't.
- mike-cardwell 16y ago"I love how Chrome tells me that this link is insecure (something wrong with SSL). Oh coincidences..." See https://cacert.org/ https://cacert.org/ and install their root if you think the CA model is broken and should be free. "Besides that, I don't quite understand what separates this from any other IM platform..?" GTalk, MSN, Yahoo Messenger, AIM, ICQ and Skype all encrypt your login details. Kik doesn't GTalk, ICQ and Skype all encrypt your actual conversations. Kik doesn't. All of the above mentioned IM services have publicly stated that they don't log IM conversations. Kik hasn't.