4 ms·
https://moxie.org/software/sslstrip/ https://moxie.org/software/sslstrip/ The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true fo
by billyhoffman 7y ago
https://moxie.org/software/sslstrip/ https://moxie.org/software/sslstrip/
The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.
- jasonkester 7y agoAgain, that looks like it needs to be sitting somewhere between the end user and the webserver. I don't disagree that it is possible to mess with http traffic in flight if it's not encrypted. I do disagree that a) there are bad guys between me and the http://catpictures.com http://catpictures.com right now and b) They have targeted me with malicious cat pictures that will cause damage somehow. My sites that allow logins are all https only. My "cat picture" site is not. Because it doesn't need https.
- prophesi 7y agoCan you give a reason for not using https in the age of LetsEncrypt? And yes, the point of MITM is that there has to be a malicious actor in the middle. This is mainly a threat when using public WiFi, like at an airport or a coffee shop. It's absolutely trivial for some bored individual to run SSLstrip for funsies and distribute malware through any HTTP connections. Also, an attacker doesn't need to somehow create malware-infested versions of the cat pictures on your site. They only need to append some javascript at the end of your site's body tag, which again, is trivial for a script to do. And maybe a transparent image with the malicious payload should they have JS disabled. To those wondering how they might protect themselves from these sorts of attacks when using non-SSL sites on public WiFi, this is where a VPN comes in handy. All of your connections will be encrypted and no longer vulnerable to MITM attacks.
- philsnow 7y agoI know you probably have a better understanding of how vpns work than I do, but the blanket statement that using a VPN makes your connections immune to MITM is not correct. True, an attacker needs to find some other link between the terminus of your VPN and the target site to MITM, and true, those links are orders of magnitude harder to compromise usually. But a VPN is not magic pixie dust that you sprinkle on your laptop and now you don't have to worry about security anymore.
- prophesi 7y agoSecurity is a battle with convenience. Sure, it's technically possible for someone to pull off a MITM attack on someone using a VPN; perhaps there's an attack vector before they establish their VPN connection, or they've compromised the server running the VPN service, etc. But that's probably only a threat to government agents and Snowden, whom have real fears of targeted attacks like that. For the layman, VPN pretty much is a magic pixie dust that will let you browse unencrypted websites with confidence that the pages won't be modified, and your form submissions won't be sniffable on your public network. Of course, it won't protect you from sites that already have malware on them.
- PenguinCoder 7y agoIt's not just about protecting sensitive information. It's about a litany of other reasons. Censorship, integrity, protect against tampering/malware campaigns, etc. These articles explain it better than I can. https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs... https://security.stackexchange.com/questions/52856/why-do-websites-use-https-when-they-dont-need-to https://security.stackexchange.com/questions/52856/why-do-we...
- magnetic 7y ago> I do disagree that a) there are bad guys between me and the http://catpictures.com http://catpictures.com right now I don't know how one can disagree with something that can't be known one way or the other. Security features/processes are there to account for the small possibility that an attack is attempted. They don't become useless simply because attacks aren't happening 100% of the time. For example: your door lock (deadbolt) is locked even when there isn't someone actively trying to break into your house. In your particular example, sitting between A and B doesn't always mean sniffing packets you send from A to B as a "passive listener". It could simply be that the attacker has fed you his/her rogue IP via DNS and you are connecting to his server that is pretending to be B. At that point yes the attacker is sitting between A and B, but it's not like s/he is sitting on a router sniffing your packets. S/he does not have to be a malicious player near the target server, or part of the infrastructure that you use to get to B. S/he can be somewhere completely remote.
- deleted 7y ago[deleted]
- giornogiovanna 7y agoThe bad guy could be your evil sister on your home network. It could be anyone in your university. What if they replaced the like button under your cat photo with a like button for something evil? Or what if they put their own ads and tracking scripts into the page to make themselves some money? Lots of ISPs already do that on HTTP pages, so it's not just a hypothetical.
- msla 7y agoIt isn't about cat pictures, it's about sending a message. The message we need to send is that Internet traffic is private and encrypted by default. You don't "turn on" encryption only when you're doing something which needs to be hidden any more than you only use envelopes when you're mailing something which needs to be hidden. Your letters to grandma are in envelopes, not because your correspondence with her is "interesting" in any real sense, but because letters in envelopes are the default. It's a social expectation, in other words, and we need to import that expectation to the Internet to the greatest extent possible, because the Internet is the new mail system, information hub, and everything else. Plus, I really don't want to give my ISP any foothold to insert advertising.