3 ms·
An attacker that is able to MITM your traffic or poison your DNS can steal your session before you ever get to the trusted https url. http://www.thoughtcrime.o
by trotsky 15y ago
An attacker that is able to MITM your traffic or poison your DNS can steal your session before you ever get to the trusted https url.
http://www.thoughtcrime.org/software/sslstrip/ http://www.thoughtcrime.org/software/sslstrip/
- y0ghur7_xxx 15y agoBut that is a problem with STS too. That is why google is HSTS preloading a lot of google domains in their browser (they hardcode the domains). Couldn't they just hardcode the redirect so that if the user types http://gmail.com/ http://gmail.com/ chrome replaces it with https://gmail.com https://gmail.com?
- trotsky 15y agoSTS solves the problem unless the attacker has a fraudulent certificate for the domain you are reaching that is signed by a CA you trust. Presumably this is far fewer attackers than those who could manipulate your DNS or are on your local network to ARP in as a middleman. Basically, two different problems - the trust only X CA for xxx.com wouldn't ever get to come into play if someone using sslstrip simply keeps you from ever going to tls.
- extension 15y agoIt's a problem with STS the first time the browser visits a particular site. Once the browser receives the STS header, all future requests to that site will be over HTTPS.