3 ms·
Because if you have a smartphone that you use to access your email then you'll be getting notifications non stop. That is, unless you want to whitelist every si
by RyanKearney 15y ago
Because if you have a smartphone that you use to access your email then you'll be getting notifications non stop. That is, unless you want to whitelist every single IP address your carrier would use.
- robg 15y agoI think that's where the reverse look ups to location becomes important. The chance that a hacker would be in the same physical location seems small.
- Tharkun 15y agoI fear your assumption might be wrong. It's much easier to steal someone's password when they're in the area than from afar. A bit of clever packet sniffing, session hijacking, DNS fun, or even some plain old binoculars are MUCH more effective than trying to guess someone's password.
- robg 15y agoHow many folks manually enter in an email pswd on their smartphones? If any of the tools you mention were readily doable today, I fear we'd be so deep in trouble, no canary would help.
- JoachimSchipper 15y agoAll of these tools are available. Also, recall that most mail clients will use STARTTLS opportunistically, i.e. will not encrypt stuff if you MITM them. The better ones may not send the login in the clear, but an attacker can still read mail - or steal the authenticated connection (this is more tricky, and pretty much requires being on the same network.) Seriously, most online security works only because the competent people have better things to do.
- bigiain 15y agoAnd many mail clients happily continue non-encrypted sessions if the STARTTLS negotiation fails. I wasted _days_ recently trying to track down code bugs that weren't there - a piece of Cisco gear that was in the clients network was running a standard configuration called SMTP Fixup which was deep packet inspecting and rewriting the "250-STARTTLS" capability responses and passing them on as "250-XXXXXXXA" on the fly. It took me way longer than it should have to debug, partly 'cause I started looking in the wrong place, but largely because most of the testing we did was with mail clients that were perfectly happy to transfer mail unencrypted when the STARTTLS capability wasn't announced. Anybody MITMing you in Starbucks could easily do the same. A little bit of thinking with my "evil hat" on leads me to believe a similar protocol aware packet inspection/modification tool could easily rewrite webpages on the fly, looking for links to common service login forms and rewrite appropriate links and form actions to be http instead of https... Maybe an appropriately paranoid way to set up this sort of canary is to have all your mobile (ie, non-fixed ip address) devices use a vpn into a trusted and well secured host?
- daeken 15y ago> A little bit of thinking with my "evil hat" on leads me to believe a similar protocol aware packet inspection/modification tool could easily rewrite webpages on the fly, looking for links to common service login forms and rewrite appropriate links and form actions to be http instead of https... That already exists in the form of sslstrip: http://www.thoughtcrime.org/software/sslstrip/ http://www.thoughtcrime.org/software/sslstrip/