5 ms·
Wouldn't it be vulnerable to simple eavesdropping? SSL can be attacked via MITM, but since certificates are authenticated your browser knows when it occurs. (I
by NinetyNine 15y ago
Wouldn't it be vulnerable to simple eavesdropping? SSL can be attacked via MITM, but since certificates are authenticated your browser knows when it occurs. (I still don't know quite how that works)
- jackowayed 15y agoI think that, assuming the proper content of the page is loaded, the communication with Stripe is done over SSL. The problem is that someone could do a MITM and give you different content that, say, sends your credit card to their server instead. And that would be a much easier MITM than if he were using SSL because they wouldn't even have to provide a fake certificate.
- jvdongen 15y agoHow that exactly works is a bit too long a topic for a comment here (try google - "public key encryption", "X.509" and "certificate authority" are some relevant search terms if you're interested). However what I'd like to point out is that 'simple eavesdropping' effectively is a Man-In-The-Middle attack, be it a passive one (the man in the middle is just keeping his mouth shut and only listening). And eavesdropping on someones internet connection is, contrary to popular believe, not that simple. The eavesdropper needs at least one of: a) effectively have a (virtual) presence on either one of the endpoints of the connection b) unfettered access to exactly the correct pieces of equipment that are part of the internet's infrastructure. c) some way of persuading your traffic to take a de-tour from a remote location Option a) is the easiest I guess - just drop a piece of malware on someones PC (takes care of that whole pesky SSL issue as well). Although certainly doable - I would not describe it as trivial. Most 'cyberattacks' targeted at the masses are not exactly efficient - their success largely depends on the large numbers of targets - targeting a specific person is quite a bit of work. Option b) is, depending on who you are either relatively easy or nearly impossible. If it's easy for you, you've probably signed a piece of paper promising you a large bank account withdrawal and/or all kinds of 'benefits' in a state-sponsored facility if you abuse your powers. That won't stop everybody and there are parties for who it is actually their job to do this kind of things, but for the most part you can forget about option b) unless you happened to have attracted the interest of aforementioned parties. In which case I wish you good luck. The feasibility of option c) depends even more on local circumstances of the victim than option a) but is a real possibility, but certainly not trivial. Something like dns-cache poisoning comes to mind. So - eavesdropping is certainly possible, but I would by no means call it simple. Rgds, Jeroen
- almost 15y agoUnless the user is using public wifi. Then eavesdropping is pretty easy. I would imagine its very much a not hugely hard possibility on WEP secured wifi networks too.
- InclinedPlane 15y agoSSL can't be MITMed because SSL certs need to be signed by a certificate authority, and those signatures can be checked against pre-loaded public keys in the browser (CA certs). However, if the serving page is non-SSL that then posts via SSL then it's possible for a MITM attack to hijack the connection and display a new page that posts to some other location (where the credit card numbers are collected, etc.) without the user's becoming aware of it easily.
- Confusion 15y agoIn theory, yes. In practice, many CA authorities have probably leaked their keys. The recent publicly known cases are only the tip of the iceberg.
- MichaelGG 15y agoInteresting - can you link to some information about CA actually losing their private key? I've read about Comodo and others allowing people to improperly sign stuff, but nothing about a CA actually losing their key.
- Confusion 15y agoSorry, I didn't mean to say that it was publicly known that CA's had lost their private keys. I meant that the publicly known security problems, about Comodo and others, is probably the tip of the iceberg. With all the hacks going on, I don't doubt for a second that private keys have been compromised, without the CA's knowing it themselves.
- InclinedPlane 15y agoDon't most (all?) CA's use hardware based private keys that can't be compromised without loosing physical possession?