4 ms·
It doesn't make a difference whether the communication is encrypted if you can't verify with whom you are communicating.
by stella 18y ago
It doesn't make a difference whether the communication is encrypted if you can't verify with whom you are communicating.
- modoc 18y agoThat's decidedly untrue. In this case I could be falling for a fake site and sending them my CC data, instead of Amazon, however I'm still protected from my CC being stolen by guy who setup the coffee house Wifi router.
- tptacek 18y agoUnfortunately, you too are misunderstanding how SSL works. If you own the coffee house WiFi router, you can decrypt any SSL session that traverses your network that doesn't use valid certificates. You simply need to inject your own certificate into the SSL session and fix a session key. You cannot secure a conversation between two unrelated parties over the Internet without some form of authentication, to "break the tie" if the attacker presents their own keys/certificates.
- modoc 18y agoActually, I'm not. I have great respect for your security knowledge, but your consistent black & white views and your assumption that anyone who doesn't share them doesn't understand the technology is frustrating. If I own a coffee house router, or if I am simply sniffing un-encrypted wifi packets out of the air in the coffee house, logging traffic is extremely simple. I can log all traffic, or just traffic to http pages with names like login, or checkout, and I can do that very very very easily. It will log tons data automatically, and let me comb through it later. As a newbie to linux I could do that. The barrier preventing me from stealing the info you send over http is VERY low, and virtually anyone can do it. The attack you describe is much more difficult to execute. The number of people who could make that attack is several orders of magnitude smaller than the previous attack. Hence my risk is several orders of magnitude smaller. You're arguing that because skilled safe-crackers can open a safe, people should just leave their valuables on their lawn chairs out front. Security isn't black and white. Nothing will be 100% secure from every type of attack. It's a matter of raising the barrier of entry for an attack high enough that it's generally not worth the trouble.
- tptacek 18y agoWhat you're not acknowledging, anywhere in the above 5 paragraphs of text, is that all the security you're talking about getting from SSL in this scenario is security that the attacker is choosing to give you. When we reason about information security, we don't usually give the attacker that kind of advantage. There is no such thing as a purely-passive attacker. In reality, no serious attacker is even going to bother sniffing your traffic; they're going to redirect it.
- modoc 18y agoSorry, the scenario we're talking about here, as laid out by you: "Not revoking certificates will negate all the security of SSL." We're not talking about the scenario where a very smart attacker is targeting me with this security hole. We're talking about the impact of not revoking the certificates in question. At which point there is a very very small possibility that I will be targeted by an active attacker with the know-how to exploit this issue. The rest of the time SSL will continue to work as designed and will protect me from wifi snoopers and suspect routers. There absolutely are passive attackers. There are people running open wifi points that log http form submissions with a "password" field, and then try the same username/password on a few major sites (ebay, amazon, etrade, gmail, BoA, etc...) automatically (working on the assumption that people use the same login/password on the many non-ssl authed non-important sites as they do for their important accounts). Successful login data is marked. I have met people running these. It costs nothing, is fully automated, and has very little risk. They may not be "serious attackers", but the likelihood of one of them getting your mom's eTrade info is much higher than an active attacker targeting your mom.
- tptacek 18y agoI'm sorry, I'm just not interested in talking about security in terms of attackers who are too dumb or lazy to carry out well-known, utterly practical attacks. You can keep saying that "the encryption part of SSL works fine with authentication"; if you add the phrase "as long as you're dealing with functionally retarded adversaries", I won't even call you on it.
- brl 18y agoOut of all the hypothetical scenarios you could have chosen, you picked one where it is not only possible to intercept your encrypted data but really quite obvious how to do it.