3 ms·
Why use a VPN if you're accessing PayPal over HTTPS?
by ewillbefull 14y ago
Why use a VPN if you're accessing PayPal over HTTPS?
- agwa 14y ago> Why use a VPN if you're accessing PayPal over HTTPS? There are too many ways things can go wrong even with HTTPS. First, how do you get to PayPal? Do you enter www.paypal.com or https://www.paypal.com https://www.paypal.com? If you do the former you can be sslstrip'd [1]. You can check for the padlock icon (plus the correct domain name in the URL) but what if you forget? All it takes to be pwn'd is forgetting once, and if you're hurrying to get a bid in on eBay you'll probably forget. What if you do go to the HTTPS URL but get a certificate warning? I'm sure most HN users would do the right thing and reject it, but for ordinary users it's probably easier to just have a corporate policy that says "always use the VPN when on the road." And even if you always go to the HTTPS URL and reject invalid certificates, what if the site operator does something stupid like include non-HTTPS content or use session cookies without the secure flag? HSTS is making things much better, but it's not a panacea - you have to have visited the site recently from a trustworthy connection for it to work. I still say VPN is better. [1] http://moxie.org/software/sslstrip/ http://moxie.org/software/sslstrip/
- qu4z-2 14y agoJust to expand slightly: If you type www.paypal.com, click login and then check for the padlock, it may very well show up. https://www.paypa1.com https://www.paypa1.com is a perfectly valid site, and you're accessing it over ssl, after all.
- kijin 14y agohttps://www.eff.org/https-everywhere https://www.eff.org/https-everywhere can fix most of the issues you mentioned, by forcing the browser to use HTTPS on domains like paypal.com. You don't even have to have visited the site recently, because the whitelist is supplied by EFF.
- agwa 14y agoThat's a very good point. (Of course there are still many sites out there that don't have HTTPS at all.)
- briandear 14y agoThere are man-in-the-middle attacks that can cause problems with https. http://www.schneier.com/blog/archives/2011/09/man-in-the-midd_4.html http://www.schneier.com/blog/archives/2011/09/man-in-the-mid...
- lukegb 14y agoIn this specific case you don't even need SSL Anywhere if you're using Chrome, because "www.paypal.com" is in Chrome's built-in HSTS SSL-only list, along with Google, Twitter, Simple, Mega, Braintree and a bunch of other places. http://src.chromium.org/viewvc/chrome/trunk/src/net/http/transport_security_state_static.json?view=markup http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...