ChatBox Sonicview Conaxsat Nanosat Viewsat i-Link DreamboxLimesat Topsat AzBox Satzen X-Factor

Go Back   FTA Files Community Forums for Satellite Equipment > General Discussions > World & Other News Discussion

World & Other News Discussion A place for FTA unrelated news.

Reply
 
LinkBack Thread Tools Rate Thread
  #1 (permalink)  
Old 03-25-2010, 11:38 AM
Putski's Avatar
Moderator
 
Location: In My Ice Shack!!!
Posts: 5,234
Thanks: 8
Thanked 12 Times in 12 Posts
Rep Power: 397
Putski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond reputePutski has a reputation beyond repute
Post Governments Using Forged SSL Certificates for Attacks on “Secure” Web Sessions

Governments Using Forged SSL Certificates for Man in the Middle Attack on “Secure” Web Sessions
From Wired
That little lock on your browser window indicating you are communicating securely with your bank or e-mail account may not always mean what you think its means.

Normally when a user visits a secure website, such as Bank of America, Gmail, PayPal or eBay, the browser examines the website’s certificate to verify its authenticity.

At a recent wiretapping convention, however, security researcher Chris Soghoian discovered that a small company was marketing internet spying boxes to the feds. The boxes were designed to intercept those communications — without breaking the encryption — by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate from any one of more than 100 trusted Certificate Authorities.

The attack is a classic man-in-the-middle attack, where Alice thinks she is talking directly to Bob, but instead Mallory found a way to get in the middle and pass the messages back and forth without Alice or Bob knowing she was there.

The existence of a marketed product indicates the vulnerability is likely being exploited by more than just information-hungry governments, according to leading encryption expert Matt Blaze, a computer science professor at University of Pennsylvania.

“If the company is selling this to law enforcement and the intelligence community, it is not that large a leap to conclude that other, more malicious people have worked out the details of how to exploit this,” Blaze said.

The company in question is known as Packet Forensics, which advertised its new man-in-the-middle capabilities in a brochure handed out at the Intelligent Support Systems (ISS) conference, a Washington, D.C., wiretapping convention that typically bans the press. Soghoian attended the convention, notoriously capturing a Sprint manager bragging about the huge volumes of surveillance requests it processes for the government.

According to the flyer: “Users have the ability to import a copy of any legitimate key they obtain (potentially by court order) or they can generate ‘look-alike’ keys designed to give the subject a false sense of confidence in its authenticity.” The product is recommended to government investigators, saying “IP communication dictates the need to examine encrypted traffic at will.” And, “Your investigative staff will collect its best evidence while users are lulled into a false sense of security afforded by web, e-mail or VOIP encryption.”
__________________
Yarrr Mateys have a rum and relax. Need some help ? Post in the Proper Disscusion!!!
And Start ur own Thread PLS!!!



ALWAYS REMEMBER USE OR LOADING OF FILES IS ALWAYS AT YOUR OWN RISK!!
Reply With Quote
Reply

Bookmarks

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bear attacks tourists in Japan! Putski World & Other News Discussion 1 09-20-2009 07:57 AM
Bobcat walks into Ariz. bar, attacks patrons Putski World & Other News Discussion 0 03-26-2009 12:04 PM


All times are GMT -5. The time now is 09:49 PM.
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
©2008 FTA Fire FTA Forums offers FTA Satellite support and FTA Files FTA Bins for all free to air satellite receivers.
Designed By: FTA FILES