Announcement

Collapse
No announcement yet.

Interesting SSL certificate attack

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Interesting SSL certificate attack

    The idea being that your web browser trusts certificate authorities (like verisign) in other foreign nations. Those CAs can be forced by their government to create a false certificate for say like http://www.bankofamerica.com. The end user would notice nothing wrong if sent to a fake site.

    Abstract: This paper introduces a new attack, the compelled certificate creation attack, in which government agencies compel a certificate authority to issue false SSL certificates that are then used by intelligence agencies to covertly intercept and hijack individuals' secure Web-based communications. We reveal alarming evidence that suggests that this attack is in active use. Finally, we introduce a lightweight browser add-on that detects and thwarts such attacks.
    https://docs.google.com/viewer?url=h...t/ssl-mitm.pdf

    #2
    Very interesting. I'll have to read teh PDF link when I have some more time.
    [SIZE=1][B]"Now more than ever the people are responsible for the character of their Congress. If that body be ignorant, reckless, and corrupt, it is because the people tolerate ignorance, recklessness, and corruption." ~President James Garfield[/B][/SIZE]
    <<< Please [URL="http://www.cainslair.com/misc.php?do=donate"]donate[/URL] >>>

    Comment


      #3
      Interesting indead, I had just head about this. Dang it, looks like I'll have to start using FF for all banking and SSL secured connections.
      [IMG]http://thepebkac.net/images/sigs/Outdoors_sig.jpg[/IMG]
      Like the community? Donate here:
      [URL="http://www.cainslair.com/misc.php?do=donate"]http://www.cainslair.com/misc.php?do=donate[/URL]

      Comment

      Cain's Lair Forums Statistics

      Collapse

      Topics: 26,187   Posts: 269,850   Members: 6,183   Active Members: 7
      Welcome to our newest member, Fermin13Q.

      Today's Birthdays

      Collapse

      There are no members with birthdays today.

      Top Active Users

      Collapse

      There are no top active users.

      More Posts

      Collapse

      • Reply to Hi guys!
        by Evil_T0NY {CLR}
        I've been Alpha and will be Beta testing the Delta Force game. It's been really getting good reviews! Definitely a good Battlefield feel to it like the...
        14 Nov 2024, 08:50 PM
      • Reply to Hope your all OK over there
        by Apache Warrior
        We had 17 inches of rain from the storm on November 7, 2024.
        Apache
        11 Nov 2024, 07:55 AM
      • Reply to Hope your all OK over there
        by Sirex
        Aye, I'm inclined to agree with that lmao
        Gone are the days of warm summers and snow filled winters here, nothing but rain and wind for 8mths of...
        10 Nov 2024, 08:53 PM
      • Reply to Hope your all OK over there
        by Apache Warrior
        Now we have had a lot of flooding in this area and there are still a lot of houses that have not been repaired. Must be the apocalypse.
        ...
        8 Nov 2024, 09:23 AM
      Working...
      X