Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Apple Devices

Notices

Reply
 
Thread Tools Search this Thread
Old 02-19-2016, 09:28 AM   #46
pdurrant
The Grand Mouse 高貴的老鼠
pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.
 
pdurrant's Avatar
 
Posts: 71,507
Karma: 306214458
Join Date: Jul 2007
Location: Norfolk, England
Device: Kindle Voyage
Quote:
Originally Posted by ApK View Post
BTW, does anyone know: Can a MitM attack be successfully executed, in the real world, if you check that the server shows a properly issued SSL cert? That is, assuming your browser is not compromised, if you actually check that the cert is issued to the correct domain from a trusted root, is there a legitimate chance of there being a MitM? I'm seriously asking because I'm not that versed in the implementation details of SSL or proxies.
I think that if you check the certificate fully, there can't be a MITM, at least, not without compromising the server or the trusted roots.

But I'm by no means an expert.
pdurrant is offline   Reply With Quote
Old 02-19-2016, 09:38 AM   #47
HarryT
eBook Enthusiast
HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.
 
HarryT's Avatar
 
Posts: 85,544
Karma: 93383043
Join Date: Nov 2006
Location: UK
Device: Kindle Oasis 2, iPad Pro 10.5", iPhone 6
This is perhaps why modern banking websites (mine at least) don't ask you to enter your complete password, but only selected letters from it. Information intercepted in such a way would not be sufficient to allow anyone to gain access to your account.
HarryT is offline   Reply With Quote
Advert
Old 02-19-2016, 11:01 AM   #48
ApK
Award-Winning Participant
ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.ApK ought to be getting tired of karma fortunes by now.
 
Posts: 7,318
Karma: 67930154
Join Date: Feb 2010
Location: NJ, USA
Device: Kindle
Quote:
Originally Posted by HarryT View Post
This is perhaps why modern banking websites (mine at least) don't ask you to enter your complete password, but only selected letters from it. Information intercepted in such a way would not be sufficient to allow anyone to gain access to your account.
Kossowsky's Law of Network Security: If there is a legal way in, then there is an illegal way in.

If those few characters give you access, they could give not you access as well.

I've never seen the partial pwd thing you're describing, but it essentially sounds like a variation of a session key. ie, the few characters that work THIS time would not be the same few characters that work THE NEXT TIME, right?

ApK
ApK is offline   Reply With Quote
Old 02-19-2016, 11:03 AM   #49
HarryT
eBook Enthusiast
HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.
 
HarryT's Avatar
 
Posts: 85,544
Karma: 93383043
Join Date: Nov 2006
Location: UK
Device: Kindle Oasis 2, iPad Pro 10.5", iPhone 6
Quote:
Originally Posted by ApK View Post
I've never seen the partial pwd thing you're describing, but it essentially sounds like a variation of a session key. ie, the few characters that work THIS time would not be the same few characters that work THE NEXT TIME, right?
That's right. It asks you at random for, say, the 2nd, 4th, and 7th character of your password.
HarryT is offline   Reply With Quote
Old 02-19-2016, 02:19 PM   #50
pdurrant
The Grand Mouse 高貴的老鼠
pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.pdurrant ought to be getting tired of karma fortunes by now.
 
pdurrant's Avatar
 
Posts: 71,507
Karma: 306214458
Join Date: Jul 2007
Location: Norfolk, England
Device: Kindle Voyage
Quote:
Originally Posted by HarryT View Post
That's right. It asks you at random for, say, the 2nd, 4th, and 7th character of your password.
My late sister-in-law wrote to the bank to check it was OK when one time it asked her for the 1st, 2nd and 3rd letters of her password.

Not many people understand true randomness.
pdurrant is offline   Reply With Quote
Advert
Old 02-21-2016, 03:17 AM   #51
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,422
Karma: 85397180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Quote:
Originally Posted by ApK View Post
BTW, does anyone know: Can a MitM attack be successfully executed, in the real world, if you check that the server shows a properly issued SSL cert? That is, assuming your browser is not compromised, if you actually check that the cert is issued to the correct domain from a trusted root, is there a legitimate chance of there being a MitM? I'm seriously asking because I'm not that versed in the implementation details of SSL or proxies.
Disclaimer: I am going to join you all in not being a security expert.

But as I understand, this is the exact threat which HTTP Strict Transport Security protects against.

MITM is usually leveraged to strip the SSL and relies on the user not knowing that the website should use HTTPS.
Of course, there are some attacks that strike against TLS itself. But generally those get fixed by software updates (not much else you can do really).


As you say, this all depends on your computer (and the certificate authority!) not being compromised. If that happens, you've lost before you started fighting.

Last edited by eschwartz; 02-21-2016 at 03:24 AM.
eschwartz is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Seriously thoughtful Verso un Forum italiano/Toward an Italian Forum beppe Lounge 262 01-19-2022 05:50 AM
MobileRead forum is requesting authentication upon entering any forum Katsunami Feedback 19 03-16-2014 02:11 AM
WOW! The Kobo Forum is Almost Getting as Much Action as the Kindle Forum!!! pokee Kobo Reader 16 11-13-2011 09:50 AM
Sondaggio su apertura forum italiano/Italian forum Poll kya General Discussions 27 11-07-2011 06:32 AM


All times are GMT -4. The time now is 10:24 AM.


MobileRead.com is a privately owned, operated and funded community.