
how-to block ads
|
 TKJunkMail Enjoy the sun Premium join:2002-03-03 Avalon, NJ
·Sprint Mobile Broa..
·Comcast
1 edit | Re: Past BBR stories established Nebuad only monitoring said by jimness000 :It sounds as though this technology could be used to gain access to proprietary info which is assumed to be secure (via HTTPS connections).Am I wrong? Yes. I think you are. The Nebuad device has no decrypting capabilities and can't see inside encrypted packets. They could tell the end points of the conversation but not see the data. -- My BLOG .. .. Internet News .. .. My Web Page | |
|   funchords Hello Premium,MVM join:2001-03-11 Washington, DC
·Verizon Online DSL
·Skype
2 edits | Re: Past BBR stories established Nebuad only monitoring said by TKJunkMail :said by jimness000 :It sounds as though this technology could be used to gain access to proprietary info which is assumed to be secure (via HTTPS connections).Am I wrong? Yes. I think you are. The Nebuad device has no decrypting capabilities and can't see inside encrypted packets. They could tell the end points of the conversation but not see the data. The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange. **
That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue.
We also have NebuAd's word that they won't try it, FWIW.
[Edit: I'm not sure this really means anything, SSL is not my strong point. It includes client sending of a code that can only be decrypted by a server's private key, but also includes several flavors of encryption of various strengths. In a cytological attack, my understanding is that the MITM can affect which get negotiated. All the more reason that we SHOULD be able to trust our ISPs and their vendors.] -- Robb Topolski -= funchords.com =- Hillsboro, Oregon HTTP is the new Bandwidth Hog...
| |
|  |  |  |  |  |   knightmb Everybody Lies
join:2003-12-01 Franklin, TN
·AT&T DSL Service
| said by funchords :The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange. That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue. We also have NebuAd's word that they won't try it, FWIW. I have to agree, they wouldn't need to waste CPU time to do this. That would actually give it a dual purpose perhaps. Serve ads and secret wiretaps. Either way, we might not be able to do anything about the secret wiretap, but at least we can make the regular stuff all look like garbage. As usual in this type of stories, I chime in the link in my signature.  -- Fight NebuAD and the like: Click Here to pollute their data | |
|  |  |   TKJunkMail Enjoy the sun Premium join:2002-03-03 Avalon, NJ
·Sprint Mobile Broa..
·Comcast
| Re: Past BBR stories established Nebuad only monitoring said by knightmb :said by funchords :The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange. That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue. We also have NebuAd's word that they won't try it, FWIW. I have to agree, they wouldn't need to waste CPU time to do this. That would actually give it a dual purpose perhaps. Serve ads and secret wiretaps. Either way, we might not be able to do anything about the secret wiretap, but at least we can make the regular stuff all look like garbage. As usual in this type of stories, I chime in the link in my signature. I think espaeth already answered the HTTPS issue here: »Re: Past BBR stories established Nebuad only monitoring -- My BLOG .. .. Internet News .. .. My Web Page | |
|  | |  |
|