Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » New Firefox Extension Thwarts MITM Attacks » Am I missing something?
Search Topic:
Uniqs:
60
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« Must have Firefox 3 to try it out  
AuthorAll Replies
-


Viper007Bond
Premium
join:2002-09-26
Portland, OR
reply to knightmb
Re: Am I missing something?

Actually, it would protect you on the first connect assuming someone else has connected to the site before. The trusted servers keep a history of known certs over time.


knightmb
Everybody Lies

join:2003-12-01
Franklin, TN
·AT&T DSL Service

reply to cdru
said by cdru See Profile :

So how does having this "notary" prevent a man in the middle attack? If there is a man in the middle between me and my bank, for instance, why can't that same man be between this notary and my bank?
It's based on the system of "how have things been" and "how have thing changed".

If your bank has always used the same certificate that doesn't expire for 8 years and one day at a coffee shop, the certificate has completely changed, but still "valid" as a MITM attack would do, it throws up an alert. I won't protect you from a MITM attack on the first ever visit to your banking website, only those afterward.

It's part of the problem computers have that humans tend to be better at. That's complete trust of strangers. If things look fishy, we get suspicious. Computers, they don't care, if 2 > 1, then they are happy. For us, when we see 2 > 1.5 we ask why 1.5 instead 1 like before?
--
Fight NebuAD and the like:
Click Here to pollute their data


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

reply to cdru
said by cdru See Profile :

So how does having this "notary" prevent a man in the middle attack? If there is a man in the middle between me and my bank, for instance, why can't that same man be between this notary and my bank?
See pages 7 thru 9 of their paper where they discuss the statistical odds against pulling off a MITM attack against the client and also against the MULTIPLE notaries at the same time.
»www.cs.cmu.edu/~perspectives/per···ix08.pdf
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?


cdru
Go Colts
Premium,MVM
join:2003-05-14
Fort Wayne, IN
So how does having this "notary" prevent a man in the middle attack? If there is a man in the middle between me and my bank, for instance, why can't that same man be between this notary and my bank?
Forums » New Firefox Extension Thwarts MITM Attacks« Must have Firefox 3 to try it out  


Saturday, 05-Dec 07:57:56 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [92] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· DNS options, what are YOU using? [TekSavvy]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Farewell [Bell Canada]
· UPS - What do you people think happened? [General Questions]
· Sun Releases Update 17 for Java SE 6 [Security]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]