Search   Feed   Browse   Add
Feed items 1 - 9 of 9 for July 2008

Comments on: Unobstructed HTTPS

Robert Accettura's Personal Blog on Web Development and Tech

By: Oliver - July 25, 2008

Robert, you have my full support, it&8217;s a thing of the user interface not the technical side. A prove that a normal user doesn&8217;t care and doesn&8217;t understand about the &8220;behind the scene&8221; difference was given to me just yesterday. He called and told me that he no longer can&8217;t use FF3 because it gives him an error accessing the webgui page of his hosting account, and he now has to use IE6 and asked my to fix the problem for FF3. The problem was easy, the webgui...
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-393250

By: Robert - July 23, 2008

Ted Mielczarek: True. And they still can. My proposal is that the UI distinguish between signed and self signed SSL certificates. The user would still know AMO is trusted, or their bank is trusted. But they would also be able to access things on their intranet, or their personal website using SSL without being told there&8217;s an error. The proposal isn&8217;t really a technical change. It&8217;s merely a UI change to be more graceful. It could even display a banner similar to that of a..
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-389819

By: Ted Mielczarek - July 22, 2008

Robert: the problem there is that the site may want SSL for both encryption and protection against DNS hijacking. For example, the AUS connection that Firefox uses to download updates is SSL not for the encryption, but for the assurance that we are in fact connecting to AUS. What happens if you install Firefox on a laptop, then fire it up for the first time on an untrusted WiFi hotspot, and someone MITMs you to serve you a malicious update Granted, the update code could be more strict than the..
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-389406

By: Robert - July 22, 2008

Neither do self-signed HTTPS connections, right Correct. You get a cookie. but if the browser shows the same chrome for it as it does for a CA-signed one, it looks every bit as good as your Financial Institution of Choice or your Secure E-mail Login Page. Funny what might happen if your DNS got hijacked and one of those sites was using a self-signed cert, eh I specifically said: The user interface should indicate that the channel is encrypted and communication is unlikely to be...
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-388624

By: Evan - July 22, 2008

John, good point. However, there is no reason the browser needs to show special chrome &8230; just let my connection go through and don&8217;t bother me. If I&8217;m going to enter my credit card, I&8217;m gonna check for a good CA-signed certificate, but otherwise I probably don&8217;t care.
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-388590

By: John Silvestri - July 21, 2008

Evan >Neither do self-signed HTTPS connections, right &8230;but if the browser shows the same chrome for it as it does for a CA-signed one, it looks every bit as good as your Financial Institution of Choice or your Secure E-mail Login Page. Funny what might happen if your DNS got hijacked and one of those sites was using a self-signed cert, eh
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-388570

By: Evan - July 21, 2008

> This is not at issue. Again, HTTP connections dont claim to be authenticated. Neither do self-signed HTTPS connections, right
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-388158

By: Remy - July 21, 2008

Robert: The point is, SSL certificates guarantee that when you are connected to a certain domain, the connection to that domain is secure (authenticated and encrypted) and not hijacked. Whether you trust that domain is up to you. Phishing works by getting people to trust malicious domains. SSL and PKI do not guarantee that any given site is trustworthy, only that it is who it claims to be. EV certs can associate a business name to a domain, but then you have to decide whether you trust that...
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-388124

By: Robert - July 21, 2008

Remy: You obviously didn&8217;t read anything before commenting. &8220;People expect HTTPS to be secure&8221; is fallacy. Just look at phishing problems. Phishing sites are often served over SSL. That&8217;s why EV-SSL was created to fix, which there&8217;s evidence to suggest it didn&8217;t work. CA&8217;s don&8217;t do &8220;high quality validation&8221;. Phishers have been using signed certificates for a long time. You can often buy them with a shared hosting account (which you can get.
http://robert.accettura.com/blog/2008/07/19/unobstructed-https/#comment-387286
Available Archives
- July (9 items)
- August (1 item)
Sponsored Links
© 2008 FeedCapsule.com  |  Contact