On CHOW: Why are shopping carts so hard to steer?
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 12 of 12:
« Previous
clues for the clueless
A few comments from a working infosec geek...

First of all, thanks David, Ferret sounds like a nice piece of work!

Also, you made a very good point with the mention of SSL man in the middle, the previous posts about safety from SSL missed a couple of things.

MITM (Man Tn The Middle) is one, another is that SSL only protects data in transit on the network (okay, technically it protects it between the en/decryption points in the protocol stack (I haven't looked at source to determine where and how that's implemented, would assume it's somewhere in the sockets interface) but not before or after the calls to the network transport) but not end to end from the user to the remote app, nor at rest at either end.

Keyloggers look at the data before the part of its lifecycle secured by SSL; MITM breaks the SSL pipe into two secured segments separated by an insecure (compromised) segment.

Thankfully MITM is somewhat challenging technically, but keyloggers are not.

Overconfidence is dangerously prevalent, a little knowledge is a dangerous thing.
Posted by: bruce_mcculley@...   Posted on: 03/06/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Public Wi-fi Network  D. T. Schmitz | 03/02/07
One additional detail...  D. T. Schmitz | 03/02/07
This article is a bit misleading...  AnonymousBugMeNotUser | 03/02/07
You are dead WRONG. Here's why:  btljooz | 03/02/07
Please try to explain yourself in coherent English...  Marty R. Milette | 03/02/07
RE: You are dead WRONG. Here's why:  Techknowledgie | 03/02/07
YOU are clueless...  JustMichael | 03/02/07
not to pick on you, but  Been_Done_Before | 03/05/07
question about keyloggers  alexlee81721 | 03/05/07
He is only partley cluless  pgm554 | 03/05/07
Actually..  dmaynor | 03/05/07
clues for the clueless  bruce_mcculley@... | 03/06/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here