[78157] in cryptography@c2.net mail archive
Re: "Free WiFi" man-in-the-middle scam seen in the wild.
daemon@ATHENA.MIT.EDU (Florian Weimer)
Tue Jan 30 11:24:48 2007
X-Original-To: cryptography@metzdowd.com
From: Florian Weimer <fw@deneb.enyo.de>
To: "Perry E. Metzger" <perry@piermont.com>
Cc: cryptography@metzdowd.com
Date: Sat, 27 Jan 2007 13:27:59 +0100
In-Reply-To: <87d555n7mp.fsf@snark.piermont.com> (Perry E. Metzger's message
of "Tue, 23 Jan 2007 09:24:30 -0500")
* Perry E. Metzger:
> If you go over to, say, www.fidelity.com, you will find that you can't
> even get to the http: version of the page any more -- you are always
> redirected to the https: version.
Of course, this only helps if users visit the site using bookmarks
that were created after the switch. If they enter "fidelity.com" (or
even just "fidelity") into their browsers to access it, switch to
HTTPS won't help at all. Perhaps this explains why someone might
think that serving the login page over HTTPS is just security theater.
In the same "we use use HTTPS and are still vulnerable to MITM
attacks" department, there's the really old issue of authenticating
cookies which are not restricted to HTTPS, but will be happily sent
over HTTP as well. *sigh*
Apart from that, the article you linked to does not even mention
actual attacks with an identity theft motive. What's worse, the
suggested countermeasures don't protect you at all. Ad-hoc networks
are insecure, and those with an access point are secure? Yeah, right.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com