|
2007-11-18
, 19:32
|
|
Posts: 739 |
Thanked: 159 times |
Joined on Sep 2007
@ Germany - Munich
|
#12
|
|
2007-11-18
, 21:43
|
|
Posts: 641 |
Thanked: 27 times |
Joined on Apr 2007
|
#13
|
I'm wandering why you say that. Of course it matters if it's https or not. If https can be broken then it's much more dangerous to send it over the internet at large. It simply couldn't be used.
|
2007-11-18
, 22:11
|
Posts: 3,401 |
Thanked: 1,255 times |
Joined on Nov 2005
@ London, UK
|
#14
|
|
2007-11-18
, 22:47
|
|
Posts: 641 |
Thanked: 27 times |
Joined on Apr 2007
|
#15
|
Even with this kind of spoofing of your WiFi connection, how does this help the 'attacker' decrypt your SSL encrypted data? Unless he has offered up a bogus secure server certificate which you then unwisely accepted despite all the browser warnings, HTTPS is generally considered to be secure (if it wasn't, internet commerce would collapse overnight). Passing confidential data over HTTP connections (wired or wireless, WEP or WPA) is not clever, but absolutely fine over a properly authenticated HTTPS connection with a valid certificate.
|
2007-11-18
, 22:55
|
Posts: 3,401 |
Thanked: 1,255 times |
Joined on Nov 2005
@ London, UK
|
#16
|
|
2007-11-18
, 22:59
|
Posts: 3,401 |
Thanked: 1,255 times |
Joined on Nov 2005
@ London, UK
|
#17
|
The Following User Says Thank You to Milhouse For This Useful Post: | ||
|
2007-11-18
, 23:01
|
|
Posts: 641 |
Thanked: 27 times |
Joined on Apr 2007
|
#18
|
The point is HTTPS *is* secure and the connection medium is irrelevant (my wired ADSL connnection can easily be sniffed at the exchange). If a user blindly accepts an invalid certificate, that isn't the fault of SSL/HTTPS - sometimes there is nothing that can be done to protect the really stupid.
|
2007-11-18
, 23:13
|
Posts: 3,401 |
Thanked: 1,255 times |
Joined on Nov 2005
@ London, UK
|
#19
|
No, they get the initial keys, I don't know of anything that does it without them.
|
2007-11-19
, 11:49
|
Posts: 3,841 |
Thanked: 1,079 times |
Joined on Nov 2006
|
#20
|
N800/OS2007|N900/Maemo5
-- Metalayer-crawler delenda est.
-- Current state: Fed up with everything MeeGo.