Web Page Certificates

Web Page Certificates

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Web Page Certificates teabox 01-20-2007
Posted by teabox on January 20, 2007, 8:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have been wondering how I can be sure, when more than one person uses
a computer, if the web page certificates are authentic or not. How do
I know that someone else didn't accept a bogus certificate?

Thank!


Posted by Todd H. on January 20, 2007, 10:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I have been wondering how I can be sure, when more than one person uses
> a computer, if the web page certificates are authentic or not. How do
> I know that someone else didn't accept a bogus certificate?

What operating system? What web browser? Do you have a separate
account on that computer that no one else has access to?

Also, it bears mentioning the obvious that just because a given web
site has an SSL certificate, and you're seeing one that is attributed
to them, doesn't mean your activities are safe and secure and that the
information you provide them won't be cracked by other means.

--
Todd H.
http://www.toddh.net/

Posted by teabox on January 21, 2007, 12:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Todd H. wrote:
>
> > I have been wondering how I can be sure, when more than one person uses
> > a computer, if the web page certificates are authentic or not. How do
> > I know that someone else didn't accept a bogus certificate?
>
> What operating system? What web browser? Do you have a separate
> account on that computer that no one else has access to?
>
>
> --
> Todd H.
> http://www.toddh.net/

Todd,

Thanks for you reply.

I am using Windows XP, SP2. Firefox 2.01 and Internet Explorer 6.

My computer at work does not have separate accounts, but even if I set
one up others could certainly use the account from time to time.

> Also, it bears mentioning the obvious that just because a given web
> site has an SSL certificate, and you're seeing one that is attributed
> to them, doesn't mean your activities are safe and secure and that the
> information you provide them won't be cracked by other means.

What other means are you thinking about? I am aware of key loggers and
traffic sniffing via programs like Cain and Abel(Cain uses fake SSL
certificates).

I am quite new to this. I am beginning to wonder if using a public
computer is safe at all. Regardless, I am interesting in understanding
how I can keep my private stuff private!

Thanks,

TB


Posted by Todd H. on January 21, 2007, 2:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Todd H. wrote:
> >
> > > I have been wondering how I can be sure, when more than one person uses
> > > a computer, if the web page certificates are authentic or not. How do
> > > I know that someone else didn't accept a bogus certificate?
> >
> > What operating system? What web browser? Do you have a separate
> > account on that computer that no one else has access to?
> >
> >
> > --
> > Todd H.
> > http://www.toddh.net/
>
> Todd,
>
> Thanks for you reply.
>
> I am using Windows XP, SP2. Firefox 2.01 and Internet Explorer 6.
>
> My computer at work does not have separate accounts, but even if I set
> one up others could certainly use the account from time to time.
>
> > Also, it bears mentioning the obvious that just because a given web
> > site has an SSL certificate, and you're seeing one that is attributed
> > to them, doesn't mean your activities are safe and secure and that the
> > information you provide them won't be cracked by other means.
>
> What other means are you thinking about? I am aware of key loggers and
> traffic sniffing via programs like Cain and Abel(Cain uses fake SSL
> certificates).

Exactly. Keyloggers for one.

Then, the actual websites you visit can be prone to attack
themselves.

Man in the middle SSL attacks are possible as well, and not all
require intervention.

> I am quite new to this. I am beginning to wonder if using a public
> computer is safe at all.

It is not. Maybe if you boot your own OS, but even then there could
be a hardware key logger installed. You never know.

> Regardless, I am interesting in understanding how I can keep my
> private stuff private!

You'll want to start by not using public computers, I'm afraid.

--
Todd H.
http://www.toddh.net/

Similar ThreadsPosted
Secure web page? February 22, 2006, 4:16 pm
routers rerouted by web page February 26, 2007, 11:07 am
posting form info to a page July 19, 2005, 11:42 am
Amazon.com's The Page You Made February 17, 2006, 7:16 pm
Certificates Question March 27, 2007, 2:50 am
Installing Certificates . Why?? help please August 26, 2007, 8:09 am

The site map in XML format XML site map

Contact Us | Privacy Policy