How to protect your privacy while on WiFi ?

How to protect your privacy while on WiFi ?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to protect your privacy while on WiFi ? wylbur37 09-10-2007
Posted by Unruh on September 13, 2007, 6:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>If I am using a library or free AP to book a vacation
> with personal info, credit card etc.
>Would you rec using a 39.99 program along with
> Vista with all the security running.
>Or would Vista with all the security running be
> enough?
>Thanks.

If you are jumping out of a plane, do you think a burning parachute is
enough or would you advise a burning parachute with a crash helmet.


>> Unruh wrote:
>>
>> >
>> > >When using the Internet via WiFi at a public place such as a
>library
>> > >or cafe, it is conceivable that the people running the router
>> > >could be capturing all of your transmissions and therefore
>> > >could be recording your name, account numbers, etc.
>> >
>> > Use ssh.
>>
>> This doesn't really add anything over a simple SSL connection.
>>
>> > But the greater danger is taht they have put trojaned files onto the
>> > computers. Thus you cannot really trust the puttyssh they installed
>>
>> The scenario is using public APs not kiosks. You're using your own
>> software and machine.
>>
>> As long as you're not foolish enough to disable security warnings, and
>> pay attention to them, there's nothing at all dangerous about using
>> sensitive Internet services from WiFi access points. It's safer than
>> handing your credit card to the flunkie behind the counter when youpay
>> for that double mocha latte. Your local library or Starbucks is no
>more
>> or less trustworthy than your ISP, and your home broadband connection
>> can be "sniffed" by your neighbors as easily as your wireless
>> connection at the AP in many cases.
>>
>> That's why end to end encryption exists folks, to make that sniffing
>an
>> exercise in futility. The only thing a onlooker can learn is where you
>> do your business, and contrary to what someone posted things like Tor
>> not only add a layer of encryption similar to SSL/HTTPS, they also
>> remove that piece of information from the equation. An HTTPS
>connection
>> made through the Tor network is 100% secure no matter where you are or
>> what you're doing when they're use properly.
>>
>> > for example, or even the keyboard, since that could be captured.
>> > If it is your own computer, then use ssh, and do not use web
>> > browsers.
>>
>> Huh?
>>
>> Then how in the heck are you going to actually do anything?
>>
>> >
>> >
>> >
>> > >Are there ways to prevent or minimize this hazard?
>> >
>> > >For example, would it help to use something like Torpark?
>> >
>> > >What would you recommend?
>> >
>>


Posted by Anonymous on September 14, 2007, 12:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Unruh wrote:

>
> >If I am using a library or free AP to book a vacation
> > with personal info, credit card etc.
> >Would you rec using a 39.99 program along with
> > Vista with all the security running.
> >Or would Vista with all the security running be
> > enough?
> >Thanks.
>
> If you are jumping out of a plane, do you think a burning parachute is
> enough or would you advise a burning parachute with a crash helmet.

This is nonsensical gibberish. Vista isn't a burning anything, and you
have no idea whether or not the alleged 39.99 program is a helmet or
not.

Windows might be a security disaster out of the box, and it certainly
plays second fiddle to some other choices as far as security goes, but
it *can* be made secure and maintained that way with minimal effort
and a smattering of common sense. And it will *always* be more secure
to harden the underlying problems than it will be to put band aids over
them. A well configured Windows box in the hands of a modestly informed
user, even with no AV/firewall/etc, is more secure than a misconfigured
Windows box with hundreds of dollars of extra "security software" in
the hands of an inattentive or under informed user.


Posted by donnie on September 14, 2007, 10:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Good point.
I guess If you had the right size apples
they could weigh just as much as oranges.


>
> >If I am using a library or free AP to book a vacation
> > with personal info, credit card etc.
> >Would you rec using a 39.99 program along with
> > Vista with all the security running.
> >Or would Vista with all the security running be
> > enough?
> >Thanks.
>
> If you are jumping out of a plane, do you think a burning parachute is
> enough or would you advise a burning parachute with a crash helmet.
>
>
> >> Unruh wrote:
> >>
> >> >
> >> > >When using the Internet via WiFi at a public place such as a
> >library
> >> > >or cafe, it is conceivable that the people running the router
> >> > >could be capturing all of your transmissions and therefore
> >> > >could be recording your name, account numbers, etc.
> >> >
> >> > Use ssh.
> >>
> >> This doesn't really add anything over a simple SSL connection.
> >>
> >> > But the greater danger is taht they have put trojaned files onto
the
> >> > computers. Thus you cannot really trust the puttyssh they
installed
> >>
> >> The scenario is using public APs not kiosks. You're using your own
> >> software and machine.
> >>
> >> As long as you're not foolish enough to disable security warnings,
and
> >> pay attention to them, there's nothing at all dangerous about using
> >> sensitive Internet services from WiFi access points. It's safer
than
> >> handing your credit card to the flunkie behind the counter when
youpay
> >> for that double mocha latte. Your local library or Starbucks is no
> >more
> >> or less trustworthy than your ISP, and your home broadband
connection
> >> can be "sniffed" by your neighbors as easily as your wireless
> >> connection at the AP in many cases.
> >>
> >> That's why end to end encryption exists folks, to make that
sniffing
> >an
> >> exercise in futility. The only thing a onlooker can learn is where
you
> >> do your business, and contrary to what someone posted things like
Tor
> >> not only add a layer of encryption similar to SSL/HTTPS, they also
> >> remove that piece of information from the equation. An HTTPS
> >connection
> >> made through the Tor network is 100% secure no matter where you are
or
> >> what you're doing when they're use properly.
> >>
> >> > for example, or even the keyboard, since that could be captured.
> >> > If it is your own computer, then use ssh, and do not use web
> >> > browsers.
> >>
> >> Huh?
> >>
> >> Then how in the heck are you going to actually do anything?
> >>
> >> >
> >> >
> >> >
> >> > >Are there ways to prevent or minimize this hazard?
> >> >
> >> > >For example, would it help to use something like Torpark?
> >> >
> >> > >What would you recommend?
> >> >
> >>
>


Posted by Unruh on September 13, 2007, 6:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>Unruh wrote:

>>
>> >When using the Internet via WiFi at a public place such as a library
>> >or cafe, it is conceivable that the people running the router
>> >could be capturing all of your transmissions and therefore
>> >could be recording your name, account numbers, etc.
>>
>> Use ssh.

>This doesn't really add anything over a simple SSL connection.

What simple ssl connection? Wireless access points do not have simple ssl
connections.


>> But the greater danger is taht they have put trojaned files onto the
>> computers. Thus you cannot really trust the puttyssh they installed

>The scenario is using public APs not kiosks. You're using your own
>software and machine.

Fine. That was not clear.


>As long as you're not foolish enough to disable security warnings, and
>pay attention to them, there's nothing at all dangerous about using
>sensitive Internet services from WiFi access points. It's safer than
>handing your credit card to the flunkie behind the counter when youpay
>for that double mocha latte. Your local library or Starbucks is no more

Untrue. The danger is localised then. It is that flunky who could subvert
your credit card. You know who he is. In the case of a net break it could
be someone in Bulgaria or Tibet. That is absolutely no comeback making the
potential cost of buggering you zero in that case, while it is high in th
ecase of your flunky.


>or less trustworthy than your ISP, and your home broadband connection
>can be "sniffed" by your neighbors as easily as your wireless
>connection at the AP in many cases.

Not if you run some decent encryption on your home machine.


>That's why end to end encryption exists folks, to make that sniffing an

End to end needs two ends. Most web sites have only one end, yours. The
other end is open.

>exercise in futility. The only thing a onlooker can learn is where you
>do your business, and contrary to what someone posted things like Tor
>not only add a layer of encryption similar to SSL/HTTPS, they also
>remove that piece of information from the equation. An HTTPS connection
>made through the Tor network is 100% secure no matter where you are or
>what you're doing when they're use properly.

>> for example, or even the keyboard, since that could be captured.
>> If it is your own computer, then use ssh, and do not use web
>> browsers.

>Huh?

>Then how in the heck are you going to actually do anything?

You think people cannot do any thing without web browsers?





Posted by Anonymous on September 14, 2007, 12:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Unruh wrote:

> >> >When using the Internet via WiFi at a public place such as a
> >> >library or cafe, it is conceivable that the people running the
> >> >router could be capturing all of your transmissions and therefore
> >> >could be recording your name, account numbers, etc.
> >>
> >> Use ssh.
>
> >This doesn't really add anything over a simple SSL connection.
>
> What simple ssl connection? Wireless access points do not have simple
> ssl connections.

Nor do they have SSH connections, however either one will make
sniffing public access points a fruitless undertaking from the POV of
that sort of attacker. The advantage to HTTPS/SSL is that it's end to
end, and ultimately available to users with modern software. They don't
have to do anything in fact but be attentive to some hard to miss
warnings.

SSH on the other hand is normally employed as a "tunnel" for other
traffic in this scenario, and that protection end precisely at the point
the SSH server converts encrypted traffic to plaintext. Everything
between the SSH server and a final destination is 100% out in the open.

You do seem to be confused about connections, access, and which security
measures address the various problems associated with "doing business"
over the net.

> >> But the greater danger is taht they have put trojaned files onto
> >> the computers. Thus you cannot really trust the puttyssh they
> >> installed
>
> >The scenario is using public APs not kiosks. You're using your own
> >software and machine.
>
> Fine. That was not clear.

It wasn't only clear, it was specifically stated.

> >As long as you're not foolish enough to disable security warnings,
> >and pay attention to them, there's nothing at all dangerous about
> >using sensitive Internet services from WiFi access points. It's
> >safer than handing your credit card to the flunkie behind the
> >counter when youpay for that double mocha latte. Your local library
> >or Starbucks is no more
>
> Untrue. The danger is localised then. It is that flunky who could
> subvert your credit card. You know who he is. In the case of a net
> break it could be someone in Bulgaria or Tibet. That is absolutely no
> comeback making the potential cost of buggering you zero in that
> case, while it is high in th ecase of your flunky.

Again, you seem confused regarding the identification of threats and
how to mitigate risks. An SSL connection secures traffic between
you and a vendor. Only two parties are privy to details like account
numbers, names, credit card info passwords, etc. When you physically
hand your credit card to a teller you're introducing a third party, so
in reality your statement about localization is exactly the opposite of
fact because you've increased your potential points of failure by 100%.
And that doesn't even take into consideration other casual observers
like the other customers in line waiting to pay for their double mocha
late fix. ;)

> >or less trustworthy than your ISP, and your home broadband connection
> >can be "sniffed" by your neighbors as easily as your wireless
> >connection at the AP in many cases.
>
> Not if you run some decent encryption on your home machine.

Wrong.

An SSH server or other encrypted "proxy" on your home machine leaves
egress traffic twisting in the wind. Everything is secured up to that
point, but between your home machine and XYZ-Corp all your data is
free for the taking.

Of course the typical scenario is tunneling SSL/encrypted traffic
through that encrypted SSH connection to your home server, so the
traffic is secure either way. In other words, the SSH/proxy tunnel adds
nothing significant to the equation in the context being discussed.

> >That's why end to end encryption exists folks, to make that sniffing
> >an
>
> End to end needs two ends. Most web sites have only one end, yours.
> The other end is open.

Complete nonsense.

SSL encrypted connections are true end to end encryption. Data is
encrypted before it leaves either end, and not decrypted until it
reaches its destination, regardless of which way it's flowing.

Please do some basic research.

> >exercise in futility. The only thing a onlooker can learn is where
> >you do your business, and contrary to what someone posted things
> >like Tor not only add a layer of encryption similar to SSL/HTTPS,
> >they also remove that piece of information from the equation. An
> >HTTPS connection made through the Tor network is 100% secure no
> >matter where you are or what you're doing when they're use properly.
>
> >> for example, or even the keyboard, since that could be captured.
> >> If it is your own computer, then use ssh, and do not use web
> >> browsers.
>
> >Huh?
>
> >Then how in the heck are you going to actually do anything?
>
> You think people cannot do any thing without web browsers?

Of course they can. But here again you're completely ignoring context.
A vast majority of net traffic is web based, and almost all of the rest
can be easily secured with an "S" version of a given protocol.

SSH is very useful for a lot of things. I use it every single day in
fact to administer remote machines, tunnel sensitive traffic into local
networks (Webmin, router administration, etc.), and simply proxy
traffic that would otherwise be rejected like the connection to the ISP
news server I used to read your posts. :) But for secure connections to
things like your Citibank or Amazon account for example, it's utterly
useless.

None of those types of services run their own SSH servers as far as I'm
aware, in fact doing so would constitute an additional security risk.
So if you're connecting to those types of services insecurely (non-SSL
connections) through an SSH server you're being nothing but a very
misguided fool. And if you are tunneling SSL/TLS encrypted traffic
through a home SSH server you're not adding any significant security to
any transactions you might be making.

The notable and already stated exception of course is the fact that
you're obfuscating where you do business from observers at the AP. For
most people this isn't any concern at all. It's simply not a State
secret that you buy books from Amazon, or bank at Wachovia. If that IS
a priority then by all means use the proper tools to mitigate that
risk. But don't waste time and/or lull yourself into a false sense of
security by misapplying perfectly good tools to the *wrong* job.


Similar ThreadsPosted
Protect Your Online Privacy And Internet Security November 6, 2004, 1:46 pm
How to protect my website? February 3, 2005, 8:45 pm
how to protect confidential document August 28, 2007, 2:40 am
How to protect your Online Customers' passwords? May 27, 2006, 12:26 pm
Actions the Government Should Take to Protect Information June 17, 2006, 2:23 pm
Is there a way to protect read-only files from copying/theft? June 4, 2004, 8:18 pm
ANN: Folder Castle 2.2 - Protect Your Files and Peace of Mind July 9, 2008, 2:34 am
Motorola Biometrics Solution Will Help Protect Delaware Citizens with Improved Identity Technology April 11, 2006, 2:22 am
Detecting Wifi networks December 20, 2004, 10:41 am
Is it safe to use a stranger's WiFi channel ? November 16, 2005, 2:04 am

The site map in XML format XML site map

Contact Us | Privacy Policy