Re: Secure Yahoo logins

From: David Schwartz (davids@webmaster.com)
Date: 08/28/02


From: David Schwartz <davids@webmaster.com>
To: <mail@blazde.co.uk>, <vuln-dev@securityfocus.com>
Date: Tue, 27 Aug 2002 21:02:57 -0700


>>My other question is if the passwords are encrypted why do they offer a
>>secure login
>>option? How does that increase security, other than adding a brief ssl
>>session.

        Because otherwise a man-in-the-middle could serve you a web page that didn't
do any fancy hashing. ;)

        DS



Relevant Pages

  • [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
    ... For general information regarding FreeBSD Security Advisories, ... FreeBSD includes software from the OpenSSL Project which implements SSL ... The SSL version 3 and TLS protocols support session renegotiation without ...
    (freebsd-announce)
  • FreeBSD Security Advisory FreeBSD-SA-09:15.ssl
    ... For general information regarding FreeBSD Security Advisories, ... FreeBSD includes software from the OpenSSL Project which implements SSL ... The SSL version 3 and TLS protocols support session renegotiation without ...
    (Bugtraq)
  • FreeBSD Security Advisory FreeBSD-SA-09:15.ssl [REVISED]
    ... For general information regarding FreeBSD Security Advisories, ... FreeBSD includes software from the OpenSSL Project which implements SSL ... The SSL version 3 and TLS protocols support session renegotiation without ...
    (FreeBSD-Security)
  • [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-09:15.ssl [REVISED]
    ... For general information regarding FreeBSD Security Advisories, ... FreeBSD includes software from the OpenSSL Project which implements SSL ... The SSL version 3 and TLS protocols support session renegotiation without ...
    (freebsd-announce)
  • FreeBSD Security Advisory FreeBSD-SA-09:15.ssl [REVISED]
    ... For general information regarding FreeBSD Security Advisories, ... FreeBSD includes software from the OpenSSL Project which implements SSL ... The SSL version 3 and TLS protocols support session renegotiation without ...
    (Bugtraq)