Re: Can SSL sessions be compromised?



Anne & Lynn Wheeler <lynn@xxxxxxxxxx> writes:

comphelp@xxxxxxxxx (Todd H.) writes:
Specify a version level of SSL (greater than known-weak SSL v 2.0)
that this applies to, or a specific implementation's flaw, cite

re:
http://www.garlic.com/~lynn/2007g.html#32 Can SSL sessions be compromised?
http://www.garlic.com/~lynn/2007g.html#38 Can SSL sessions be compromised?

SSL is suppose to do two things ... 1) are you really talking to the
webserver that you think you are talking to and 2) hide/encrypt
information during transmission.

the attacks that I'm aware have been with regard to the first item
... including allowing various kinds of MITM-attacks (as mentioned
in previous posts).

recent post about MITM-attack
http://www.garlic.com/~lynn/aadsm26.htm#47 SSL MITM-attacks make the news

as well blog discussion

THREATWATCH: MITB SPOTTED: MITM OVER SSL FROM WITHIN THE BROWSER
https://financialcryptography.com/mt/archives/000884.html

MITM, is indeed relatively simple with SSL.

The silly post I replied which you trimmed implied weakness in the
encryption, which if it actually exists must be a compromise that is
very tightly held.

Best Regards,
--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: Can SSL sessions be compromised?
    ... which if it actually exists must be a compromise that is ... http://www.garlic.com/~lynn/2007g.html#32 Can SSL sessions be compromised? ... the encryption part, by comparison, is much more reliable and trusted. ... encryption (if you weren't trying for MITM countermeasures). ...
    (comp.security.misc)
  • Re: Unencrypted Email
    ... Would you use the same argument for SSL for say, internet banking. ... someone would need to compromise one of the mail servers ...
    (Security-Basics)
  • Re: [fw-wiz] Re: Firewalls breaking stuff: [Was re: fwtk]
    ... >Let's say a client of yours has a requirement to offer remote email access by ... compromise approach that is as simple as possible ... SSL accelerators are _performance_ tools not security tools. ... An SSL implementation is an SSL implementation; ...
    (Firewall-Wizards)
  • Re: Can SSL sessions be compromised?
    ... http://www.garlic.com/~lynn/2007g.html#32 Can SSL sessions be compromised? ... including allowing various kinds of MITM-attacks (as mentioned ... in previous posts). ...
    (comp.security.misc)
  • Re: SSL vs HTTPS
    ... Eduardo wrote: ... > Could anyone explain to me the difference between SSL and HTTPS? ... SSL over HTTP, the actual implementation of the SSL protocol for HTTP. ... It includes things like the port number used for SSL sessions (by ...
    (comp.security.ssh)