Re: Secure file transfer
- From: "Sebastian G." <seppi@xxxxxxxxx>
- Date: Fri, 21 Dec 2007 01:02:51 +0100
evans@xxxxxxxxxxxxxxxxxxx wrote:
1. When I use Auth SSL to connect, I see this message in the session
script:
AUTH SSL
500 This security scheme is not implemented
Does that mean that my login and password are in clear text? And/or
that any files I transfer are also vulnerable?
If you're in implicit SSL mode: No, since you're already running everything within an SSL session (and therefore trying to establish another SSL session fails, intentionally). I guess this is what your tech guys tried to communicate to you.
On the other, even in explitic SSL mode this is not the end of the world, since there're a some othe rknown other variants to initiate SSL mode (like MODE SSL and PROTP).
2. Web-based services such as Yahoo Mail protect the login (https://
shows up on the URL bar when you log in), but thereafter it is
straight http://. This means that any mail I send or receive would be
visible as clear text to a sniffer, correct?
No, because they're target URL of their login forms is an https:// URL.
Yes, because this is still a problem since this form, send over an unsecured HTTP connection, could be spoofed, and without looking at the websites HTML code you don't know to which URL the form is pointing to (and after sending the data it might be too late).
> If that's the case, why isn't it a huge problem?
It is, these idiots just don't want to acknowledge the problem.
> Is it simply a matter of too much email, too few hackers?!
No, it's about the additional processing cost and therefore hardware cost.
.
- References:
- Secure file transfer
- From: evans
- Re: Secure file transfer
- From: Sebastian G.
- Re: Secure file transfer
- From: Unruh
- Re: Secure file transfer
- From: Sebastian G.
- Re: Secure file transfer
- From: Gerald Vogt
- Re: Secure file transfer
- From: Sebastian G.
- Re: Secure file transfer
- From: Gerald Vogt
- Re: Secure file transfer
- From: evans
- Secure file transfer
- Prev by Date: Re: wireless security
- Next by Date: FBI aims for world's largest biometrics database
- Previous by thread: Re: Secure file transfer
- Next by thread: Re: Secure file transfer
- Index(es):
Relevant Pages
|
|