Re: Best secure surfing solution

From: Colonel Flagg (colonel_flagg_at_NOSOUPFORJ00internetwarzone.org)
Date: 01/31/04


Date: Fri, 30 Jan 2004 20:50:58 -0500

In article <f86efd4e.0401301646.3729e776@posting.google.com>, lgst036
@hotmail.com says...
> Hi,
>
> I would be grateful if someone could give me some advice.
> Not wanting my ISP or employer to see confidential emails and surfing,
> I have set up a service with companies providing secure web browsing
> (Idzap, the cloak, etc). So my web browser is using https using
> certificates from the company offering this service.
> I have read about possibilities of intercepting the https with "man in
> the middle" or maybe other techniques.
> How difficult it is for an ISP or my company&#8217;s network
> administrator to do that. Translated in money, how much would they
> need to spend to do that.
> Are there any better solutions, maybe a VPN service, Kerberos setup or
> anything else possible.
> Of course the above assumes that the secure service provider is
> trusted on which I would be keen to find any of their commonly known
> policies. (maybe suggestions)
>
> Many thanks
>
> George
>

other than the money involved in paying a good sysadmin his/her wages,
it can be done for free. keep a watch on your certificates, have your
client authenticate the cert and question any cert change. reverify with
the issuing agency and make sure signatures are correct.

-- 
Colonel Flagg
http://www.internetwarzone.org/
Privacy at a click:
http://www.cotse.net 
Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."
"...I see stupid people."


Relevant Pages

  • Re: Best secure surfing solution
    ... So my web browser is using https using ... > certificates from the company offering this service. ... Translated in money, how much would they ... client authenticate the cert and question any cert change. ...
    (alt.computer.security)
  • Re: How are you guys allowing OWA?
    ... enable HTTPS, or is there something else I need to do? ... Configure Folder or Web Site to Use SSL/HTTPS ... Accept client certificates. ...
    (microsoft.public.exchange2000.admin)
  • Re: Fedora home server using core 9
    ... various free projects see the need to use HTTPS, ... They'll get cheaper, or free, certificates ... money to someone like Verisign to assert that they're who they claim to ... Some just can't afford to do that. ...
    (Fedora)
  • Re: https confusion
    ... Can someone point me to a explanation of how https ... authorized users. ... although certificates ... signed by any certificate authority the server trusts, ...
    (comp.os.linux.security)
  • Re: Certificates (MCSE,CCNA,...)
    ... Subject: Certificates ... I used the Todd Lammle CCNA study book and scored ... >>: money on obtaining ... > Send FREE Valentine eCards with Yahoo! ...
    (Security-Basics)