BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] comcast wifi question
- Subject: [Discuss] comcast wifi question
- From: bill.n1vux at gmail.com (Bill Ricker)
- Date: Thu, 6 Nov 2014 09:24:25 -0500
- In-reply-to: <f317a6efafe346ce86d7064639bdcd09@BN3PR0401MB1204.namprd04.prod.outlook.com>
- References: <545971EF.5030400@gmail.com> <545976F5.6040907@gmail.com> <545AC024.1000408@gmail.com> <f317a6efafe346ce86d7064639bdcd09@BN3PR0401MB1204.namprd04.prod.outlook.com>
Ned - Your comments on WiFi encryption and Insecurity of DNS are right on. But .. > If you're connecting to secure services, then your traffic is secure, even on the unencrypted wifi. Maybe. Maybe not. tl;dr - Google HTTPS *is* safe from MITM but *only* with Chrome so far. Rest of HTTPS not as much. If the hacker with control of the WiFi AP is working for an organization with control of any of the many Root CA certs built into your device/browser (Hong Kong Post Office, US DOD, Chinese Govt, ...), or illicit access to a leaked CA key, or can trick any of them into creating wildcard certs, the untrusted WiFi node can do MITM on your HTTPS session *silently*, no "bad cert" clickthru required.. Aside from VPN, the one defense today is host cert (actually CA) pinning. (Google properties have this via Chrome; internet draft recommending this for all site/browser pairs !). (I think Chromium is included in the above but not certain. One might hope Android native browser has the google pinning but also IDK without checking.) -- Bill Ricker bill.n1vux at gmail.com https://www.linkedin.com/in/n1vux
- Follow-Ups:
- [Discuss] comcast wifi question
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] comcast wifi question
- References:
- [Discuss] comcast wifi question
- From: eric.chadbourne at gmail.com (Eric Chadbourne)
- [Discuss] comcast wifi question
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] comcast wifi question
- From: eric.chadbourne at gmail.com (Eric Chadbourne)
- [Discuss] comcast wifi question
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] comcast wifi question
- Prev by Date: [Discuss] Revisiting VMWare ESX backup options
- Next by Date: [Discuss] Revisiting VMWare ESX backup options
- Previous by thread: [Discuss] comcast wifi question
- Next by thread: [Discuss] comcast wifi question
- Index(es):