BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: bill at horne.net (Bill Horne)
- Date: Sun, 07 Dec 2014 14:02:25 -0500
- In-reply-to: <5481D65F.7050104@gmail.com>
- References: <sjm8uirdxem.fsf@securerf.ihtfp.org> <BN3PR0401MB1204B299B351DFF7F2E85FBDDC7D0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjmlhmqcb1j.fsf@securerf.ihtfp.org> <BN3PR0401MB120492A5BDE4D3CEE0AECDD3DC7A0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uiqc7sw.fsf@securerf.ihtfp.org> <547E0FB3.3070005@gmail.com> <sjmy4qobui6.fsf@securerf.ihtfp.org> <547F3855.10106@gmail.com> <sjmtx1bbf7w.fsf@securerf.ihtfp.org> <5480856D.6050205@gmail.com> <20141204163645.GA11641@dragontoe.org> <54809327.5040802@gmail.com> <225b01d00fe5$dde00d40$99a027c0$@Polcari.com> <5480A14C.1080303@gmail.com> <CA+h9Qs5wWchqNJxCWQ4ty7RaFSd+JtfFS6hVQQF19-0O2ZnqDQ@mail.gmail.com> <5481D65F.7050104@gmail.com>
On 12/5/2014 10:59 AM, Richard Pieri wrote: > On 12/4/2014 11:42 PM, John Abreau wrote: >> On the other hand, if you accept the bad guy's poisoned DNS data: > > Long story short: Joe is screwed either way. Or I am depending on who > takes the fall. If someone is reprimanded or fired or even killed > because a security system is working as designed? That's a terrible > system. > No offense, but Joe might not have a choice: the hotel wants him to click on a user agreement, and so the box they've bought will intercept every DNS call and redirect it to their consent page before allowing Joe to connect to the net. I can't say if that's going to happen at Starbucks or [whereever], but it might. I don't know if that agreement gives the hotel/mega-corp permission to monitor emails as well as collect the click list, but MITM attacks require Joe to agree to accept an invalid certificate at some point, and it's possible to disable his ability to do so. End-to-end email encryption would prevent any monitoring of the email, and a corporate VPN would obviate the problem altogether. Some companies avoid the issue altogether by entering fixed IP addresses in VPN scripts - the only matching key is/should be at the VPN box/server, so there's no loss of flexibility, and IP addresses are cheap enough if the company wants to provide a backup. In any case, Joe's logs will verify that he made the attempt. Of course, theory and practice often differ in security, and we've all met mister "JustDoItOrYou'reFired" who likes to tell us to break the rules, but that isn't a technical problem. A well designed security suite will give Joe the option of sending his reports by encrypting them first with a few key clicks. FWIW. YMMV. Bill Horne -- E. William Horne 339-364-8487
- Follow-Ups:
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: Joe at Polcari.com (Joe Polcari)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: jabr at blu.org (John Abreau)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] DNSSEC
- Next by Date: [Discuss] free SSL certs from the EFF
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):