Computer hack allows HTTPS session hijacking

MplsBob

Senior member
Jul 30, 2000
340
0
0
The ARS Technica site has an article about a successful hacking of the Hypertext Transfer Protocol Secure (HTTPS).

HTTPS protects us when we want secure Internet communication during online banking, when we use our credit card, etc.

The hack has been named CRIME. CRIME works only when both the browser and server support TLS compression or SPDY, an open networking protocol used by both Google and Twitter. Microsoft's Internet Explorer, Google's Chrome and Mozilla's Firefox browsers are all believed to be immune to the attack.

Question: Are there any steps we can take to reduce our vulnerability to this?
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,054
197
116
Not sure really, probably not much besides perhaps using opera for secure sites. I'm pretty sure everyone is working on a fix that will be out asap.
 

cl-scott

ASUS Support
Jul 5, 2012
457
0
0
Is there maybe a typo in there? You state IE, Chrome, and Firefox are thought to be immune, then want to know what can be done to mitigate the risk. So if you're an Opera or Safari user, you'd just switch to one of the supposed immune browsers.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,054
197
116
Yes, i think it was a typo. I read that all of those browsers are susceptible to this attack so I guess opera is not.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,541
419
126
Quote from - http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/

"CRIME works only when both the browser and server support TLS compression or SPDY, an open networking protocol used by both Google and Twitter. Microsoft's Internet Explorer, Google's Chrome and Mozilla's Firefox browsers are all believed to be immune to the attack, but at time of writing smartphone browsers and a myriad of other applications that rely on TLS are believed to remain vulnerable".

End of Quote.

As you see, the main problem is Smart phone apps.

IMHO anyone who do Banking and other type of must be secure connection from his/her Smart Phone has to use to same phone to call ASAP a Psychiatrist and get a Mental Exam.

If one does not get it, there is a reason why Gov. and other agencies are using special Blackberries and Not your Telco. regular edition phones.



 
Last edited:

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Quote from - http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/

"CRIME works only when both the browser and server support TLS compression or SPDY, an open networking protocol used by both Google and Twitter. Microsoft's Internet Explorer, Google's Chrome and Mozilla's Firefox browsers are all believed to be immune to the attack, but at time of writing smartphone browsers and a myriad of other applications that rely on TLS are believed to remain vulnerable".

End of Quote.

As you see, the main problem is Smart phone apps.

IMHO anyone who do Banking and other type of must be secure connection from his/her Smart Phone has to use to same phone to call ASAP a Psychiatrist and get a Mental Exam.

If one does not get it, there is a reason why Gov. and other agencies are using special Blackberries and Not your Telco. regular edition phones.


You omitted an important part:

Both Chrome and Firefox were susceptible until recently. Google and Mozilla released patches after the weaknesses were privately reported by Juliano Rizzo (@julianor) and Thai Duong, the researchers who devised the CRIME exploits. Internet Explorer was never vulnerable because it never supported SPDY (pronounced "speedy") or the TLS compression scheme known as Deflate.

As you can see, from a security perspective there is no real differentiation between mobile apps and desktop apps. Doing banking and other secure transactions on your phone is just as secure as doing them on a PC.

Blackberries are more secure because they're less functional, just like IE in this case.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,541
419
126
I am aware of it, security patches is part of our life.

However, what matter is the end result, the Desktop/Laptop Browsers can be patched the Mobile stay risky.

Functional or Not, it is secondary to the risk taken while using Mobiles for Banking and CC activities.


 
Last edited:

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
I am aware of it, security patches is part of our life.

However, what matter is the end result, the Desktop/Laptop Browsers can be patched the Mobile stay risky.

Functional or Not, it is secondary to the risk taken while using Mobiles for Banking and CC activities.



No, the mobile apps can be patched just as easily as well. I get updates for my mobile apps every day. A mobile computer is still a computer, the distinction you're drawing is unwarranted. Internet banking is equally risky regardless of the platform. Actually, in theory it's less risky because mobile environments are more controlled and thus have less under-vetted code in them.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |