Slashdot Mirror


Perfect MITM Attacks With No-Check SSL Certs

StartCom writes "In a previous article I reported about Man-In-The-Middle attacks and spotlighted an example showing that they really happen. MITM attacks just got easier. In the attack described previously, untrusted certificates from an unknown issuer were used. Want to make the attack perfect with no error and a fully trusted certificate? No problem, just head over to one of Comodo's resellers. Screenshots and disclosure provided at the link."

8 of 300 comments (clear)

  1. Really now. by cp.tar · · Score: 4, Funny

    The example cited is "RESOLVED INVALID". The link to the "perfect attack" seems to be slashdotted. And at the time I started writing this comment, there have been no comments whatsoever.

    Does this mean that Slashdotters have all swarmed the link trying to find out how to execute the perfect attack? Are we seeing a new trend here, with people actually reading TFAs?

    Or is it that too many people have Greasemonkey scripts filtering out kdawson's posts?

    --
    Ignore this signature. By order.
    1. Re:Really now. by ghmh · · Score: 5, Funny

      Apparently the perfect attack is actually 'Slashdot in the Middle'

  2. Looks like DDOS beats all by 00_NOP · · Score: 2, Funny

    It had "0" comments when I started and I still could not RTFA

  3. Re:Don't do this at home by Anonymous Coward · · Score: 3, Funny

    I have a much bigger concern. Who certifies those who certify the certifiers?

  4. Re:Don't do this at home by gomiam · · Score: 2, Funny

    ...your local psychiatrist?

  5. Re:Don't do this at home by ScreamingCactus · · Score: 2, Funny

    Simple. We give the MITM attackers the power to certify the certifiers. That way we have a system of checks and balances.

    --
    The path to enlightenment is truly through homemade drugs!
  6. Re:Don't do this at home by kabloom · · Score: 2, Funny

    Nobody. They don't have an HTTPS site.

  7. Re:OK, which CA must leave the trusted list? by dubbreak · · Score: 2, Funny

    but yes, I think making and enforcing standards for CAs is a good role for the government.

    Which "the government" are you talking about here? ...

    I nominate Canada. They seem to be a respected world power. Everyone will be willing to listen to them.

    --
    "If you are going through hell, keep going." - Winston Churchill