RE: how can you verify that the site you get is not a fake?

From: Joel Jaeggli (joelja_at_darkwing.uoregon.edu)
Date: 06/06/05

  • Next message: Joel Jaeggli: "RE: how can you verify that the site you get is not a fake?"
    Date: Mon, 6 Jun 2005 10:27:34 -0700 (PDT)
    To: bedouglas@earthlink.net, For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    On Mon, 6 Jun 2005, bruce wrote:

    > matt, i unsderstand what you're saying...
    >
    > but i still don't see how this protects/allows a user to 'know' that th site
    > he's on is the correct site...
    >
    > as an example. i go to the verisign site (www.verisign.com) i can select the
    > verisign logo, which displays a pop-up. i read it, it looks good.. i think
    > i'm secure...
    >
    > however, there's nothing that i look at, that couldn't be forged/faked by
    > you or i with the right web app knowledge...

    No, that's the point, the cert is infeasible to forge.

    > i understand that the 'ssl/lock' is a function of the browser and is
    > supposed to be used to present details of the ssl certificate employed... i
    > also understand that the lock function is a component of the browser...
    > however, this asumes the user knows to click on the 'lock'. if i were to
    > provide a fake 'picture/icon' for the user to select, such that it displayed
    > the fake ssl information, in all likelyhood, the user wouldn't know the
    > difference..

    Social engineering is something that can only be prevent through
    vigilance.

    > -bruce
    >
    >
    > -----Original Message-----
    > From: fedora-list-bounces@redhat.com
    > [mailto:fedora-list-bounces@redhat.com]On Behalf Of Matthew Miller
    > Sent: Monday, June 06, 2005 6:16 AM
    > To: For users of Fedora Core releases
    > Subject: Re: how can you verify that the site you get is not a fake?
    >
    >
    > On Mon, Jun 06, 2005 at 06:05:58AM -0700, bruce wrote:
    >> but you still haven't addressed my problem/issue/question...
    >> and that's how do i as a user (not an app) know that this is the right
    >> site for the url i entered... my fear is that a malicious site, could
    >> simply fake the information he's providing, to 'look' like the actual/real
    >> site...
    >> and as of yet.. i can't craft a solution to this issue...
    >
    > You could trust us that it's very hard to fake the SSL information, and then
    > you could inspect that. (Double click on the little lock icon.) You'll see
    > something like:
    >
    > Web Site Identity Verified
    >
    > The web site www.bu.edu supports authentication for the page you are
    > viewing. The identity of this web site has been verified by Thawte
    > Consulting cc, a certificate authority you trust for this purpose.
    >
    >
    > In the Firefox advanced preferences, you can manage which certificate
    > authorities you trust.
    >
    >
    >
    > --
    > Matthew Miller mattdm@mattdm.org <http://www.mattdm.org/>
    > Boston University Linux ------> <http://linux.bu.edu/>
    > Current office temperature: 80 degrees Fahrenheit.
    >
    > --
    > fedora-list mailing list
    > fedora-list@redhat.com
    > To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    >
    >

    -- 
    --------------------------------------------------------------------------
    Joel Jaeggli  	       Unix Consulting 	       joelja@darkwing.uoregon.edu
    GPG Key Fingerprint:     5C6E 0104 BAF0 40B0 5BD3 C38B F000 35AB B67F 56B2
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Joel Jaeggli: "RE: how can you verify that the site you get is not a fake?"

    Relevant Pages

    • RE: how can you verify that the site you get is not a fake?
      ... provide a fake 'picture/icon' for the user to select, ... You could trust us that it's very hard to fake the SSL information, ... Web Site Identity Verified ... a certificate authority you trust for this purpose. ...
      (Fedora)
    • Re: Safe e-mail?
      ... |> scw-media.de, and their web site is www.scw-webshop24.de, so it ... I Googled for "type face", ... | I find the Web Of Trust does not work at all for me, ... | signature for him, and he for me, but we have no one in common, so the ...
      (comp.os.linux.misc)
    • Re: Program that disables my anti-virus
      ... >> Also I can't visit the symantec web site or other various anti virus websites. ... You can't trust the system any more. ... know how to handle this program: uninstall it. ...
      (microsoft.public.security)
    • Re: huge party tonight as alert investers look set to win billions on abduls piss poor judgement....
      ... NOW, after having FAKED HIS OWN DEATH, cleared off from his Cambridge ... After all the trouble this FAKE went through faking his own death. ... But keep on posting all your rubbish... ... Talking of his 'web site', (He'll start and get twitchy now, and take ...
      (uk.politics.misc)
    • Re: how to redeploy .net app without iisreset
      ... Although it doesn't lock the DLLs, it seems to lock the parent directory ... locks and then I could rename the web root directory. ... we found that we had to stop the Web site before uploading a new ...
      (microsoft.public.inetserver.iis)