Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > 2+2 Communities > Other Other Topics
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 05-13-2007, 09:55 PM
StevieG StevieG is offline
Senior Member
 
Join Date: Jan 2003
Location: b-more
Posts: 3,558
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

[ QUOTE ]
guids and n.s. are giving good advice.

I will add to what n.s. said though. Your bank, brokerage firm, reputable e-commerce sites, Gmail, etc, are all using encryption (you'll see a padlock in your browser) when you are handing off a password to them.

However many other sites where you use a password, including 2+2, are not encrypted when you hand off the password.

Therefore if you use the same password everywhere then that increases your risk when using wireless.

I suggest not using the same password everywhere, and certainly not using the same password for unencrypted sites that you use for encrypted sites with information you really want to protect.

[/ QUOTE ]
Reply With Quote
  #12  
Old 05-13-2007, 09:58 PM
guids guids is offline
Senior Member
 
Join Date: Oct 2005
Posts: 12,908
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

This caveat is, even though your bank, gmail, etc passwords are sent over ssl (encryption), it is fairly easy to get those passwords. What an attcker does is set up a fake website on his laptop, and impersonates the AP (what your laptops connects to), then he looks at all the information in unencrypted form, because his fake website doesnt use encryption, takes that info, sends it to its real destination over the internet, and transmits any response back to your computer. Hence the name man in the midddle


(your box)--------(his laptop)---------internet
Reply With Quote
  #13  
Old 05-13-2007, 10:00 PM
Howard Beale Howard Beale is offline
Senior Member
 
Join Date: Sep 2005
Posts: 3,170
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

[ QUOTE ]
guids and n.s. are giving good advice.

I will add to what n.s. said though. Your bank, brokerage firm, reputable e-commerce sites, Gmail, etc, are all using encryption (you'll see a padlock in your browser) when you are handing off a password to them.

However many other sites where you use a password, including 2+2, are not encrypted when you hand off the password.

Therefore if you use the same password everywhere then wireless might be very dangerous for you.

I suggest not using the same password everywhere, and certainly not using the same password for unencrypted sites that you use for encrypted sites with information you really want to protect.

[/ QUOTE ]

I use different passwords for every site that I need one for. If anybody steals my notebook I'm in trouble. However, there are only a couple that I use on encrypted sites and those I have memorized.

A basic question:

How does the encryption work when sending the info from MY computer to the bank's secure system? That's what I don't get. Does my computer somehow send out info that's encrypted w/o me knowing anything about it automatically?
Reply With Quote
  #14  
Old 05-13-2007, 10:03 PM
guids guids is offline
Senior Member
 
Join Date: Oct 2005
Posts: 12,908
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

yes, the webbrowser you are using has a built in transparent encrption, so even though you may not know it you are sending encrypted info at certan times, you can tell when if you see a little lock at the bottom of the screen in IE
Reply With Quote
  #15  
Old 05-13-2007, 10:14 PM
Jcrew Jcrew is offline
Senior Member
 
Join Date: Dec 2004
Posts: 302
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

Unless you have the habit of checking the security certificates of the websites, I would not do any sensitive logins while using a public WiFi station.
Reply With Quote
  #16  
Old 05-13-2007, 10:14 PM
gol4pro gol4pro is offline
Senior Member
 
Join Date: Apr 2005
Posts: 2,087
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

A+.
Reply With Quote
  #17  
Old 05-13-2007, 10:22 PM
Rootabager Rootabager is offline
Senior Member
 
Join Date: May 2005
Location: Lexington KY
Posts: 2,317
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

Should have bashed him over the head with a computer cave man style. Then drug one of the bitches working there out by her hair.
Reply With Quote
  #18  
Old 05-13-2007, 10:47 PM
DeadMoney_J DeadMoney_J is offline
Senior Member
 
Join Date: Feb 2006
Posts: 280
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

[ QUOTE ]
Howard,

I can't answer the wireless question, but I can recommend that you daisy chain your Claymores together if you decide to go the cave route. Hope this helps.

[/ QUOTE ]

QFT. One of the best and most practical pieces of advice that I've ever seen given in OOT.
Reply With Quote
  #19  
Old 05-13-2007, 11:13 PM
blutarski blutarski is offline
Senior Member
 
Join Date: Oct 2006
Location: iron fist, velvet glove
Posts: 3,654
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

They just found some ancient buddhist drawings in caves in Nepal.
Reply With Quote
  #20  
Old 05-14-2007, 03:53 AM
n.s. n.s. is offline
Senior Member
 
Join Date: Oct 2004
Location: t(\" t)
Posts: 2,185
Default Re: Sony Store guy tells me to go live in a cave. (long w/pics + a Q)

[ QUOTE ]
This caveat is, even though your bank, gmail, etc passwords are sent over ssl (encryption), it is fairly easy to get those passwords. What an attcker does is set up a fake website on his laptop, and impersonates the AP (what your laptops connects to), then he looks at all the information in unencrypted form, because his fake website doesnt use encryption, takes that info, sends it to its real destination over the internet, and transmits any response back to your computer. Hence the name man in the midddle


(your box)--------(his laptop)---------internet

[/ QUOTE ]

Good point - I never really thought of faking an access point to do this sort of attack. Would the attacker have to disable the real AP first somehow (DOS attack?) so that Howard's computer doesn't find the real one first? Or can it just beat it to the punch when the laptop searches for a DHCP server?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 01:32 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.