Forgot your password?
typodupeerror
Encryption

+ - HTTPS encryption is too little too late->

Submitted by DeFender1031
DeFender1031 (1107097) writes "So it's time to pay the bills. You go to your bank's website to transfer some money, you log in, and your account information is completely secure because the bank's servers establish an HTTPS connection with your browser, right? WRONG! This article describes in plain english how a man-in-the-middle can be performed prior to an HTTPS handshake, neutralizing any security precautions that might have been in place. The attack described here can be extended to any protocol where the server specifies whether to use a secure or insecure mode."
Link to Original Source
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

HTTPS encryption is too little too late

Comments Filter:

A committee is a life form with six or more legs and no brain. -- Lazarus Long, "Time Enough For Love"

Working...