magicbus wrote:
rwbradley wrote:
bwanshoom wrote:
dshinnick, look up a man-in-the-middle attack. If someone controls your connection to the internet (e.g. they own the router) they can make you think you're talking to your bank, but you're not. It's not hard to fake a website that looks like BOA, for example. Phishing attackers do this all the time. And most people wouldn't know a good certificate from a bad one. There have been numerous cases of certificate authorities (someone your browser trusts implicitly by default even though you've never heard of 99% of them. Do you trust the Chinese government? Your browser did...until last month) being hacked and issuing bogus but perfectly valid certificates.
There are malicious hotspots that do this kind of thing. Someone on this forum mentioned they owned a WiFi Pineapple which does everything I just mentioned.
As has been noted numerous times in this thread, the likelihood of this occurring is quite small but it's non-zero. Depending on how paranoid or cautious you are you might care or you might not.
Well described. I think you stated it far more clearly than my feeble attempts.
Well now hold on... you can't have it both ways! You agree 100% that hacking certificates is occurring all the time and Man In the Middle attacks are easy BUT not where it applies to VPN's?
rwbradley wrote:
1) Paid VPN services are based on a model of trust, just like Certificate Authorities who issue the SSL certificates to the banks, or even the Banks themselves. They would go out of business if they are not trustworthy.
So it's OK to trust certificates for a VPN but not for banks :? You wholeheartedly agree that a MIM attack could make me think I am talking to BOA but the same MIM attack can't pretend to be my VPN service? I must be missing some subtle difference!
Dave
Please reread your quote, the answer is right there. What I agreed to is his description including but not limited to "the likelihood of this occurring is quite small but it's non-zero" Nowhere in any of the previous posts did I or anyone say it is happening all the time, we explained how easy it is to do in various different wordings. Just because your house has never been robbed and you keep your doors unlocked every night does not mean you are secure, it just means you live in a safe neighborhood or have been lucky so far. My house or none of my neighbors that I speak to have ever been robbed, but I am not about to leave my doors unlocked because it makes it too easy for some bored 16 year old. And yes I understand that a lock will not stop a robbery, but it will mean the thief will most likely move on to the next house and look for an easier target.
Re VPNs. I am not about to write pages of information on VPN's and how IPSEC works vs SSL. Hint the difference is massive, the types of encryption used, the methods of sharing keys etc. IPSEC VPN's are significantly more secure and have no known exploits to them unless using an older less secure encryption algorithm and use an entirely different trust model than a secure website does. I will concede that you cannot trust anything fully on the internet, but you sure can trust some things more than others, IPSEC VPN's are one that you can trust more than the SSL encryption your Bank uses. The technical aspects of this is significant and I will loose most of the readers if I try to explain it. The point of mine an other responses was to illustrate in laymen terms to those who are not a CISSP and CEH like myself, so that others can benefit from the years or decades of experience that some who have responded have, without needing a Phd in Computer Science to understand it.
At this point the OP has thanked everyone for their responses and made a decision based on the recommendations. The topic has been explained numerous times, in different ways, by a number of different people. So this thread does not continue to go around in circles 6 more times, I suggest we agree to disagree and move on with our lives. I will be unsubscribing to this thread and will have no further comments on the topic.