Results 1 to 11 of 11

Thread: Understanding Security

  1. #1

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611

    Question

    I was browsing an eSecurity firms web site and go this message - does thgis mean that their site is not really secure of set up correctly? What are the risks?
    Attached Images Attached Images  

  2. #2

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611
    Other half of message
    Attached Images Attached Images  

  3. #3

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611
    To clarify - I'm not worried that something terrible is about to happen to me for visiting the site - but is their site vunerable? Can they be taken seriously as security consultants.

  4. #4
    New Member Jeff_1's Avatar
    Join Date
    Jan 2001
    Location
    Right behind you.
    Posts
    10

    Smile Umm..

    It doesnt exactly mean that the site is insecure.
    The certificate's are ways that your ISP or just your computer "trust" the content from that website.

    Certificate's are given to company's web site so they can be trusted to do things..like encryption..stuff like that.

    Not exactly sure though.
    Last edited by Jeff_1; Feb 22nd, 2001 at 11:12 AM.
    Tip of the Day

    Did you know...

    There are no tips available.

  5. #5

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611
    I think to point that I was thinking of was - if a certificate isn't traceable (as this one says it was) could it be a fake or altered?

    If it's a fake could it be on someone else's site just pretending to be the site it says it is.

    (For the sake of discussion let's be really paranoid about this)

  6. #6
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    Certificates need to be authenticated by a Certificate Authority such as Verisign before they're valid. Your message means that the certificate couldn't be verified as an authentically-created certificate.

    It's like the difference between writing a will and having a solicitor draw one up for you.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  7. #7
    New Member Jeff_1's Avatar
    Join Date
    Jan 2001
    Location
    Right behind you.
    Posts
    10

    Talking Yeah what he said

    I tried to say that but the mix of ephedra and caffinee kind of makes me jabber on and on..heh
    Tip of the Day

    Did you know...

    There are no tips available.

  8. #8

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611

    Smile

    Originally posted by parksie
    Certificates need to be authenticated by a Certificate Authority such as Verisign before they're valid. Your message means that the certificate couldn't be verified as an authentically-created certificate.

    It's like the difference between writing a will and having a solicitor draw one up for you.
    Nicely put! But isn't it really like someone at a funeral saying its "I found this will and the old codger's inhertiance is all MINE!!". If the will is drawn up by a good solicitor then there is a trusted third party to validate it. It is not then the source of the will is suspect. I guess - in principle - so is a site with a certificate that couldn't be verified as an authentically-created certificate. Is that right?

  9. #9
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    Yep.

    Although technically a Trusted Third Party (TTP) is a different thing -- they're someone else with your public/private key pair.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  10. #10

    Thread Starter
    Fanatic Member Kzin's Avatar
    Join Date
    Dec 2000
    Posts
    611
    So (hypothetically) what would be the worst case scenario for a certificate like that - what is the worst that could happen? Could a site with a certifiacte like that be fake (I doubt if the example one is - this is hypothetical remember!)

  11. #11
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    Browsing a secure website, not that much bad can happen. All it means is you can't be sure who's at the other end. Normally the certificate contains the destination address and this is validated. In this case it's just not guaranteed. You won't lose any in-transit security.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width