Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Check if your company/ISP is intercepting your HTTPS traffic

  • 10-04-2013 05:42PM
    #1
    Closed Accounts Posts: 8,015 ✭✭✭


    Hi,

    Steve Gibson is a well known security expert who is the brains in the excellent "Security Now" podcast.

    He knocked up a web utility to help you detect whether your company might be intercepting your HTTPS traffic with a man-in-the-middle attack.

    ( installing the own root certificates, so they can create fake facebook/gmail etc certs )

    GRC Fingerprints link

    Basically he lists the HTTPS cert fingerprints of known websites, eg. Facebook.
    www.facebook.com	*.facebook.com	F5:6B:F2:44:63:B0:BD:61:36:C5:E8:72:34:6B:32:04:28:FF:4D:7C
    

    But you can put in your own website and he'll get the cert that his unintercepted site sees, eg.
    www.boards.ie *.boards.ie	C7:13:71:7A:A1:0B:CE:37:B1:77:46:FE:27:F1:58:A0:76:28:8D:42
    

    So then you go to https://www.boards.ie, view the cert in your browser and compare the fingerprints of the cert that YOU see, eg. in this case the SHA1 fingerprint matches, so I know that my company isn't intercepting the HTTPS traffic to boards.

    regards,
    CD
    Tagged:


Comments

  • Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭Khannie


    Nice one. Some security companies do offer that trusted man in the middle as a service.


  • Registered Users, Registered Users 2 Posts: 8,814 ✭✭✭BaconZombie


    Wait... When did Boards start using HTTPS?
    Hi,

    Steve Gibson is a well known security expert who is the brains in the excellent "Security Now" podcast.

    He knocked up a web utility to help you detect whether your company might be intercepting your HTTPS traffic with a man-in-the-middle attack.

    ( installing the own root certificates, so they can create fake facebook/gmail etc certs )

    GRC Fingerprints link

    Basically he lists the HTTPS cert fingerprints of known websites, eg. Facebook.
    www.facebook.com	*.facebook.com	F5:6B:F2:44:63:B0:BD:61:36:C5:E8:72:34:6B:32:04:28:FF:4D:7C
    

    But you can put in your own website and he'll get the cert that his unintercepted site sees, eg.
    www.boards.ie *.boards.ie	C7:13:71:7A:A1:0B:CE:37:B1:77:46:FE:27:F1:58:A0:76:28:8D:42
    

    So then you go to https://www.boards.ie, view the cert in your browser and compare the fingerprints of the cert that YOU see, eg. in this case the SHA1 fingerprint matches, so I know that my company isn't intercepting the HTTPS traffic to boards.

    regards,
    CD


  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 96,117 Mod ✭✭✭✭Capt'n Midnight


    Wait... When did Boards start using HTTPS?
    https://www.eff.org/https-everywhere does what it says on the tin.


    is OCSP still vulnerable to man in the middle attacks / is there another reliable way of verifying certs automatically ?


  • Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭Khannie




  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 96,117 Mod ✭✭✭✭Capt'n Midnight


    https everywhere also has options for the EFF SSL Observatory https://www.eff.org/observatory


  • Advertisement
  • Closed Accounts Posts: 8,015 ✭✭✭CreepingDeath


    https everywhere also has options for the EFF SSL Observatory https://www.eff.org/observatory

    Interesting, I've just enabled that.
    I had been using Https everywhere for boards as a matter of routine.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Wait... When did Boards start using HTTPS?

    I'm not sure if they want us to be using SSL just yet. They will keep re-directing you back you normal HTTP.


    el1dKhX.png


  • Closed Accounts Posts: 3,981 ✭✭✭[-0-]


    I'm not sure if they want us to be using SSL just yet. They will keep re-directing you back you normal HTTP.


    el1dKhX.png

    Yeah when I use https on boards the pages don't render properly.


Advertisement