Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all,
Vanilla are planning an update to the site on April 24th (next Wednesday). It is a major PHP8 update which is expected to boost performance across the site. The site will be down from 7pm and it is expected to take about an hour to complete. We appreciate your patience during the update.
Thanks all.

Check if your company/ISP is intercepting your HTTPS traffic

  • 10-04-2013 5:42pm
    #1
    Closed Accounts Posts: 8,016 ✭✭✭CreepingDeath


    Hi,

    Steve Gibson is a well known security expert who is the brains in the excellent "Security Now" podcast.

    He knocked up a web utility to help you detect whether your company might be intercepting your HTTPS traffic with a man-in-the-middle attack.

    ( installing the own root certificates, so they can create fake facebook/gmail etc certs )

    GRC Fingerprints link

    Basically he lists the HTTPS cert fingerprints of known websites, eg. Facebook.
    www.facebook.com	*.facebook.com	F5:6B:F2:44:63:B0:BD:61:36:C5:E8:72:34:6B:32:04:28:FF:4D:7C
    

    But you can put in your own website and he'll get the cert that his unintercepted site sees, eg.
    www.boards.ie *.boards.ie	C7:13:71:7A:A1:0B:CE:37:B1:77:46:FE:27:F1:58:A0:76:28:8D:42
    

    So then you go to https://www.boards.ie, view the cert in your browser and compare the fingerprints of the cert that YOU see, eg. in this case the SHA1 fingerprint matches, so I know that my company isn't intercepting the HTTPS traffic to boards.

    regards,
    CD
    Tagged:


Comments

  • Moderators, Technology & Internet Moderators Posts: 37,485 Mod ✭✭✭✭Khannie


    Nice one. Some security companies do offer that trusted man in the middle as a service.


  • Registered Users Posts: 8,811 ✭✭✭BaconZombie


    Wait... When did Boards start using HTTPS?
    Hi,

    Steve Gibson is a well known security expert who is the brains in the excellent "Security Now" podcast.

    He knocked up a web utility to help you detect whether your company might be intercepting your HTTPS traffic with a man-in-the-middle attack.

    ( installing the own root certificates, so they can create fake facebook/gmail etc certs )

    GRC Fingerprints link

    Basically he lists the HTTPS cert fingerprints of known websites, eg. Facebook.
    www.facebook.com	*.facebook.com	F5:6B:F2:44:63:B0:BD:61:36:C5:E8:72:34:6B:32:04:28:FF:4D:7C
    

    But you can put in your own website and he'll get the cert that his unintercepted site sees, eg.
    www.boards.ie *.boards.ie	C7:13:71:7A:A1:0B:CE:37:B1:77:46:FE:27:F1:58:A0:76:28:8D:42
    

    So then you go to https://www.boards.ie, view the cert in your browser and compare the fingerprints of the cert that YOU see, eg. in this case the SHA1 fingerprint matches, so I know that my company isn't intercepting the HTTPS traffic to boards.

    regards,
    CD


  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 90,659 Mod ✭✭✭✭Capt'n Midnight


    Wait... When did Boards start using HTTPS?
    https://www.eff.org/https-everywhere does what it says on the tin.


    is OCSP still vulnerable to man in the middle attacks / is there another reliable way of verifying certs automatically ?


  • Moderators, Technology & Internet Moderators Posts: 37,485 Mod ✭✭✭✭Khannie




  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 90,659 Mod ✭✭✭✭Capt'n Midnight


    https everywhere also has options for the EFF SSL Observatory https://www.eff.org/observatory


  • Advertisement
  • Closed Accounts Posts: 8,016 ✭✭✭CreepingDeath


    https everywhere also has options for the EFF SSL Observatory https://www.eff.org/observatory

    Interesting, I've just enabled that.
    I had been using Https everywhere for boards as a matter of routine.


  • Closed Accounts Posts: 2,267 ✭✭✭ Owen Careful Rash


    Wait... When did Boards start using HTTPS?

    I'm not sure if they want us to be using SSL just yet. They will keep re-directing you back you normal HTTP.


    el1dKhX.png


  • Closed Accounts Posts: 3,981 ✭✭✭[-0-]


    I'm not sure if they want us to be using SSL just yet. They will keep re-directing you back you normal HTTP.


    el1dKhX.png

    Yeah when I use https on boards the pages don't render properly.


Advertisement