Re: HotSpot Security



In article <84lkhrr8id.fsf@xxxxxxxxx>, comphelp@xxxxxxxxx (Todd H.)
wrote:

Kurt Ullman <kurtullman@xxxxxxxxx> writes:

In article <84tzwfr9xc.fsf@xxxxxxxxx>, comphelp@xxxxxxxxx (Todd H.)
wrote:



So... if you are careful to verify certificates and have your web
browser config'd to not accept sslv2 certs I'd say yer secure enough.
Have your guard up.

So, if I get a certificate is expired or not what it is supposed
to be warning I just run in the opposite direction? Especially if they
aren't showing up at home.

Right.

Anything special with a MacBook, or should I go ask this question on
one of the Apple groups?

They do pretty well so long as you have been applying the loads of
patches apple's been issuing. There are low level wireless issues
with mac's and pc's as well that got a lot of press at the security
cons last year and I think those have been patched, though that's not
to say that 0day exploits on similar vulns aren't out there, your odds
of getting hit with one at a tpyical cafe are fairly low.

The security of SSL relies a lot of the user doing smart things with
security warnings, so be diligent. :-) So many folks just click to
make dialog boxes happy and don't read anything, and in that there are
problems. :-)

Thanks. I generally worry about certificate stuff even when I am home
and non-wireless directly into the modem. Paranoia runs VERY deep
outside the house. (g).
.



Relevant Pages

  • RE: Checkpoint smart defance as IPS
    ... "security is to increase difficulty level for an attack." ... Security is a function of survivability, ... you can validate which certificate was used is. ... intercept *any* SSL/TLS communication in the world, ...
    (Security-Basics)
  • [NT] Flaw in Outlook 2002s Way of Handling V1 Exchange Server Security Certificates Leads To Informa
    ... Beyond Security would like to welcome Tiscali World Online ... Encryption is used to prevent parties other ... Outlook uses public key certificates to facilitate the exchange of the ... there are other certificate options including V1 Exchange Server Security ...
    (Securiteam)
  • Re: Embedding Simple MFC GUI app into website
    ... particular technology is "evil" goes beyond common sense and increases ... his denouncement of ActiveX and Java (and Flash, ... ActiveX, in particular, is an antipattern for security. ... Since you must obtain a certificate for code signing from the trusted ...
    (microsoft.public.vc.mfc)
  • Re: Auto Enrollment not working for one DC
    ... Windows Server 2003 SP1 introduces enhanced default security settings for the DCOM protocol. ... Windows Server 2003 Certificate Services provides enrollment and administration services by using the DCOM protocol. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Auto Enrollment not working for one DC
    ... I was already aware of the post SP1 problem with the CERTSVC_DCOM_ACCESS ... Certificate Services: Effects of security enhancements to the DCOM protocol ...
    (microsoft.public.windows.server.active_directory)