Re: ecommerce / ssl over 3g ?
- From: Geoff Winkless <usenet-at-geoff-dot-dj@[127.0.0.1]>
- Date: Wed, 23 Nov 2005 16:00:20 +0000
Mike H wrote:
IIRC, as SSL is initiated, the client requests a key from the site. The proxy, sitting in the middle of this exchange, grabs this request, and requests one from the site itself instead. This way it gets the key! It then sends the response on to the client.
This is perfectly possible: however your proxy will not be able to re-encode the stream since it doesn't know the private key.
The only way (as I said before) for a proxy to intercept a request in this way is for it to pass the request to the server, decrypt it and then re-encrypt in its own SSL channel - at which point the encrypting certificate would not match the site certificate and the browser would complain bitterly.
If what you said were true then a Man-In-The-Middle attack would be a piece of cake and SSL would be a complete waste of time.
The only way 3 could make this work is by having their own key set as a trusted signing authority in every single client which would be accessing the internet through their proxy, including every browser on a computer that could be connected through a phone, and then generate on-the-fly their own signed certificate for every SSL site requested.
I suppose this could be construed as "how you have your proxy set up" but it requires an explicit action by the phone manufacturer or the OEM supplier and even then it would still fail for people browsing on their laptops using their phone as a modem (with bluetooth or whatever).
Further, I imagine that any ISP attempting to do this kind of thing would soon find themselves in a pile of public-relations doo-doo significantly bigger and smellier than anything Sony are experiencing right now.
Geoff .
- Follow-Ups:
- Re: ecommerce / ssl over 3g ?
- From: Mike H
- Re: ecommerce / ssl over 3g ?
- From: Stephen Henson
- Re: ecommerce / ssl over 3g ?
- References:
- ecommerce / ssl over 3g ?
- From: .
- Re: ecommerce / ssl over 3g ?
- From: Chris
- Re: ecommerce / ssl over 3g ?
- From: Mike H
- Re: ecommerce / ssl over 3g ?
- From: Geoff Winkless
- Re: ecommerce / ssl over 3g ?
- From: Mike H
- ecommerce / ssl over 3g ?
- Prev by Date: Re: Moving from one Orange contract to another
- Next by Date: Re: German mobile SIM card
- Previous by thread: Re: ecommerce / ssl over 3g ?
- Next by thread: Re: ecommerce / ssl over 3g ?
- Index(es):
Relevant Pages
|