lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: frank at knobbe.us (Frank Knobbe)
Subject: Wireless ISPs

On Tue, 2004-05-11 at 13:33, D B wrote:
> All transactions done via secure websites are secure,

No, they are not. It's just harder to intercept the data.

> A wired internet connection
> limits the number of people who have access to this
> data simply by the nature of the internet putting it
> within acceptable risk.

Same can be said for wireless. (Except that the perimeter of the attack
arena is defined by the wireless emissions instead of cable runs.)

> It is legal according to US law to eavesdrop on
> wireless connections. 

Maybe, INAL. But it is illegal to commit fraud with the data gathered by
eavesdropping.

> 2. Encrypt all wireless transmissions at least making
> someone who gains access to this data prosecutable. 

Uhm... someone that accesses and uses the data is already prosecutable.

> Please direct all flames to /dev/null

Neat. Never heard that before... :)


-Frank

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20040511/27ce987e/attachment.bin

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ