Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 16, 2009, 12:57:19 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
335012
Posts
37066
Topics
84019
Members
Latest Member:
dirtyblanket
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Melih's Corner - CEO Talk/Discussions/Blog
Some thoughts I wanted to share with you all
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: Some thoughts I wanted to share with you all (Read 20975 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Some thoughts I wanted to share with you all
«
on:
June 10, 2006, 05:03:18 PM »
The New Dawn: Security is not Trust
Despite talk about encryption and security on the Internet, we are still falling short of true identity trust assurance every time we go online. Why? Our current attempts of encryption only encrypt our communications, but don’t check who is on the receiver. Thus giving users a false sense of security. After all, what is the point of encrypting something for someone you have not authenticated? For all we know we could be encrypting and securing information for the fraudster on the other end.
Through real world examples of fraud, phishing and finally trust, I will outline what steps are necessary to move the Internet from merely encrypted messaging to a secure environment with established trust between user and emerchant and back again. This article will outline why some tools work and some don’t, as well as what actions must be taken to prepare us for the next Internet revolution, the next threat and hopefully an age of trust
Not all Animals – or Internet Padlocks - are created Equal!
It’s a fact of life, we look different, we act different, and we feel different! And that is why browser providers like MS, Mozilla Firefox, Opera and KDE want to change the way their browsers look, feel and interact with the end user. Yet, their security padlocks seem to remain unchanged, providing us with an icon of trust and security that may not only be outdated, but may be a wolf in sheep’s clothing.
Today, not all Secure Sockets Layers (SSLs) – padlocks to the general user - are created equal, and some are even being used as tools in today’s phishing attacks. However, it is hard to tell a secure lock from a non-secure lock when they all look the same. This growing online inconsistency is making it more important that our end users be able to identify a true authenticated site and that browsers work with trusted Certification Authorities to ensure that the padlocks are doing what they promise.
But the good news is: All is about to change! We are about to have a more trusted indicator in the browsers!
http://news.com.com/Browsers+to+get+sturdier+padlocks/2100-1029_3-5989633.html
.
thanks
Melih
«
Last Edit: November 25, 2007, 11:22:19 AM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7454
... and I say to myself, "What a wonderful world"
Re: Some thoughts I wanted to share with you all
«
Reply #1 on:
June 10, 2006, 05:26:31 PM »
Hey Melih,
The new padlock icon in IE7 is embedded within the application. How hard do you think it would be for someone to extract the unsafe padlock icon from the executable and replace it with a copy of the safe padlock icon? Then, the browser would show the safe icon regardless of the authentication level of the site.
Would it be better to have the safe and unsafe icons as separate image files that could be verified somehow each and every time they are due to be displayed by the browser?
What do you think?
Ewen :-)
(WCF3)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #2 on:
June 10, 2006, 05:34:47 PM »
Quote from: panic on June 10, 2006, 05:26:31 PM
Hey Melih,
The new padlock icon in IE7 is embedded within the application. How hard do you think it would be for someone to extract the unsafe padlock icon from the executable and replace it with a copy of the safe padlock icon? Then, the browser would show the safe icon regardless of the authentication level of the site.
Would it be better to have the safe and unsafe icons as separate image files that could be verified somehow each and every time they are due to be displayed by the browser?
What do you think?
Ewen :-)
(WCF3)
I really haven't analysed how IE7 handle this Ewen, sorry :-( But if it is as easy as you suggest, then we should alert IE guys to it. They are great bunch of guys who are very serious about security and user experience.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7454
... and I say to myself, "What a wonderful world"
Re: Some thoughts I wanted to share with you all
«
Reply #3 on:
June 10, 2006, 05:38:12 PM »
Quote from: Melih on June 10, 2006, 05:34:47 PM
I really haven't analysed how IE7 handle this Ewen, sorry :-( But if it is as easy as you suggest, then we should alert IE guys to it. They are great bunch of guys who are very serious about security and user experience.
Melih
I'm pretty sure that they are embedded icons but I'd love to be wrong. The bit I wrote about swapping the icons around was just off the top of my head, but it would certainly be easy enough to do, wouldn't it, and it would achieve the objective of misleading the user.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #4 on:
June 10, 2006, 05:44:48 PM »
Quote from: panic on June 10, 2006, 05:38:12 PM
I'm pretty sure that they are embedded icons but I'd love to be wrong. The bit I wrote about swapping the icons around was just off the top of my head, but it would certainly be easy enough to do, wouldn't it, and it would achieve the objective of misleading the user.
Ewen :-)
ok lets take a look at the threat model.
today phishing takes place using SSL (there were 461 phishing attacks using SSL according to netcraft). So the threat model does not require the phisher to introduce any client code into the victim's machine. In the method you are suggesting, there is a need for a client code. So while it is possible to do what you are suggesting (based on the assumptions you make) its not the current model that fraudsters/phishers use. But that does not mean that they won't in the future!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7454
... and I say to myself, "What a wonderful world"
Re: Some thoughts I wanted to share with you all
«
Reply #5 on:
June 10, 2006, 06:00:15 PM »
Quote from: Melih on June 10, 2006, 05:44:48 PM
ok lets take a look at the threat model.
today phishing takes place using SSL (there were 461 phishing attacks using SSL according to netcraft). So the threat model does not require the phisher to introduce any client code into the victim's machine. In the method you are suggesting, there is a need for a client code. So while it is possible to do what you are suggesting (based on the assumptions you make) its not the current model that fraudsters/phishers use. But that does not mean that they won't in the future!
Melih
Yeah, I wasn't thinking in terms of just SSL attacks. If someone could manipulate the browser, then any site could give the appearance of safety, and most users really only concern themselves with the appearance.
e
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #6 on:
June 11, 2006, 01:15:02 AM »
Quote from: panic on June 10, 2006, 06:00:15 PM
Yeah, I wasn't thinking in terms of just SSL attacks. If someone could manipulate the browser, then any site could give the appearance of safety, and most users really only concern themselves with the appearance.
e
Yes, there is no protection, afaik, against code modiying the appearance.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
1nf3s73d
Newbie
Offline
Posts: 11
Re: Some thoughts I wanted to share with you all
«
Reply #7 on:
July 18, 2006, 01:09:24 PM »
I understand what panic is saying...
I use to love hot bar
a skin change for bland IE5&6
now picture hot bar (or some other company)skin alteration
for IE7 / opera / mozilla
from what I used to understand hot bar is / was a key logger
now picture phishers paying hot bar or someone else rights for ssl locks or what have you
I don't know how to put it but could be...bad... really really bad news for many...
I haven't seen skins for IE7 but I have seen them for opera and firefox
Logged
you're 'bout as ate up as a soup sandwich in the middle of the ocean dur'n a tsunami...
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5320
I'm not a complete idiot, some bits are missing.
Re: Some thoughts I wanted to share with you all
«
Reply #8 on:
July 18, 2006, 02:51:29 PM »
Quote from: Melih on June 11, 2006, 01:15:02 AM
Yes, there is no protection, afaik, against code modiying the appearance.
Melih
But.. if the phishermen (?) can find the icon in memory and change it. Then logic dictates, that someone else must also be able to find it & detect if it has been changed or not. Right?
Logged
Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #9 on:
July 18, 2006, 06:49:06 PM »
Quote from: kail on July 18, 2006, 02:51:29 PM
But.. if the phishermen (?) can find the icon in memory and change it. Then logic dictates, that someone else must also be able to find it & detect if it has been changed or not. Right?
Even under this scenerio a phisher no longer can just benefit from sending emails, he/she now has to introduce a code into people's machine on top of the email.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5320
I'm not a complete idiot, some bits are missing.
Re: Some thoughts I wanted to share with you all
«
Reply #10 on:
July 18, 2006, 07:35:33 PM »
Quote
Even under this scenerio a phisher no longer can just benefit from sending emails, he/she now has to introduce a code into people's machine on top of the email.
So, are they targeting certain email clients (like Outlook/Outlook Express) & browsers (when web mail is used perhaps) and trying to exploit vulnerabilities or is it something else?
Logged
Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #11 on:
July 18, 2006, 07:40:30 PM »
Quote from: kail on July 18, 2006, 07:35:33 PM
So, are they targeting certain email clients (like Outlook/Outlook Express) & browsers (when web mail is used perhaps) and trying to exploit vulnerabilities or is it something else?
They do social engineering attacks whereby they send an email pretending to be a bank and when user clicks on that link they go to a website that looks like a bank. And on this site, you are asked to part with your username and password etc. Now the phisher has all the info to logon to your bank and merrily transfer monies.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1085
Re: Some thoughts I wanted to share with you all
«
Reply #12 on:
August 16, 2006, 10:44:33 AM »
Quote from: Melih on June 10, 2006, 05:34:47 PM
I really haven't analysed how IE7 handle this Ewen, sorry :-( But if it is as easy as you suggest, then we should alert IE guys to it. They are great bunch of guys who are very serious about security and user experience.
Melih
I'll be sticking with Opera for the forseeable
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8217
Re: Some thoughts I wanted to share with you all
«
Reply #13 on:
August 16, 2006, 01:14:21 PM »
Quote from: andyman35 on August 16, 2006, 10:44:33 AM
I'll be sticking with Opera for the forseeable
I like Opera too! They have a good bunch of developers who develop some cool technology! They are very forward looking.
(Actually we just recruited one of their good guys to help Comodo with Product management :-) )
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
comicfan2000
Guest
Re: Some thoughts I wanted to share with you all
«
Reply #14 on:
September 23, 2006, 06:20:42 PM »
While I am not as security enlightened as most of you, I would think that in order to securly make other's mistakes safe (cough IE) and since the browsers can be manipulated, perhaps a security measure that would install\attach to your browser, a sort of guard that would be run from the pc that would detect changes\falsehoods in the browser if a manipulation was trying to take place, stop or notify user of this, sort of a lock down option or restart safety measure. Would this in fact help with SSL as well? not too sure about that. Yet another hair brained idea by yours truly.
Cheers,
Paul
Logged
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - Program Lineup
===> Comodo.TV - News and Announcements
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.047 seconds with 17 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com