Forum for the entire range of BMW electric vehicles
BMW Garage BMW Meets Register Today's Posts
BIMMERPOST Universal Forums Off-Topic Discussions Board

Post Reply
 
Thread Tools Search this Thread
      07-30-2010, 02:52 PM   #1
335e92tx
ahat
335e92tx's Avatar
1036
Rep
2,592
Posts

Drives: Was '07-335e92 - Now '13-335IS
Join Date: Mar 2008
Location: Texas

iTrader: (6)

vulnerabilities in SSL and tabbed browers

Everything I am reading here seems to indicate that as long as you open your SSL sessions in a new browser window, you should be ok. That is what I recommend.

http://threatpost.com/en_us/print/5953

[1]LAS VEGAS--A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions.

The research, done by Robert Hansen of SecTheory, shows that browsers such as Firefox, Internet Explorer and Chrome have a number of architectural problems that can essentially negate the security that SSL is meant to provide for sensitive Web transactions. The techniques that Hansen has developed, which he demonstrated at the Black Hat conference here Thursday, give an attacker the ability to do any number of nasty things to a target machine, including forcing the download of an executable file, overwriting the URL field in the browser and overwrite secure HTTPS cookies with non-secure cookies.

A big part of the problem, Hansen said in an interview, is that browsers don't enforce policies that would isolate the tabs in an open browser from one another. This allows an attacker who can control one of the tabs, say a normal non-SSL session, to also affect content in the other tabs, even if they're using SSL. Hansen identified several techniques that enable him to watch an SSL-protected session and glean a lot of information about what the user is doing, based on timing certain parts of the Web session and knowing how long it takes for part of a site to load. He also can tell whether a user is logged in on a given site and use a specific technique to log the user out so he can then watch the login operation and steal the credentials.
__________________

'13 335IS N54 (1 of 373 LeMans Blue out of 3597 total production e92)- Grey interior (1 of 24 in LMB with any trans- 1 of 14 with DCT)-MODS -MFactory LSD/MHD-BQ custom Tune/ATM-IC/AFE Momentum GT Intake/Konis/Mfront&HeimJoint Rear rods&arms/Brembos.
https://photos.app.goo.gl/Lo6aHZRo7XqtPkhL8
Appreciate 0
      07-30-2010, 02:58 PM   #2
BTM
Banned
United_States
483
Rep
10,309
Posts

Drives: A///MERICAN!!!
Join Date: Mar 2010
Location: A///MERICA!!!

iTrader: (11)

Garage List
Interesting, I've never even thought about this until now
Appreciate 0
Post Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 08:08 AM.




bmw
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST