ZJSK.COM
welcome to my space
X
Search:  
 HOME   SSL Web Security
SSL Web Security
Published by: cfz 2009-01-09
Welcome to:zjsk.com

  • How secure is SSL 128-bit today? Can it be cracked and how?


  • I feel like I should clarify that I ask because I run several SSL enabled web servers and I won't ensure that I'm not risking my computer's data due to unsecure SSL.


  • "Secure" all depends on how long you want to keep the data in the SSL stream safe from prying eyes. If you're sending the location of a long lost National Treasure worth billions to your recovery team, you'll likely want the data to be secure just long enough for the treasure to be recovered and moved - after that the information becomes worthless (or worth much less than it was when the treasure was still in place). Basically figure it as "sensitivity of data" versus "duration of concealment". The higher either is, the more security you need, and if both are high, the security requirements can become astronomical. There's nothing wrong with SSL 128bit these days. It'll keep your online banking activities safe from casual packet sniffers out on the net. Anyone with the computing horsepower needed to decrypt the data stream in any kind of practical time period wouldn't need to steal your bank password anyways - they could attack the bank directly and get *everyone's* password. You're far more likely to get into trouble from spyware on your computer watching what you type and getting usernames and passwords stole that way. So... ways of cracking SSL 1) Execute a man-in-the-middle attack - Intercept your SSL request going to a server and pretend to be that server - not very practicle unless you're under government surveillance with enough resources (and time) to set up for it 2) Exploit a vulnerability in your or the other side's SSL software (bad random number generators, buffer overflows, etc...) - The SSL portions of browsers tend to be tested pretty well and checked for bugs by lots of people. Not to say it's impossible (and there have been problems before), but not too likely 3) Compromise your machine or the remote machine you're connecting to - Very likely, as it's so very easy to pick up a lot junk with simple browsing of "safe" sites with Internet Explorer, or reading email with attachments. 4) and as always, brute force attacks - Not too likely. Even SSL 128 would require a huge and very fast computer to attempt guessing all possible keys. If the attacker was seeking a username/password from the data being brute forced, by the time the computer managed to crack the SSL encryption, you'd most likely have changed that password to something else. As such, I'm personally more worried about my computer (or the remote server I'm connecting to) being compromised than someone cracking the SSL layer. It's so much easier to watch someone type in a password, than it is to decrypt the password from the SSL stream later on. And... for the previous comment, I don't know what XML has to do with SSL. It's like saying "new standards like the english language...". XML is used to define other languages and facilitate data transfers between disparate systems. It's not and never has been a method of encryption (though, you could use it to *specify* an encryption language). A DDoS attack also has nothing to do with SSL . DDoS is the act of using a large number of computers to flood one (or a few) servers with so much bogus data that they can't process any more legitimate attacks. If you meant a distributed computing effort, then that's a different thing. But a distributed key cracking effort still boils down to a brute force attack, and ANY encryption scheme, no matter how powerful of secure, will invariably be broken by such an attack.


  • Very helpful marcbb-ga. Can I give you the $4?


  • Naw. Thanks. Call it a freebee. Merry Christmas.


  • Yes it can. SSL Secure socket layer technolgy fairly old. New standards like XML and higher levels of pgp encryption are muych more secure. As far as how it is unsecure there are loopholes in the code that can be pentrated through DDos attacks it can not handle high levels of such attacks
  • Web Messaging Security::
    Activate SSL for the Web Messaging server. See Configuring the Web Server for information about the SSL options. Web Messaging with an SSL connection
    http://www.ipswitch.com/support/imail/guide/imailug8.1/Chapter 9 webmess5.html
    HOME
    Testing SSL with command line tools | Security Viewpoints::
    Security, operating systems and the IT industry SSL tools like these are valuable for assessing more than just web servers. Tags: openssl, ssl, web security
    http://advosys.ca/viewpoints/2006/08/testing-ssl-with-command-line-tools
    HOME
    SSL, SSL Certificates, Server Certificates, Web Server Certificates::
    SSL, SSL Certificates, Server Certificates, Web Server Certificates, Digital SSL and web security products are critical components of these services and we
    http://geotrusteurope.com/corporate/press/pr_GT_Europe_092903.htm
    HOME



    What dress should i wear for an interview ?
    Financial Representative =Insurance salesman?

    You are looking at:zjsk.com's SSL Web Security, click zjsk.com to home
  • flytecomm
  • are my parents immediate family members
  • lhr nrt for under 600 00
  • the last gasp for air canada
  • anyone got any of the destina sale fares
  • super comfort promotion
  • se e 2 1 can it be combined with a companion award
  • ottawa s september 11th payout to the airlines
  • mini report re skyservice yyc las
  • why is destina ca more expensive than aircanada ca
  • ua or ac across pond in c
  • yvr yyc yvr help needed
  • exploding the myths about business travelers
  •  
  • out of country medical insurance what do you buy
  • destina ca does not recoginize some destinations
  • double starwood points on bookings today only
  • u s govt interested in following cda s air traffic control model
  • aeroplan and skymiles rewards
  • a moment of your time please
  • maple leaf club
  • diner s club renews for 3 years
  • westjet revenue passenger miles increase 51 5
  • my online photo albums are up
  • super fast q miles postings
  • threshold bonus
  • question on ac s 767
  • star alliance awards on ac vs star alliance other airlines
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 zjsk.com        Site made:CFZ