 
              Certificates CS 142 Lecture Notes: Network Security Slide 1
SSL/TLS Overview Browser Server client-hello server-hello + {server-cert}SK CA Key exchange (several options) Random client-key-exchange: {K}PK server key K K {HTTP data}K Most common: only the server is authenticated CS 142 Lecture Notes: Network Security Slide 2
SSL Stripping Replace https:// with http:// Active Attacker HTTP request HTTP request Modified response HTTP response HTTP request HTTPS request HTTP response HTTPS response Browser Server Attacker opens HTTPS Attacker observes session, forwards requests private info and responses CS 142 Lecture Notes: Network Security Slide 3
HTTPS Indicators HTTP HTTPS Firefox 10 IE 8 Chrome 17 CS 142 Lecture Notes: Network Security Slide 4
Mixed Content Indicators Silly dialogs Firefox 10: no SSL indicator Chrome 17: caution sign IE 8: warning dialog, no SSL lock CS 142 Lecture Notes: Network Security Slide 5
CS 142 Lecture Notes: Network Security Slide 6
Recommend
More recommend