Safe Browsing at SIIT Here is the web page containing your news - - PowerPoint PPT Presentation

safe browsing at siit
SMART_READER_LITE
LIVE PREVIEW

Safe Browsing at SIIT Here is the web page containing your news - - PowerPoint PPT Presentation

Safe Browsing at SIIT Here is the web page containing your news feeds Response Response http://www.facebook.com/ Send me the web page of my news feeds the Internet Request Request wsiit Login as 5722123456 with mysEcretpassw0rd the


slide-1
SLIDE 1

Safe Browsing at SIIT

slide-2
SLIDE 2

the Internet

wsiit Send me the web page

  • f my news feeds

Here is the web page containing your news feeds Request Request Response Response http://www.facebook.com/

slide-3
SLIDE 3

the Internet

wsiit Login as 5722123456 with mysEcretpassw0rd Here is the web page for registration Request Request Response Response

slide-4
SLIDE 4

Can someone else see the web pages you are visiting?

slide-5
SLIDE 5

the Internet

wsiit

slide-6
SLIDE 6
slide-7
SLIDE 7

Request Request Request Request Response Response Response Response

slide-8
SLIDE 8

When using WiFi, assume everyone nearby can “see” everything you do on the Internet

the websites you visit: www.YouShouldNotBeHere.com the information on web pages: Account balance = 1,000,000,000 Baht the comments you post: Dr Steve is the worst lecturer ever! the passwords you submit: 5722123456, mysEcretpassw0rd

slide-9
SLIDE 9

When using WiFi, assume everyone nearby can “see” everything you do on the Internet unless you use encryption

WiFi Encryption: WPA Web Browsing Encryption: https

slide-10
SLIDE 10

a6i#l)P1 a6i#l)P1 a6i#l)P1 a6i#l)P1 9G<3t_da; 9G<3t_da; 9G<3t_da; 9G<3t_da; Request Request Response Response Decrypt with key Encrypt with key

Encryption changes the message so that

  • nly those with the same key can read it
slide-11
SLIDE 11

Use HTTPS when accessing “important” websites Use WPA in your own WiFi network

slide-12
SLIDE 12

Man-in-the-Middle Attack on HTTPS

fake_wsiit

Everything encrypted with the key can be decrypted by attacker ( )

You think I am Facebook Facebook thinks I am you

Facebook gives “you” ( ) the key You receive the key from “Facebook” ( )

slide-13
SLIDE 13

Beware of security warnings!

Especially for websites that don't normally give a warning

slide-14
SLIDE 14

Safe Browsing with WiFi

Assume everyone can see what you are doing Use HTTPS when accessing “important” websites Use WPA in your own WiFi network Beware of security warnings when using HTTPS

Use your powers for good

Linux

mitmproxy

Bi Sam Dana Steve