BleepingComputer.com: Security - Unsecured Wrieless-Hotel

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Security - Unsecured Wrieless-Hotel

#1 User is offline   pagemaker 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 01-January 11

Posted 01 January 2011 - 11:50 AM

I am on a secure page on an unsecured hotel wireless connection. Is it safe to enter financial info on this page? The lower right hand section has the secure lock, but I am not certain if someone can see the info that is not blocked out (like the password is).

#2 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 01 January 2011 - 06:47 PM

View Postpagemaker, on 01 January 2011 - 11:50 AM, said:

Is it safe to enter financial info on this page? The lower right hand section has the secure lock


In theory, yes, it is safe. But there are some risks. I would not do it.

The secure lock you see is actually for the page you are viewing right now, it is not for the page to which you will be posting your confidential data.
By convention, the data you will be posting will also use HTTPS, but it's just that: a convention. Unless you examine the HTML code (and probably the JavaScript code), you can't be 100% sure that your data will be posted with HTTPS. But in almost all of the cases, it will be.

You should also inspect the certificate by clicking on the secure lock, to be sure that it is a certificate from your bank, issued by a CA you trust.
Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

#3 User is offline   somdcomputerguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 17
  • Joined: 22-December 10
  • Gender:Male
  • Location:West Virginia

Posted 01 January 2011 - 07:21 PM

If you're using Firefox, this extension - https://addons.mozilla.org/en-US/firefox/addon/3199/ - Link Alert, may be useful to you. Basically when you hover over a link or button, a tooltip displays next to the pointer stating the destination. So you can easily tell if it's https or not..
-bruce /* somdcomputerguy */
'If you change the way you look at things, the things you look at change.'

#4 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 02 January 2011 - 11:41 AM

Here is an interesting press release:

Quote

Sheriff's Detectives Arrest Suspected Identity Thief
Santa Barbara - December 30th, 2010

...

Further investigation has revealed that Ehimika would select his victim’s by trolling through neighborhoods looking for unsecured wireless internet connections. Once he identified a residence with a vulnerable signal, he would use his computer skills to obtain critical personal information from his victims and then ultimately tap into their home equity accounts.

...


http://www.sbsheriff.org/pr/12301001.html
Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users