2009 03 11 Wednesday

Another thing...

Another thing regarding Hamster/Ferret below... Using SSL doesn't always protect against this kind of attack. See here for examples...
SSL is not always complete. A good example is Gmail. In theory, using the HTTPS version of Gmail should protect you by going to https://mail.google.com/mail, but this doesn't work as you think. The JavaScript code uses an XMLHttpRequest object to make HTTP requests in the background. These are also SSL encrypted by default - but they become unencrypted if SSL fails.

When you open your laptop and connect to a WiFi hotspot, it usually presents you with a login page, or a page that forces you to accept their terms and conditions. During this time, SSL will be blocked. Gmail will therefore backoff and attempt non-SSL connections. These also fail - but not before disclosing the cookie information that allow hackers to sidejack your account.

2006 02 07 Tuesday

links for 2/7/06

trying something new today that I've seen on other sites: links I've been reading today...

  • Linux on a Palm Treo 650 Gets Real - there are less boundries to getting linux working on a Palm TX then there are on a Treo so this could be an interesting project. As is said in the comments though, power saving features are probably a long way off still.
  • Contrstruction Begins for Madison's Citywide Wireless - They said they will be done with downtown, the airport, and the Alliant Energy Center by the end of March; the entire city should be done a year later.

really looking forward to citywide wireless. still haven't heard much about pricing though...