Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
PKI - Breaking the Yellow Lock
Richard Forno, 2002-02-13

PKI provides Web users with a false sense of security that undermines the security of their on-line information.

Comments Mode:
PKI - Breaking the Yellow Lock 2002-02-13
Anonymous (1 replies)
PKI - Breaking the Yellow Lock 2002-02-22
Anonymous
PKI - Breaking the Yellow Lock 2002-02-14
Sjonnie (1 replies)
PKI - Breaking the Yellow Lock 2002-02-15
Anonymous (1 replies)
Man-in-the-Middle 2002-02-17
Anonymous
This is news... how? 2002-02-15
TheReject (2 replies)
This is news... how? 2002-02-15
Rick Forno (1 replies)
This is news... how? 2002-02-27
Anonymous
This is news... how? 2002-02-19
Chroma Key (1 replies)
This is news... how? 2002-02-20
Anonymous (1 replies)
This is news... how? 2002-02-22
J. Rogers
PKI - Breaking the Yellow Lock 2002-02-17
Anonymous
PKI - Breaking the Yellow Lock 2002-02-17
Exothermic Reaction (2 replies)
PKI - Breaking the Yellow Lock 2002-02-20
Anonymous
PKI - Breaking the Yellow Lock 2002-02-18
Anonymous
PKI - Breaking the Yellow Lock 2002-02-18
Anonymous
PKI - Breaking the Yellow Lock 2002-02-19
A concerned person
PKI - Breaking the Yellow Lock 2002-02-19
A concerned person (1 replies)
This flaw has been widespread and well known for over a year. Obviously there is no "easy" way to secure an on-line transaction. One method that comes to mind is exchanging the actual public key over a phone instead of the Internet so as to verify the integrity (thus preventing a man-in-the-middle-attack). But how many e-commerce sites would even know what you're talking about? This also brings up the subject that credit cards themselves are pretty insecure. For example, you can pay your bill at a restaraunt and if waiter or waitress is nepharious they may have a pocket card reader to capture the data on your magnetic strip, thus being able to reproduce you credit card. The end result is generally someone on the other side of the world using your card to rack up thousands of dollars of frivelous spending. In closing, the fundamental problems in our financial infrastructure and the systems involved therein are serious and must be addressed expeditiously.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/60/10575#10575
PKI - Breaking the Yellow Lock 2002-02-20
WillieWang
PKI - Breaking the Yellow Lock 2002-02-20
emts@telstra.com (1 replies)
PKI - Breaking the Yellow Lock 2002-02-23
Anonymous
PKI - Breaking the Yellow Lock 2002-02-21
Anonymous (1 replies)
PKI - Breaking the Yellow Lock 2002-02-22
Anonymous
To the Author 2002-02-27
Anonymous (1 replies)
To the Author 2002-03-02
Anonymous (1 replies)
To the Author 2002-03-04
Anonymous
PKI - Breaking the Yellow Lock 2002-03-06
Milind Gokhale







 

Privacy Statement
Copyright 2009, SecurityFocus