|
|
|
|
|
|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
IT / Network guru's - are we being tracked via (SSL) certificates now?
G'day Folks,
Here's a question for IT / Network guru's As the title says "are we being tracked via (SSL) certificates now?" Example #1 - online email account - hotmail for example You get a news letter from a company that has lots of pictures in it. A certificate monitoring add on in firefox can quite often go crazy when you open one of these emails. For some emails I've had as many as 4 certificates being issued. Example #2 - recent issue with my children's school's online payment system for lunches If a child at school has to stay for lunch in Holland you typically have to pay an amount for the supervision. Our school has an online payment system which you have to use. There was a certificate error showing the usual firefox "get me out of here" message. I complained to the school that it could be an unsafe connection etc. I got the usual "add in an exception" response - to which my response was "poke off - that's unprofessional of your IT department they're not fit to be running an online payment system". After much fun they came back with very simple instructions. 1) Visit the site from where the SSL certificate is issued. 2) Come back to our site. I followed the instructions (with all the blockers and monitors I have all switched on) and found that a java script script installed a certificate authority in my browser which then "allowed" the school's site to work. I thought that that was pretty scary. Just think how much fun people could have with one wrong click situations. I don't think that SSL is as secure as it is made out to be. Is this system of issuing certificates now being used to monitor people's clicks?
__________________
1992 W201 190E 1.8 171,000 km - Daily driver 1981 W123 300D ~ 100,000 miles / 160,000 km - project car stripped to the bone 1965 Land Rover Series 2a Station Wagon CIS recovery therapy! 1961 Volvo PV544 Bare metal rat rod-ish thing I'm here to chat about cars and to help others - I'm not here "to always be right" like an internet warrior Don't leave that there - I'll take it to bits! |
|
#2
|
|||
|
|||
|
No real danger. The school is just too cheap (and rightly so) to pay for a signed cert from a company that happens to be blessed by MS and Apple. Nothing wrong with self-signed certificates in my book -- they're no more or less secure than one from VerySlime or ThawteLess. (If the cert changes, then you can worry about a man-in-the-middle attack or a hijacked domain.)
As far as the others - the pics are probably being pulled down via https, from different servers. If you're worried about tracking, set your email not to open external pics by default. If you download pics from an external server (https or not), they can track your IP addy. Last edited by spdrun; 11-30-2012 at 02:35 PM. |
|
#3
|
|||
|
|||
|
There are far fewer entities who can track you when using ssl.
__________________
Remember, Safety Third! '99 E300 Turbodiesel, '82 300TD, 1996 12V Cummins Turbo, '94 Neoplan - Detroit 6V92TA |
|
#4
|
||||
|
||||
|
Thanks for the replies - I think this is going to be as big as flash cookies. The way it works at the moment seems to me to be open to abuse.
__________________
1992 W201 190E 1.8 171,000 km - Daily driver 1981 W123 300D ~ 100,000 miles / 160,000 km - project car stripped to the bone 1965 Land Rover Series 2a Station Wagon CIS recovery therapy! 1961 Volvo PV544 Bare metal rat rod-ish thing I'm here to chat about cars and to help others - I'm not here "to always be right" like an internet warrior Don't leave that there - I'll take it to bits! |
![]() |
| Bookmarks |
|
|