search -  faq -  rulez -  staff

forums






map cycle
irc              pwnalizer
voice         dswp bar




Register

Login


It is currently 05.22.12

 

All times are UTC + 1 hour




Post new topic Reply to topic  [ 18 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: CAs and other stuff
PostPosted: 09.13.11 
Offline
Ingame Mod
User avatar

Joined: 12.19.09
Posts: 742
Location: @Gauss:
-----tdm:  
nick: eX3m
skill: 1849.56
kills: 48977
deaths: 28863
ratio: 1.69
-----bomb:  
nick: LetsPlay
skill: 1585.77
kills: 1867
deaths: 1761
ratio: 1.06
-----ts:  
nick: eX3m
skill: 1461.8
kills: 360
deaths: 296
ratio: 1.21
They told us - nothing what is free can be good as paid, and yet they failed so much people could have been in danger. We can only hope that they will get the words of people that CA system is so shitty, highschooler could do better, but well as long as there is money in it i don't think they will give up easily..
http://www.theinquirer.net/inquirer/news/2106643/diginotar-hackers-targeted-cia-mossad-mi6



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.13.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
meh when he released ComodoGate i thought like 'ok that smart little iranian guy stumbled about something huge, fine, but he is kind a narcissistic praisin himself and reactin to every line on twitter, idiot, will never hear of him again'.
But this one is dramatic, i read through the lists of domains and institutes that where/maybe compromised, wow.
I'm not so deeply into CAs and i stopped following his (religious) shit published on etherpads and twitter and so on but as far as i understand, the complete CA system and of course SSL are simply fucked, right? so is TOR than...
guess he made lots of money selling CA's for MITM's



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.13.11 
Offline
Ingame Mod
User avatar

Joined: 12.19.09
Posts: 742
Location: @Gauss:
-----tdm:  
nick: eX3m
skill: 1849.56
kills: 48977
deaths: 28863
ratio: 1.69
-----bomb:  
nick: LetsPlay
skill: 1585.77
kills: 1867
deaths: 1761
ratio: 1.06
-----ts:  
nick: eX3m
skill: 1461.8
kills: 360
deaths: 296
ratio: 1.21
Well if he is a single guy is questionable: Only reported attack i've heard of is on Iranian citizens (about 300 000)..
http://www.pcworld.com/businesscenter/article/239534/comodo_hacker_claims_credit_for_diginotar_attack.html
Well afaik it works like this: you trust your Certificate "provider" which is mozilla/microsoft etc. They trust all the certificates issued by CA, selected by them. So until you do an update with deleted hacked CA, you still "trust" them. Yeah the thing is this is business so DigiNotar wasn't really talkative about the breach so it kinda fked up.. Well everything is "fine" if you have update :)



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.13.11 
Offline
[dswp]R.Stallman
User avatar

Joined: 04.13.09
Posts: 2380
Location: Solar System/≈Zagreb
-----tdm:  
nick: [Natirips]KrizoGon
skill: 1576.51
kills: 63066
deaths: 71167
ratio: 0.88
-----bomb:  
nick: Laziness
skill: 1453.78
kills: 3274
deaths: 3676
ratio: 0.89
-----ts:  
nick: [dswp]AimMe
skill: 1434.11
kills: 212
deaths: 215
ratio: 0.98
I never really understood how can anything be safe on the Internet to begin with since Internet and privacy are antonyms. Thus I personally see no reason to even try using encryption of any kind from the start.

_________________
ssh natirips@*.255.255.255 sudo chown -R natirips /
Image



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.14.11 
Offline
Ingame Mod
User avatar

Joined: 08.30.08
Posts: 870
Location: Aveiro, Portugal
-----tdm:  
nick: Ham&Cheese
skill: 1923.53
kills: 181902
deaths: 85486
ratio: 2.12
-----bomb:  
nick: Heretic
skill: 1709.41
kills: 13738
deaths: 7832
ratio: 1.75
-----ts:  
nick: RedEyes
skill: 1550.33
kills: 2141
deaths: 1402
ratio: 1.52
http://arstechnica.com/open-source/news ... -stack.ars



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.14.11 
Offline
Ingame Mod
User avatar

Joined: 05.08.09
Posts: 437
Location: Germany
-----tdm:  
nick: fubar
skill: 1621.86
kills: 66219
deaths: 50256
ratio: 1.31
-----bomb:  
nick: |S.Kracht|
skill: 1492.6
kills: 58
deaths: 62
ratio: 0.93
-----ts:  
nick: |S.Kracht|
skill: 1379.73
kills: 357
deaths: 368
ratio: 0.97
That reminds me a bit of Dual_EC_DRBG =)



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.15.11 
Offline
[dswp]R.Stallman
User avatar

Joined: 04.13.09
Posts: 2380
Location: Solar System/≈Zagreb
-----tdm:  
nick: [Natirips]KrizoGon
skill: 1576.51
kills: 63066
deaths: 71167
ratio: 0.88
-----bomb:  
nick: Laziness
skill: 1453.78
kills: 3274
deaths: 3676
ratio: 0.89
-----ts:  
nick: [dswp]AimMe
skill: 1434.11
kills: 212
deaths: 215
ratio: 0.98
So my instincts that told me not to use BSD despite being a *nix fan were right.

_________________
ssh natirips@*.255.255.255 sudo chown -R natirips /
Image



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.17.11 
Offline
Humppaimitat
User avatar

Joined: 07.15.08
Posts: 3773
Location: Behind U
-----tdm:  
nick: cp_-r_miez.plz
skill: 1718.46
kills: 119204
deaths: 79658
ratio: 1.49
-----bomb:  
nick: miez.plz
skill: 1485.74
kills: 9854
deaths: 9081
ratio: 1.08
-----ts:  
nick: miez.plz
skill: 1429.43
kills: 1055
deaths: 778
ratio: 1.35
so what do we learn from this?
- ssl sux the way its used by now.
- open source is bad cause its open source.
- not everything that looks like done by 1-2 college students is done by 1-2 college students.
great :)

@ssl certs
im still with the opinion that theres a mistake by design:
companies rule the certificates, not governments.
a companys goal is always making money. if theres a problem with that, it will try anything cause it dont wanna die...
it would be great if there would be encryption in general, no plain http anylonger. why dont we/they validate the server somehow else?

@topic: i didnt really understand how "he" did it.
can someone help me out? he went to where first?
i mean: u must do some in the DNS to get the client on ur faked site, but how do u get him to eat ur faked cert?
compromise thawte sounds like the very second unbelievable hard step for me, so they accept the

_________________
Image



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.18.11 
Offline
[dswp]R.Stallman
User avatar

Joined: 04.13.09
Posts: 2380
Location: Solar System/≈Zagreb
-----tdm:  
nick: [Natirips]KrizoGon
skill: 1576.51
kills: 63066
deaths: 71167
ratio: 0.88
-----bomb:  
nick: Laziness
skill: 1453.78
kills: 3274
deaths: 3676
ratio: 0.89
-----ts:  
nick: [dswp]AimMe
skill: 1434.11
kills: 212
deaths: 215
ratio: 0.98
If you're talking to a fake/compromised certificate verification server how can you tell the difference between real and face certificate?


Oh, and apropos open source being bad "because it's open source", what makes you think closed source is any better/safer? Like you said, big companies would do anything for money, what makes big closed-source-making companies any different?


Internet is public. Period. That's why I don't use it for anything critically important.

_________________
ssh natirips@*.255.255.255 sudo chown -R natirips /
Image



 


Top
 Profile  
 
 Post subject: Re: CAs and other stuff
PostPosted: 09.23.11 
Offline
Ingame Mod
User avatar

Joined: 12.19.09
Posts: 742
Location: @Gauss:
-----tdm:  
nick: eX3m
skill: 1849.56
kills: 48977
deaths: 28863
ratio: 1.69
-----bomb:  
nick: LetsPlay
skill: 1585.77
kills: 1867
deaths: 1761
ratio: 1.06
-----ts:  
nick: eX3m
skill: 1461.8
kills: 360
deaths: 296
ratio: 1.21
Like if the things weren't bad enough.. :D
http://freerepublic.com/focus/f-chat/2781678/posts



 


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 18 posts ]  Go to page 1, 2  Next

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Imprint

Powered by phpBB © 2000, 2002, 2005, 2007, 2008, 2009, 2010 phpBB Group

Skin by Lucas Kane
we use apache2 mod rewrite with phpBB SEO
map train_beta1-100 © 2009 by SteveMcQueen
Statistics Backend + Database by XLR Stats and B3 Bot
mapvote robot and gameserver monitor © 2009 by BlinKy
mumble viewer Copyright © 2008 Dominik Radner (aka Urmel)
mumble switcher and integration © 2008 by XTJ7, Unclefragger and Wursti
Localisation Plugin © 2009, Team Leads Plugin © 2009 and Knifer Plugin © 2009 by SvaRoX



voice server
tdm » dswp.de:22222
status: online
players: 2/45
map: ut4_druglord
 
bomb » dswp.de:22223
status: online
players: 0/12
map: ut4_harbortown
 
jump » dswp.de:22224
status: online
players: 0/10
map: ut4_train_dl1
 
team survivor » dswp.de:22225
status: online
players: 0/20
map: ut4_prague
 
siesta » dswp.de:22226
status: offline
btw test the new ajax serwer monitor here!
top 20 players


nameskillkills
RastaSkud1601.41404124
NormaSnockers1782.95356641
Hateyouall1601.33252483
Slevin.Kelevra1714.18189976
Wagner_Moura1562.9188001
Ham&Cheese1923.53181902
z0rn1608.41181016
[dswp]Ana1754.25177628
Goomba1710.31172531
Mad1684.29165635
sleepingsun1662.42162927
Zohan1611.07159737
ubercunt1634.93159240
[VR]Amantius1693.89155438
[dswp]Zottel1738.96151362
TG|Deviant1934.94148148
Graf_ZahlIII1683.66136671
ZEBRA(ESP)1598.25134104
DeletedUser0011537.41132992
marshallLaw1744.68128298