ssl question
Author
Discussion

billb

Original Poster:

3,198 posts

295 months

Wednesday 6th July 2005
quotequote all
this might be a stupid question so forgive my ignorance but..

If you have a web page open running https eg a bank and another open just using http can in theory someone hack in via the http page and then go through your https connection and get in without u knowing? if that makes sense

_dobbo_

14,619 posts

278 months

Wednesday 6th July 2005
quotequote all
I seriously doubt it - to do that you would have to visit an HTTP page that could exploit a flaw in your browser to the extent that a person could then read the contents of another window!

If they have hacked your PC and have a keystroke logger installed then https isn't protecting you anyway, but I think the above scenario is unlikely in the extreme.


GreenV8S

31,023 posts

314 months

Wednesday 6th July 2005
quotequote all
HTTPS protects you from eavesdropping over the wire. If either side provides a certificate then you can verify that they are the people that the certificate was issued to.

HTTPS does nothing to help browser security. Browsers are supposed to prevent web pages from different domains from interacting with each other, but they aren't all implemented perfectly.

If your machine has been compromised with spyware then all bets are off.

roadsweeper

3,789 posts

304 months

Wednesday 6th July 2005
quotequote all
GreenV8S said:
If your machine has been compromised with spyware then all bets are off.



Consider the a broswer vulnerability could allow a malicious website to install software on your computer. This software can then do as it wishes, including logging key strokes, etc. In this way the scenario you paint is possible, if unlikely to happen in the short window of time in which both pages are open. It is more likely that malware would have been installed previously.

The best defence IMO is to use a secure browser (I use Firefox as I feel it is more secure due to a combination of being less common than IE and hence less of a target, and more robustly written, though it is not perfect) and update it as soon as new security patches are released. This applies to all applications you run and the OS itself (use Windows Update).
Also, avoid visiting websites or installing software you don't trust, use anti-virus, anti-spam and firewall software (the latter blocking Internet access to all programs except the few which really need it) and scan your computer regularly.
Personally, I also use Firefox's powerful cookie controls to limit a very few websites (less than 20) to set or update cookies on my computer.

Hope this helps.

roadie.