Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 8th, 2001, 02:56 PM
Robert12345 Robert12345 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2000
Posts: 65 Robert12345 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 31 m 38 sec
Reputation Power: 8
I see many web sites with pages , eg CC detail forms, within a SSL secure site server but clearly without any encrypting such as PGP. Does this offer any protection?

Reply With Quote
  #2  
Old March 8th, 2001, 05:36 PM
rod k rod k is offline
Apprentice Deity
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Jul 1999
Location: Niagara Falls (On the wrong side of the gorge)
Posts: 3,237 rod k User rank is Private First Class (20 - 50 Reputation Level)rod k User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 m 8 sec
Reputation Power: 13
Send a message via AIM to rod k
Does your browser display the locked padlock icon? If so, then it is secure. Just because you can't see the encryption doesn't mean it isn't happening.

Reply With Quote
  #3  
Old March 12th, 2001, 09:55 AM
Robert12345 Robert12345 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2000
Posts: 65 Robert12345 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 31 m 38 sec
Reputation Power: 8
But can't see public key

Thanks for taking the time to reply, Rod. If I look at the source code for some pages offering 'a secure site' I cannot see reference to any Public Key. I myself have pages using PGP and the Public Key is visable via View | Source.

I can also have a 'standard' html form that sends info from a web page that is on a Secure Server - where I can see the Padlock - but this info is not encrypted.

Surely the latter does not offer any/much protection?

Reply With Quote
  #4  
Old March 12th, 2001, 10:42 AM
rod k rod k is offline
Apprentice Deity
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Jul 1999
Location: Niagara Falls (On the wrong side of the gorge)
Posts: 3,237 rod k User rank is Private First Class (20 - 50 Reputation Level)rod k User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 m 8 sec
Reputation Power: 13
Send a message via AIM to rod k
You don't need to 'see' the keys, they're there.

The en/de cryption is handled by the server and the browser in the background.

When an https connection is first established the browser and client exchange public keys. (A little more complicated than that but you get the idea).

When the server sends content it first encrypts the data with the clients public key which is then decrypted by the client and the content is displayed. (you never see the keys or the encrypted content). When the client sends a request (including any form data you might have submitted) the data is first encrypted by the client with the servers public key. Again, you won't see the encrypted data being sent or the key it is encryted with.

This is extremely secure.

Reply With Quote
  #5  
Old March 12th, 2001, 10:46 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Apache with SSL encrypts the connection (the session) between you and the server. If Apache supposes to launch sendmail to send something to you, the transmission between smtpd to your mail server is not. Does this answer your question?

Reply With Quote
  #6  
Old March 14th, 2001, 07:05 AM
cillian cillian is offline
Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2000
Location: Galway, Ireland
Posts: 10 cillian User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
There is a lot of this ppl branding their sites as secure just because the data from the form to server takes place over a SSL then is emailed to a admin.
The email part is insecure. As you said it must be PGP or something equivalent to do the job.

But what is commonly done is the data is stored in the database and only a notice email is sent to the admin with no private info.

Admin then logs in securely over an SSL and reads the data.

Hope this helps

--cj

Reply With Quote
  #7  
Old March 15th, 2001, 03:48 PM
rod k rod k is offline
Apprentice Deity
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Jul 1999
Location: Niagara Falls (On the wrong side of the gorge)
Posts: 3,237 rod k User rank is Private First Class (20 - 50 Reputation Level)rod k User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 m 8 sec
Reputation Power: 13
Send a message via AIM to rod k
You guys are right. It never occured to me tht someone might actually send a plain email containing the data they just received over a secure server. SHEESH, scary what some people do.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Secure sites


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway