Langsung ke konten utama

Avoid “Man-in-the-Middle” Attacks With Perspectives

The Perspectives Firefox Extension is a useful free add-on for Firefox that improves the usability of the browser and provides an additional layer of security when connecting to sites using SSL.

When you use a protocol like SSL to connect to a secure web site, your communication with that site is vulnerable to a “man-in-the-middle” attack unless you’re able to identify the remote server in a secure manner. Most sites can be securely identified because they buy a certificate from a Certificate Authority like VeriSign. Unfortunately, as certificates can be expensive and tricky to administer, some sites prefer to self-certify, and some have expired certificates. Attempting to connect to one of these sites will lead to Firefox issuing the “Website Certified by Unknown Authority” warning that you’ve probably seen many times:
Have you ever just clicked “OK” to accept a certificate without checking it out? Most of the time, it’s probably fine, but you could be leaving yourself open to attack.

Perspectives replaces this warning with one that’s much more useful in that it connects to a database to identify the site. If a self-signed certificate is valid, it will skip the warning, but if it looks suspicious and potentially could be an attack,  it will issue a stern warning that you’re less likely to ignore.

There’s more technical detail on how Perspectives works via “Network Notaries” at the web site (it’s a project of the School of Computer Science at Carnegie Mellon University). If you’re using Firefox 3 or later, I recommend that you install this add-on.

What other security-related add-ons do you recommend?
source: http://webworkerdaily.com/2010/03/30/avoid-man-in-the-middle-attacks-with-perspectives/

POPULAR

Kerajaan Jeumpa, Kerajaan Islam Pertama Nusantara

Teori tentang kerajaan Islam pertama di Nusantara sampai saat ini masih banyak diperdebatkan oleh para peneliti, baik cendekiawan Muslim maupun non Muslim. Umumnya perbedaan pendapat tentang teori ini didasarkan pada teori awal mula masuknya Islam ke Nusantara. Mengenai teori Islamisasi di Nusantara, para ahli sejarah terbagi menjadi 3 kelompok besar, yaitu pendukung (i) Teori Gujarat (ii) Teori Parsia dan (iii) Teori Mekah (Arab). Bukan maksud tulisan ini untuk membahas teori-teori tersebut secara mendetil, namun dari penelitian yang penulis lakukan, maka dapat disimpulkan bahwa Teori Mekkah (Arab) lebih mendekati kebenaran dengan fakta-fakta yang dikemukakan. Teori Mekkah (Arab) hakikatnya adalah koreksi terhadap teori Gujarat dan bantahan terhadap teori Persia. Di antara para ahli yang menganut teori ini adalah T.W. Arnold, Crawfurd, Keijzer, Niemann, De Holander, SMN. Al-Attas, A. Hasymi, dan Hamka. i Arnold menyatakan para pedagang Arab menyebarkan Islam ketika mereka mendo...

Zakiah Nurmala and Biography

Hacking with Google, Is it Possible

Every hacker needs to develop his abilities if he wants to maintain up to date. That's why he will use every tool he can find. From all of these possible options, Google hacks have become a new instrument for hackers. Although Google hacking isn't widespread knowledge, it should be understood by any hacker and even for the everyday computer user. But, if you want to become a hacker, Google is the way to go. Learn how to hack Google and you will acquire a powerful tool for your everyday work. What Is Google Hacking? Basically, it's the ability to use Google for finding hidden bits of data or information that the hacker can use for his advantage. Or in other words, hacking Google search appliance. How so? Let's say that you are a black hacker (someone who uses his hacking abilities for selfish purposes) and want to access the email account of a chosen victim. The first thing that hacker's do is to find out what is the secret question in the email account of their...