Bars For Sale > Pattaya Bars > Online Thailand Hotels > Thailand Website Directory > Check On Your Girl > Pattaya Photo Guide > Pattaya Videos
Featured Businesses
![]() ![]() |
May 16 2008, 01:01 AM
Post
#1
|
|
|
Supreme Pattaya Addict ![]() ![]() ![]() ![]() Group: Trusted Member Posts: 282 Joined: 6-April 07 From: Ulthuan Member No.: 3,848 ![]() |
Generally it's not a good idea to be entering passwords and other sensitive data in free wireless hot spots due to lack of encryption, security and because of threats like the 'Man in the Middle' technique.
Now my little brainwave...... As far as I am aware only keystrokes can be recorded/logged? What if (before going on-line) you open a word document, type in your relevant passwords, etc and then after going on-line you copy and paste them into the relevant fields. Obviously theres no keystrokes to log this way as you will be clicking with the mouse and I assume theres not a simple way to track mouse movements. Has anyone ever tried this or knows if its a good prevention technique? Doc |
|
|
|
May 16 2008, 02:28 AM
Post
#2
|
|
|
Supreme Pattaya Addict ![]() ![]() ![]() ![]() Group: Trusted Member Posts: 408 Joined: 23-September 07 From: USA Member No.: 9,855 ![]() |
if you type in the information in the word doc they can see the keystrokes there too.
A nifty little way to try and frustrate their keylogger may be to type a ton of nonsense words into the doc, with your password cleverly hidden in there, and then copy/paste. OR I guess you could carry around the word doc on a USB drive. |
|
|
|
May 18 2008, 07:19 PM
Post
#3
|
|
|
Advanced Pattaya Addict ![]() ![]() ![]() Group: Trusted Member Posts: 120 Joined: 8-January 07 Member No.: 481 ![]() |
|
|
|
|
May 20 2008, 01:58 AM
Post
#4
|
|
|
Newbie Addict ![]() Group: Member Posts: 11 Joined: 5-March 07 Member No.: 2,707 ![]() |
Hi,
it might help against key loggers if the document is set up before the key logger is attached. However, it does not help at all against the threats of free wireless hot spots. After copy & paste the information into the relevant fields finally the information has to be transmitted to a server. That's the weak point without encryption and even with encryption still the man-in-the-middle is a threat. So your proposal is far away from being a good prevention technique. Actually it's rather bad. The only way to be somehow safe is to use strong encryption for authentication and authorization. ak |
|
|
|
May 20 2008, 02:27 AM
Post
#5
|
|
|
Alεx aka IHM ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 5,001 Joined: 22-October 07 From: London Member No.: 11,269 ![]() |
Hi, it might help against key loggers if the document is set up before the key logger is attached. However, it does not help at all against the threats of free wireless hot spots. After copy & paste the information into the relevant fields finally the information has to be transmitted to a server. That's the weak point without encryption and even with encryption still the man-in-the-middle is a threat. So your proposal is far away from being a good prevention technique. Actually it's rather bad. The only way to be somehow safe is to use strong encryption for authentication and authorization. ak What would be the best way to do it mate? Any software you can recommend? |
|
|
|
May 20 2008, 11:25 AM
Post
#6
|
|
|
Thai Girl Anthropologist ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Root Admin Posts: 10,663 Joined: 5-December 06 From: สัตหีบ (sattahip) Member No.: 1 ![]() |
|
|
|
|
May 20 2008, 11:44 AM
Post
#7
|
|
|
Mr Frequent Flyer © ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 6,111 Joined: 5-December 06 From: Somewhere between Malaysia and Thailand Member No.: 6 ![]() |
I'm going to assume that the OP is taking about using his own computer on someone elses WiFi connection. If this is the case the information you send on that system is exactly the same as that which is transmitted on the internet. If the information is send encrypted then it is sent encrypted on the third party WiFi connection the same as on the internet. The only way a key logger can capture passwords entered on a secure page is if the keylogger software is already installed on your computer.
Your computer encrypts the information before it leaves your machine. I think you should be more worried about the information that you put in the internet than across the WiFi connection as more people can access it. BTW once your computer has encrypted the information it can not decrypt it. This is because to encrypt the data your computer uses a public key. To decrypt the data the private key is required, Only the public key is transmitted on the internet. For more information on this you can see public-key cryptography. |
|
|
|
May 21 2008, 03:13 AM
Post
#8
|
|
|
Newbie Addict ![]() Group: Member Posts: 11 Joined: 5-March 07 Member No.: 2,707 ![]() |
What would be the best way to do it mate? Any software you can recommend? Basically all modern browsers and mail clients have implemented secure protocols. The problem is that not all web sites/servers support the secure protocols (e.g. https). Try connecting to the web servers with https and check the certificates carefully. If you connect directly to your mail server configure your mail client to use TLS/SSL. You could use a VPN if you want to connect e.g. to your company to access the file server. You should use a firewall in your company supporting VPNs and on your computer you would have to install a VPN client. And of course install anti virus and firewall software. However, all these measures will not give you 100% safety. But it makes it more difficult to attack your data. It's like securing your home, the more measures you take the more difficult it will be to penetrate. Hope this helps a little bit. |
|
|
|
May 21 2008, 04:24 PM
Post
#9
|
|
|
Alεx aka IHM ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 5,001 Joined: 22-October 07 From: London Member No.: 11,269 ![]() |
Basically all modern browsers and mail clients have implemented secure protocols. The problem is that not all web sites/servers support the secure protocols (e.g. https). Try connecting to the web servers with https and check the certificates carefully. If you connect directly to your mail server configure your mail client to use TLS/SSL. You could use a VPN if you want to connect e.g. to your company to access the file server. You should use a firewall in your company supporting VPNs and on your computer you would have to install a VPN client. And of course install anti virus and firewall software. However, all these measures will not give you 100% safety. But it makes it more difficult to attack your data. It's like securing your home, the more measures you take the more difficult it will be to penetrate. Hope this helps a little bit. Nice one akka, thanks for your reply dude. |
|
|
|
May 21 2008, 09:59 PM
Post
#10
|
|
|
Newbie Addict ![]() Group: Member Posts: 20 Joined: 19-March 08 Member No.: 15,200 ![]() |
I think you are talking about different attacks.
Keystroke logging monitors the keyboard input, via either software or hardware, and records the keystrokes, which are then accesses at a later time. This would normally happen via some kind of software malware on the computer, or someone has installed a hardware logger on the keyboard cable or inside the computer. Wireless eavesdropping happens when then data they you have entered is sent to the website over a wireless network, and others can see the packets as they go over the air. Should not happen if you are connecting to a https:// site as this uses encryption, however even if you use https you can't be sure something done behind the scenes is being sent using unencrypted http. And then we have man-in-the middle where you try to connect to somewhere, and the connection is intercepted, and the software pretends to be where you want to connect, accepts your input, and then really connects and impersonates you doing the transaction. Cut-and-paste should defeat simple keystroke logging, however wouldn't touch the other two. If you are using your own computer, and have appropriate anti-malware software installed, you are hopefully protected from software keystroke logging, and unless someone has physical access to your computer to install hardware keystroke logging, you should be safe from that too. Internet cafe computers I wouldn't touch with a bargepole, vulnerable to both software and hardware logging, and very little you can do to assess there security. If you just want to google a few things should be ok, but don't login to anything. Basically don't enter any data that you are not prepared to become public. Wireless eavesdropping can probably be adequately addressed by using a proxy server via https, or a socks server via an otherwise encrypted channel ie ssh -D. Man in the middle should not be possible using https, however depends, as does most security, on people doing all the right things when designing and setting things up, and not cutting corners. If you really want to learn how to secure your connections, then you should google the subject and be prepared to spend some time understanding and sorting thru the suggestions. So much will depend on exactly what you are trying to protect and how and what you are trying to access. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
0 | KhunIT |
174 | 15th May 2007 - 11:49 AM Last post by: KhunIT |
|||
![]() |
22 | Captain Murgatroyd |
810 | 24th June 2008 - 06:10 AM Last post by: TBarmy |
|||
![]() |
5 | maxmax32 |
810 | 7th September 2007 - 06:05 PM Last post by: pattx |
|||
![]() |
4 | routeman |
211 | 19th January 2008 - 04:28 AM Last post by: joe_publico |
|||
![]() |
5 | Mavrick |
311 | 12th February 2008 - 01:39 AM Last post by: nadia |
|||
![]() |
0 | joepattaya |
186 | 23rd February 2008 - 09:24 AM Last post by: joepattaya |
|||
![]() |
2 | fritzzzzz35 |
214 | 5th June 2008 - 01:33 PM Last post by: Hardeep J |
|||
![]() |
7 | wilka |
260 | 8th July 2008 - 01:19 AM Last post by: Infiniium |
|||
![]() |
1 | porndog |
128 | 7th July 2008 - 05:22 PM Last post by: Esco |
|||
![]() |
0 | Gman-KM |
71 | 5th August 2008 - 02:20 AM Last post by: Gman-KM |
|||
| Lo-Fi Version | Time is now: 10th January 2009 - 08:16 AM |