in reply to Re: (OT) SSL Certificates: Self-Signing and Alternative Solutions
in thread (OT) SSL Certificates: Self-Signing and Alternative Solutions
While we're bothering to educate users, why not explode the "Must Have Encryption on Credit Card Numbers" myth?
For a random person on the Internet, sniffing traffic to get credit card numbers (even if everything was sent in cleartext) is difficult, and doesn't get a very large reward. You'll have to get a machine physically on the network of a router, grab all the traffic (which could be well into gigabytes per day, or even per hour), and anylize all of it for CC nums.
Consider that many companies store the credit card on a machine sitting just outside their main firewall. There could be thousands of CC nums sitting on one of these machines at any one time. Compared to traffic sniffing, cracking into those boxes is often piss-easy (just wait for the next OpenSSH or Windows bug to come along--shouldn't take too long in either case). Those boxes are your main point of security failure, not SSL.
----
I wanted to explore how Perl's closures can be manipulated, and ended up creating an object system by accident.
-- Schemer
: () { :|:& };:
Note: All code is untested, unless otherwise stated
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: (OT) SSL Certificates: Self-Signing and Alternative Solutions
by inman (Curate) on Nov 10, 2003 at 16:09 UTC | |
by hardburn (Abbot) on Nov 10, 2003 at 16:23 UTC | |
|
Re: Re: Re: (OT) SSL Certificates: Self-Signing and Alternative Solutions
by jreades (Friar) on Nov 14, 2003 at 13:24 UTC | |
by hardburn (Abbot) on Nov 14, 2003 at 14:41 UTC | |
|
Re: Re: Re: (OT) SSL Certificates: Self-Signing and Alternative Solutions
by Anonymous Monk on Nov 15, 2003 at 05:12 UTC |