Quote:
Originally Posted by Rob
I've put up a response to that. Rather off topic I think for that site though.
However as far a Phorm / webwise and any similar points go there are concerns. Most message boards are indeed not https, yet by choice many users choose to give some private details. It is for the use during their signup and subsequent use, to determine their trust of the site. They have the belief the site will endeavour to abide by it's terms of use. More importantly though, they have the belief that their data transmissions are not being intercepted.
Message boards are perhaps the most vulnerable thing to the privacy of users compared to phorm. Many users disclose stuff they shouldn't often to non public parts of the board. Where there is no https, are we saying that phorm can scan the message boards of private areas restricted to member only users?
|
given the abilitys of the layer7 DPI kit , can it , for sure, they dont call it 'a man in the middle attack' for nothing and usually that refers to the far slower software impimentations not this commercial grade
Deep Packet Inspection Hardware.
http://en.wikipedia.org/wiki/Deep_packet_inspection
will it, scan the private password protected areas in just http sites ?,given the current data we have all looked over these last few weeks, it can and it will, infact it appears it cant stop itself, unless its manually got your site details in some Phorm of blacklist they maintain, the total oposite of everyone else, they will unless they know not too...
BUT regarding http
s see this BT question put just today...
the implication is they already did perhaps read https at some point in one of the old trials......
http://www.beta.bt.com/bta/forums/me...ID=17784#17784
"
L deAblow [img]Download Failed (1)[/img]
Posts: 59
Registered: 3/13/08 Re: BT Webwise Discussion Thread
Posted: Apr 15, 2008 7:46 PM
[img]Download Failed (1)[/img] in response to:
Mark W [img]Download Failed (1)[/img] Reply
Mark W can I confirm that those people who had problems accessing services like Rapidshare at the time of the profiling were being distrupted by the PHORM profiler.
Rapidshare limit the number of downloads per IP and also check for the same account accessing the rapidshare service simulateously.
With the Profiler also getting a copy of the web page after I have used my account to log in would suggest they were profiling HTTPs as well as HTTP during the trial.
This would obviously show that banking account details were also profiled as part of the trial.
Please comment soonest as Rapidshare keep a log of all IP that a account holder uses
For support free of commercial sleaze try the other forum at http://www.filesaveas.co.uk/cgi-bin/forum/YaBB.pl?catselect=general"