View Single Post
Old 11-04-2008, 22:48   #2951
unicus
Inactive
 
Join Date: Mar 2008
Posts: 60
unicus is an unknown quantity at this point
Re: Virgin Media Phorm Webwise Adverts [Updated: See Post No. 1, 77, 102 & 797]

Quote:
Originally Posted by bishbosh View Post
http://www.bbc.co.uk/blogs/technolog...ish_phorm.html

In the comments: A Possibility?

Webwise works by having a layer 7 switch intercept and impersonate the client and server requests on the network: -

You browse to a secure site

The switch takes this request and passes it to the site as its own, adding the Webwise cookie.

When the site responds with its public encryption key, the switch strips the public key for the site out, adds its own public key and forwards the request to you.

Even when you exchange a private key, the switch will also intercept this, (seeing it already has the public key) create its own private key and use its key to communicate with your 'secure' website.

Meanwhile, all this decrypted data is being forwarded into Webwise for 'processing'. This is the fatal flaw with SSL.

If your ISP or your network admin wants to 'snoop' on your browsing, they can.

Bear in mind that you can send certificates in the post on a USB stick, however, header information is NOT encrypted - so they can still see which sites you are visiting, even if they can't decrypt the traffic being sent.
I also thought about this and questioned it here #2176 though I had initially forgotten about certification. After subsequent reading, including this, I have come to the conclusion that using this deep packet equipment would make a 'man-in-the-middle' attack possible. Now if someone working for Phorm were not trustworthy...
unicus is offline