Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 

gzt

10978 posts

Uber Geek


  # 1393802 24-Sep-2015 19:43
Send private message

nzerin: ok thanks guys, I will look into all these options. cry

If you want to post some specific information about your hosting/platform/software/version/configuration - you may get some very good advice here related to those components.

15388 posts

Uber Geek

Trusted
Subscriber

  # 1393840 24-Sep-2015 20:30
Send private message

MadEngineer: https://www.startssl.com

Any good?


SSL certificates are all roughly the same when it comes to encryption. The higher level ones validate that you are who you say you are, the cheaper ones give no such assurances.

 
 
 
 


8035 posts

Uber Geek

Trusted

  # 1394903 26-Sep-2015 16:15
Send private message

MadEngineer: https://www.startssl.com

Any good?


Pros: Free class 1 ssl certificates, you pay to verify your identity for higher class certs instead of paying per cert like other providers.

Cons: Horribly designed annoying website, based in Israel so things that require manual approval/verification at their end can take a day or more due to time difference.

981 posts

Ultimate Geek

Trusted

  # 1394989 26-Sep-2015 18:30
Send private message

If you are using cloudflare as your CDN you can use the cloudflare account. They have a product called Universal SSL.  

BDFL - Memuneh
64956 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

15388 posts

Uber Geek

Trusted
Subscriber

  # 1394991 26-Sep-2015 18:31
Send private message

darylblake: If you are using cloudflare as your CDN you can use the cloudflare account. They have a product called Universal SSL.  


That typically only encrypts from browser to CloudFlare, not to the server. It can be configured to connect to the server using an encrypted connection, but that is less common and more hassle. It's not secure end to end.

 
 
 
 


mme

147 posts

Master Geek

Subscriber

  # 1395044 26-Sep-2015 20:35
Send private message

Just use a self signed CERT and use Cloudflare to serve the front end. Especially if PayPal handles the payment stuff

Mr Snotty
8940 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  # 1395075 26-Sep-2015 22:34
Send private message

I just self-sign my certificates, enable SPDY support then use Cloudflare to serve up an actual certificate on my sites (see https://management.interwebz.co.nz as an example). For my own hosted stuff not behind Cloudflare I use StartSSL's free certificate which works really well however don't lose the private key for your certificate else you'll find you're forking out some coin for a certificate reset.






17 posts

Geek


  # 1395301 27-Sep-2015 19:08
Send private message

Wow thanks everyone, I will get onto the SSL cert and look into the Cloudflare service. cheers

15388 posts

Uber Geek

Trusted
Subscriber

  # 1395316 27-Sep-2015 19:46
One person supports this post
Send private message

Don't get an SSL cert before you work out your whole game plan. Self signing is possible, if you do CloudFlare, but not with shared hosting, yes if you use a VPS.

Encryption in transit is still an illusion of security. Intercepting and decrypting traffic is pretty rarely a way to compromise a website. Breaking in via known vulnerabilities is far more likely, and easier.

184 posts

Master Geek


  # 1399925 5-Oct-2015 01:33
Send private message

Just to throw another angle:
At work we have a checkpoint firewall.

The other day I was doing some internet banking at work (yes it happens)... I took a look at the cert, and to my surprise the cert was not issued by my bank, but rather from our internal PKI.... Not cool.
So, it seems the checkpoint is doing the encryption between itself and the bank, then decrypting, inspecting the traffic, then re-encrypting between itself and my PC.
Wasn't getting a cert error or any indication this was happening because the PC I was using trusts our internal PKI.

Needless to say, not banking at work anymore...... So, the point is just because you see the padlock looking all happy.... If it's not your network you are on, still check the cert.

2663 posts

Uber Geek

Trusted
Lifetime subscriber

  # 1400322 5-Oct-2015 14:39
Send private message

UncleArthur: Just to throw another angle:
At work we have a checkpoint firewall.

The other day I was doing some internet banking at work (yes it happens)... I took a look at the cert, and to my surprise the cert was not issued by my bank, but rather from our internal PKI.... Not cool.
So, it seems the checkpoint is doing the encryption between itself and the bank, then decrypting, inspecting the traffic, then re-encrypting between itself and my PC.
Wasn't getting a cert error or any indication this was happening because the PC I was using trusts our internal PKI.

Needless to say, not banking at work anymore...... So, the point is just because you see the padlock looking all happy.... If it's not your network you are on, still check the cert.

Well spotted.

Unfortunately this is going to get more and more common and trickle down to SMBs.  Google pushing for SSL on all web traffic means more web traffic is encrypted, and this will include web-borne malware.  To provide comprehensive protection, firewall vendors are having to inject themselves into the path of SSL connections to protect against this.  That was just the 'big guys', but I am seeing more SMB firewalls doing this.




"4 wheels move the body.  2 wheels move the soul."

“Don't believe anything you read on the net. Except this. Well, including this, I suppose.” Douglas Adams

1927 posts

Uber Geek


  # 1400571 5-Oct-2015 21:06
Send private message

Indeed - and how to employ a transparent proxy without doing the above.

258 posts

Ultimate Geek


  # 1402897 9-Oct-2015 10:20
Send private message

UncleArthur: The other day I was doing some internet banking at work (yes it happens)... I took a look at the cert, and to my surprise the cert was not issued by my bank, but rather from our internal PKI.... Not cool.
So, it seems the checkpoint is doing the encryption between itself and the bank, then decrypting, inspecting the traffic, then re-encrypting between itself and my PC.


That is quite bad form by your work. CheckPoint themselves go to great lengths to say that when you are doing HTTPS inspection on your firewalls that you NEED to set exceptions for certain traffic - i.e. financial and health. Your work is opening themselves up to issues if they don't follow these guidelines, as they, in theory, are privvy to personal details if they don't do this. And yes, in hacking terms this is referred to as a man in the middle.

I believe that HTTPS interception is currently the only way to be able to look inside encrypted traffic. And with an average of around 40% (rough memory recall) and growing of traffic in organistions being encrypted there is a real requirement to do this. But with the above caveats.

EDIT: words

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Samsung Galaxy Fold now available in New Zealand
Posted 6-Dec-2019 00:01


NZ company oDocs awarded US$ 100,000 Dubai World Expo grant
Posted 5-Dec-2019 16:00


New Zealand Rugby Selects AWS-Powered Analytics for Deeper Game Insights
Posted 5-Dec-2019 11:33


IMAGR and Farro bring checkout-less supermarket shopping to New Zealand
Posted 5-Dec-2019 09:07


Wellington Airport becomes first 5G connected airport in the country
Posted 3-Dec-2019 08:42


MetService secures Al Jazeera as a new weather client
Posted 28-Nov-2019 09:40


NZ a top 10 connected nation with stage one of ultra-fast broadband roll-out completed
Posted 24-Nov-2019 14:15


Microsoft Translator understands te reo Māori
Posted 22-Nov-2019 08:46


Chorus to launch Hyperfibre service
Posted 18-Nov-2019 15:00


Microsoft launches first Experience Center worldwide for Asia Pacific in Singapore
Posted 13-Nov-2019 13:08


Disney+ comes to LG Smart TVs
Posted 13-Nov-2019 12:55


Spark launches new wireless broadband "Unplan Metro"
Posted 11-Nov-2019 08:19


Malwarebytes overhauls flagship product with new UI, faster engine and lighter footprint
Posted 6-Nov-2019 11:48


CarbonClick launches into Digital Marketplaces
Posted 6-Nov-2019 11:42


Kordia offers Microsoft Azure Peering Service
Posted 6-Nov-2019 11:41



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.