ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Firefox tool counters man-in-the-middle attacks

Elinor Mills CNET News.com

Published: 27 Aug 2008 10:57 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Researchers at Carnegie Mellon University have released an extension for Firefox 3 that can protect wireless-network users from so-called 'man-in-the-middle' attacks.

The software, dubbed 'Perspectives', is available for download for free.

Perspectives also protects against attacks that exploit a recently exposed flaw in the DNS system, which translates web addresses into numerical IP addresses, said Dave Andersen, a computer science professor at Carnegie Mellon University, who was an adviser on the Perspectives project.

In an attack on the DNS system, someone typing in a legitimate web address could be unwittingly redirected to a malicious site. Perspectives would pop up a warning to the web surfer that the site they are going to is suspicious.

In general, Perspectives is designed to guide web surfers away from malicious sites. It is also designed to assure surfers when they visit sites that are safe but which Firefox warns about because the sites are not paying a third-party certificate authority, such as VeriSign, for authentication, and instead are using 'self-signed' digital certificates, also known as keys.

Signing up with a certificate authority can be expensive and time-consuming, so some sites prefer to do it themselves, Andersen said. If they do, Firefox penalises them by displaying an error message that says the browser is unable to verify that the site can be trusted.

The messages leave many web surfers confused, and they may either avoid a legitimately safe site or get used to automatically accepting certificates with the warning and inadvertently trust a malicious site at some point.

Read this

Comment
The days of desktop antivirus apps are numbered

Security vendors are exploring new avenues in the fight against malware, making the death of the desktop antivirus app a serious proposition...

Read more +

"The fear is that the Firefox policy will force some sites to use certificate authorities but will make others not use any security at all," Andersen said.

The Perspectives software queries servers around the internet that Andersen has set up as notary-type nodes and asks them to verify the certificate they see for the website sought and to verify what certificate they have historically seen for that site. If the computers are in agreement on those questions, the surfer is sent directly to the site. If there is disagreement on those questions, the browser displays a warning to the web surfer that the site is suspicious.

"The average [internet] user probably wouldn't see one of these attacks in a given year," Andersen said, when asked how severe the problem is. "But, an unlucky user in an airport or some convention where there happened to be a bad guy [lurking on the network] would definitely be vulnerable."

Credit: Firefox extension protects against man-in-the-middle attacks from CNET News.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
33 out of 33 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

The Technological Singularity

Are we approaching a point when machines may wake up and become self or seemingly self aware? Vernor Vinge in 1993 seemed to think so. He refered to this event as the "technological... More

1 comment

Mobile Operating Systems: MOPS At a Gl...

Mobile Operating Systems: At a Glance Author: Eric Everson, Founder MyMobiSafe Since posting my blog exposing the security Google G1 security issue, I have received a few emails... More

Post a comment

Met Police catch test cheats

I saw the funny side of this press release, I can just imagine the two people sitting in the car giving the answers to the questions. Why they had wires running from under the bonnet... More

Post a comment