Is Stack Overflow “secure”? Kind of...
troyhunt.com
troyhunt.com
Out of curiosity, does anyone know how much traffic I'd have to hit before my "$20 SSL certificate" started being a chokepoint and bottleneck? If I were able to hit stackoverflow levels of traffic, I'm sure I'd be able to figure out a way to afford it (although maybe even they haven't yet), but I'm curious at lower levels of traffic if I should still worry.
I do realize now that my question is too simplistic and obviously varies according to the nature of the application, server config, etc. So won't expect any answers for it. :)
"In order to do this we had to deploy no additional machines and no special hardware. On our production front-end machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead. Many people believe that SSL takes a lot of CPU time and we hope the above numbers (public for the first time) will help to dispel that."
https://www.verisign.com.au/ssl/ssl-information-center/ssl-r...
Admittedly, my use-case for the Stack Exchange sites (specifically Server Fault) is a little different than most people's and I'm a lot more worried about "theft" of my "identity" there than most people would be. Still, though, I'd like to see the answer revisited in light of mid-2012 technology / costs. I suppose I should go post something over there...
With most WiFi encryption (basically except WPA2 Enterprise, which won't be in use in cafés) you can still receive the traffic as long as you see the initial handshake for the device connecting to the network. Sniffing software like Wireshark or Aircrack-NG can handle the decryption transparently.
Once you can see the traffic Firesheep or something like it will work in the same way as on an unencrypted network.
Also, the author omits a crucial workaround. When on a public network, communication can be made secure if routed through an encrypted tunnel to a known-secure network, such as with a properly configured VPN.
The first condition is satisfied whenever you're in a coffee shop, airport, hotel, university campus, wifi-enabled public transportation ... i.e. pretty much everywhere except your own home and possibly your workplace. Some of these places use WPA, but most I've seen don't use any encryption. The second condition shouldn't be too easy to satisfy, either, particularly when you're in a place like the Bay Area.
Blacklisting isn't good enough when it comes to security, we all know that. So the advice should rather be: Anyone can steal your Stack Overflow session at any time whatsoever, unless you're using an Ethernet cable or your own secure Wi-Fi. (Even then, your ISP or a three-letter government agency could see your traffic, but they're probably more interested in watching you than impersonating you.)
"i don't really care that the stackoverflow guys don't care because it doesn't really matter"
"i'll just post it here knowing that it won't help the average joe either, because he will never read or understand what i wrote"
who's the target audience for that post? if you're just explaining cookie theft ssl and openid to unknown audience by the example of stackoverflow. by all means write it in the first paragraph.
have some respect man
Would that fit your definition of a "call to action?"
I'm working on a side project now which uses a similar approach for security (delegate it). While I had already planned on making sure the app would be available over SSL, this was a good reminder of why.
The beautiful thing about the Internet and, indeed, free choice is that you could have stopped reading this article and moved on at any time.
"A little harsh. I think it's a good reminder for all of those new products and services being developed as we speak who can make this a priority now instead of having to layer it on later."
i hope you see the irony. you're right with what you say. but it would be even better of a place if people would actually try to create something of value, both positive or negative. but this is somewhere in between.
something with more value and much more precise is the stackoverflow link someone posted in this thread
http://meta.stackoverflow.com/questions/69171/why-doesnt-the...