Search n00bz.net

Entries in arp (1)

Wednesday
Mar242010

Public Networks equal prying eyes

Today while in a Salesforce.com demo, I showcased that SSL (the "S" in https) can be stripped away using a classic man-in-the-middle attack.

Luckily, the Salesforce.com team were good sports about it. We discussed alternative access control via IP Address filtering and tokens. This occured over Don Julio 42.


Remember, if your on a public network at Starbucks or the airport, traffic can be sniffed. This means content and passwords.

I have some video recording I will do later this week to show you how.