Tom's Hardware > Forum > Old Man/Woman's Club > Other > Internet encryption allready possible but where is it?

Internet encryption allready possible but where is it?

Forum Old Man/Woman's Club : Other - Internet encryption allready possible but where is it?

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Yeah yeah, I know some of you don't want to hear about computer stuff here. It's your forum blabla whatever.
Other should be named "Other 2" maybe? Dunno whereelse to post this.
I'm just wondering about The Internet. Nowadays you see banking sites protecting their customers with encryption (https). I was just wondering why the whole Internet isn't encrypted yet while many firms etc are complaining about hackers hacking them and many hackers setting up "Evil Twins hotspots" at airports/hotells etc while The Internet criminality is increasing dramaticly.
The goverments knows about the problem everybody knows it and encryption is THE solution. Encrypting your hdd etc.
Let me guess, is it terrorism that will cost us our privacy as a reason not the make 256 bit encryption the main Internet standard?
I would like your opinion on this matter. Please only serious posts. Not childish Prick (Pr!ck etc) reactions.

Sponsored Links
Register or log in to remove.

Prick.

------------------------------ +35 Wingding approval points +10 Scouse approval +22 Mammary Manipulation
+5 Comedy +15 Belated Holy Points +5 Messianic Approval + 5 penile innovation
+13 Baked Ham creativity +65 Obscure Quote

Reply to KingLoftusXII

it's most likely down to cost or something like that or maybe apple is applying pressure cause they don't like security in their software.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger
- 0 +

SyPheR,

Just on the off chance that you don't like the responses here, you could try General Networking or one of the subforums. (Apologies for the UK link but that's the only one I can get to from this machine.)

One thing is for certain: you can post wherever you like, but you cannot influence what kind of responses you are going to get, not here and not on any other forum either. If it makes you feel any better: I cannot influence that either, noone can.

Reply to BigMac
- 0 +

Okay. Fine.

Why isn't HTTPS generally used?

Easy. Encryption/decryption places EXTRA load onto the CPU and memory of a server (or servers), and a lot thereof if you're running something decent like 256 bit or greater. This means that more expensive and powerful equipment is required to serve that site. Plus, encryption software tends to be pricey (or utter tripe, sometimes both).

Another (very minor) problem with web encryption is browser support. Older browsers may require a plug-in to allow encryption. This could add admin overhead for the webmaster(s).

Finally, if I'm a network admin in charge of a corporate network (with web/DNS/VNC/etc servers) then I'm only going to spend the time/resources/overhead on securing that which needs to be secured. I'm not going to waste time securing the site that Jimmy from Accounting put up on the corporate network detailing him/his family/friends. I mean, really, I don't give a toss what crackers are attempting to steal his family photos. I'm more fussed about crackers stealing the company financial records/Intellectual Property/other high-sensitivity data.

There are a whole slew of other reasons. Talk to a networking specialist and/or an programmer about this. Mathematicians can be helpful in understanding encryption too.

Oh, by the way, here's the llama suit, you know what to do. [/Given up]

------------------------------ http://www.catb.org/~esr/faqs/smart-questions.html - I WISH PEOPLE WOULD APPLY THIS!
Reply to mugz

Where's your picture?

------------------------------ No more promise no more sorrow,
No longer will I follow.
Can anybody hear me?
I just want to be me.
Reply to JustPlainJef

He shaved this morning. Perfectionism can be a pain in the hind quarters.

Reply to Vokofpolisiekar
- 0 +

HTTPS or SSL can cost from $150 to $10,000 a year if you go with a 3rd party verified certificate.

Its easy to setup. Install your CA, create your data file, certify it against your own CA and then import your personally verified certificate on your site.

Problem is anyone can mimic an SSL site if its not verified by a 3rd party source. If you make your own, I could copy it within a few minutes.

Thus, you have to use a 3rd party do it.. its a yearly cost. Every year you need to replace your certificate, meaning a bunch of people are going to have headaches trying to make the certificate work with their browser, or update their computers.

I deal with this with Bank of America because those f'ing morons over there can't figure out how to properly replace their certificate on their end, which ends up with a week of down time until they can figure out that they need to remove the expired certificate, then import the new certificate so people can access the site.

It comes down to money and its not really all that great of protection.

I just finished setting it up last week for a financial system.. its only good when the person connecting to the site takes the time to verify the certificate is value. Most people set their browsers to not prompt when the certificate changes - if you go from https://www.bigbank.com to a redirected https://www.bigbank.com - the fastest way to know you're not on it is to check the certificate associated.
But if that person created their own, you'll see the little green bar and gold lock in IE, or the other features of other browsers, stating you're on a certified secure site. Which one? Doesn't matter, its secure though.

------------------------------ "Alcoholism is a disease, but it's the only one you can get yelled at for having. Goddammit Otto, you are an alcoholic. Goddammit Otto, you have Lupus... one of those two doesn't sound right." M. H.
Reply to riser
- 0 +

Thx for the reactions guys. I appreciate it.
Never expected it to cost that much.
Is that because 256 bit encryption could also be decrypted? So they'll have to maintain different encryption methodes to keep hackers from decrypting the data?

Why not use a layered encryption that is impossible to decrypt. Much cheaper in maintainance, right?

Mugz, sure the server loads are high with all these encryption calculations but will it still be high when we are like 10 years ahead in time? CPU's are becoming more and more powerfull over the years. Maybe that would be the time where encryption will become the main standard?

Riser, I've read that long time ago about faking urls and getting redirected etc. Do you think this will always stay the main problem in secure surfing? I think the problem lies more with the Browser developers. They should make this protection option a standard once you install it.

Reply to SyPheR

You can already get dedicated crypto cards to use for AES encryption.

If you want safer surfing I suggest you take a look at the noscript add-on for Firefox. It stunned me just how much scripting there is out there when I first had a play with it.

------------------------------ BoM - Just another bunch of cheese eating surrender monkeys
Reply to audiovoodoo

secure surfing is using a well built host file. Most peps, most likely, don't even know that the OS automatically installs a host file. Its up to the person to discover all the IPs that have been cycled in a big circle. No encryption needed cheap. The tool the FBI would rather not see on the net is the best one.
currently my host has over 320 thousand IP dns that are cycled back to the open world of cyber space most of these are evil IP that steal just for the fun. Even better is hacking the system to crash, then use a good flooder so now they have a fck of a time starting back up. Most hackers are not interested in your or my computers, its the server they want and being dudez in the other we are pricks.

------------------------------ WAITING FOR THE NEXT MOMENT TO STRIKE

 

Reply to gomerpile

- 0 +

The noscript addin is more sensible on the browser level than full-on encryption.

------------------------------ http://www.catb.org/~esr/faqs/smart-questions.html - I WISH PEOPLE WOULD APPLY THIS!
Reply to mugz

No! Turn off your PC and burn it!


Hackers will steal your homes and force you to be raped by rabid goats!


Live in fear! Fear! FEEEEEAAAAARRRRRRR!!!!!


* This announcement brought to you in association with the US and UK governments *


Message edited by llama_man on 06-27-2008 at 02:43:22 PM
------------------------------ +46.53 Pedantry/+75 Wingding Approval/+27 Vindictive bastard/+7 innovative violence/+11 Scouse trophies/Bastages WD:9 RC:4 AV:1 [specials; cluster:2,leather elbow patched:1,pre-approved:3,first class (upgrade):1,multi-thread:1,double-barrel:1]
Reply to llama_man

thank christ, at least that is not as bad as rabid llamas. I would really be sh!tting it then.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger
- 0 +

SyPheR wrote :

Thx for the reactions guys. I appreciate it.
Never expected it to cost that much.
Is that because 256 bit encryption could also be decrypted? So they'll have to maintain different encryption methodes to keep hackers from decrypting the data?

Why not use a layered encryption that is impossible to decrypt. Much cheaper in maintainance, right?

Mugz, sure the server loads are high with all these encryption calculations but will it still be high when we are like 10 years ahead in time? CPU's are becoming more and more powerfull over the years. Maybe that would be the time where encryption will become the main standard?

Riser, I've read that long time ago about faking urls and getting redirected etc. Do you think this will always stay the main problem in secure surfing? I think the problem lies more with the Browser developers. They should make this protection option a standard once you install it.



The CPU usuage isn't an issue. Its 1-3% use on a webserver hosting a bunch of stuff. I'm running it on a 7 year old system without any issues. I haven't seen any issues with the CPU.. its about the same as encrypting files on your computer/server. You don't see a change.

The cost is there because the certificate issuing company insures the company for data loss and such. The idea is that you go out and download the certificate which validates against the websites. You get a public key and a private key. Its fairly secure.. especially when adding in a login - Banks have SSL and then a login. Two layers. The bank website won't let you in without the certificate stating you're on that site. Getting the certificate isn't hard.. duplicating is a matter of the person accessing the site not knowing all that they're doing. Faking the website, getting their username/password, and cross scripting to pull their bank info isn't exactly hard to do for someone skilled in webdesign. Basically, they're acting as a proxy.

As far as encryption goes, you can get a varying degree. Most of them have more insurance as the level of certificate goes up, ensuring a higher level of accuracy.

http://www.verisign.com/ssl/buy-ss [...] index.html

I had another site that offered the certs for less.

I would imagine having dedicated secure DNS servers out there for financial institutes would help increase some security. Right now you don't really know if the DNS server you're using is secured or was modified by an outside source. If you understand DNS, you can modify internet DNS addresses to point anywhere. But it won't last long since the other DNS servers are likely to over write it with a replication process - but if you're able to get onto a root DNS server and make a change, you could take over the internet DNS structure within a matter of a couple hours.

Overall, as it stands, the internet is really 'safe' for what its worth. All the so called 'insecurities' can be attributed to the people using the computer. In an overall ideal situation, everyone would know what they're doing. Since that isn't the case, SSL won't even really help all that much.

In fact, there was a time when Google was crawling on sites and was pulling people's login information and reading their emails after they've logged in. Google's gmail scans your emails when you open them. Not really secure, but people think it is.

A few years back, one would only need to poison a cookie or use SQL injection to bypass a login. When these approaches were figured out, websites were changed to not allow it. Having the SSL there keeps people from modifying anything on the outside because they're using a public key, not the private key. But you can pull the private key and hack it to recreate it to get that access, but that's just getting over simple part of the security.

Overall, https won't take over for a long time because the benefit isn't there. It'll stick with financial places but I haven't heard of any new security coming out. 256bit encruption is probably here for the next few years at least.

Too many programs out there bypass it easily.. Google and Barracuda come to mind.

As far as browsers go, IEEE has a new internet they're working on getting out. Its in the alpha stages right now, much like the internet was in the very early 90s. Its limited to only select institutions and its supposed to be a whole lot more secure and change the way webpages are done along with data transfer. I'm guessing it'll come out in the next 10-15 years for public use. I think they're keeping it mainly for institutions, governments, and military at this point. It currently has roots in the US, some countries in the EU, Japan, and Canada if I remember.. might be some others out there.

That will change a lot of the current security issues.. and when you start moving into IPv6 with increased ranges, they'll be able to divide out blocks of IPs to financial institutes, with security, that will make accessing them different.

Basically, a lot of changes coming diown the road in the next few years. The internet was never designed to do what it does today which is why the quality of data transfer is poor.

Changes are to come.. starting with IPv6 and all that good stuff.

------------------------------ "Alcoholism is a disease, but it's the only one you can get yelled at for having. Goddammit Otto, you are an alcoholic. Goddammit Otto, you have Lupus... one of those two doesn't sound right." M. H.
Reply to riser
- 0 +

You find it entertaining to type all that? You really need to get laid.

Reply to BigMac
- 0 +

BigMac wrote :

You find it entertaining to type all that? You really need to get laid.



Madonna will do.

It's very interresting stuff, I bet he got laid while typing that.

Reply to SyPheR
- 0 +

I think he missed the money shot.

------------------------------ Doctor Hooter
Boobs Boobs Boobs...who loves boobs?...I do I do

 

Reply to zpyrd

SyPheR catches each and every one...then swallows.

------------------------------ +35 Wingding approval points +10 Scouse approval +22 Mammary Manipulation
+5 Comedy +15 Belated Holy Points +5 Messianic Approval + 5 penile innovation
+13 Baked Ham creativity +65 Obscure Quote

Reply to KingLoftusXII
- 0 +

I'm trying to swallow your text too. Guess that you've glued it with some kind of sticky stuff. It's hard to figure out even when it's that simple. :(

Reply to SyPheR

Pretend it's sperm, then it'll go down like it normally does.

------------------------------ +35 Wingding approval points +10 Scouse approval +22 Mammary Manipulation
+5 Comedy +15 Belated Holy Points +5 Messianic Approval + 5 penile innovation
+13 Baked Ham creativity +65 Obscure Quote

Reply to KingLoftusXII
- 0 +

. .
. .
. .

------------------------------ http://www.catb.org/~esr/faqs/smart-questions.html - I WISH PEOPLE WOULD APPLY THIS!
Reply to mugz

That was Mugz's way of representing himself swallowing a fat wad of man-cream.

Reply to WingDing

Not to be confused with his representation of swallowing a small dribble of Mick muck.

------------------------------ BoM - Just another bunch of cheese eating surrender monkeys
Reply to audiovoodoo

You'd know as much about that as anyone.

Reply to WingDing

The perverts pathetic panticle potion production is matched only by that or his Mrs Philips output.

------------------------------ BoM - Just another bunch of cheese eating surrender monkeys
Reply to audiovoodoo

You guys ain't gonna let that go, are you??

Reply to WingDing

I doubt it by the reoccurance that's fuelled by the persistence of the board here.

That's the Wingding CC Bill Board or if you like WCCBB.

Reply to Vokofpolisiekar

The Wingding CC Bunch of Bastages, more like...

Reply to WingDing

You've been stingy with those too recently. Credit crunch hitting you hard?

------------------------------ +46.53 Pedantry/+75 Wingding Approval/+27 Vindictive bastard/+7 innovative violence/+11 Scouse trophies/Bastages WD:9 RC:4 AV:1 [specials; cluster:2,leather elbow patched:1,pre-approved:3,first class (upgrade):1,multi-thread:1,double-barrel:1]
Reply to llama_man

You're all in the wrong business. Anyone heard of a crime crunch? No, I didn't think so. In fact there have been reports that insurance fraud increases are a direct result of the credit crunch. Crime is always a winner.

Reply to Tom_Smart

not for society it ain't.

remember kids, do not follow the examples of those in the other.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger

And remember to practice what you preach.

Reply to Vokofpolisiekar

Actually, I couldn't give much of a toss about the "credit crunch". Tax never goes away so I've got a job for life. Hooray!

Besides, it might help with obesity problem - a bit of poverty might encourage the fat bast*rds to buy fewer pies.

------------------------------ +46.53 Pedantry/+75 Wingding Approval/+27 Vindictive bastard/+7 innovative violence/+11 Scouse trophies/Bastages WD:9 RC:4 AV:1 [specials; cluster:2,leather elbow patched:1,pre-approved:3,first class (upgrade):1,multi-thread:1,double-barrel:1]
Reply to llama_man

or walk and cycle more to avoid fuel costs.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger

Nah, people would rather starve and be broke than actually walk anywhere. People are lazy f*ckers, in case you hadn't noticed.

------------------------------ +46.53 Pedantry/+75 Wingding Approval/+27 Vindictive bastard/+7 innovative violence/+11 Scouse trophies/Bastages WD:9 RC:4 AV:1 [specials; cluster:2,leather elbow patched:1,pre-approved:3,first class (upgrade):1,multi-thread:1,double-barrel:1]
Reply to llama_man

clearly we need cattle prods to herd them places instead of waiting for them to act by themselves, force them to save some money.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger

If there were fewer pies, what would Geordies eat?

Reply to WingDing

The Jocks. It's win, win.

Reply to Tom_Smart

i would like to see them try, also a good portion of the population are actually just bloated would be corpses who have pumped so much junk into themselves i doubt they'd be tasty.

------------------------------ I'm a git, deal with it.

Antec 1200,PC Power & Cooling 750,Gigabyte DS4-x48,Intel Q9550@3.4 W/Xigmatek S1283,8GB OCZ DDR2 800,ATI 4870X2,X-FI>CA 640C amp>Tannoy R300/Senn 595's
Reply to strangestranger

I wonder why? Could it be your nation's obsession with deep fried pizza and Mars bar fritters?

Reply to Tom_Smart

That's marginally better than lentil-eating hippies.

Reply to WingDing
- 0 +

Tom_Smart, the oven is hot. Why not step into it and see what pizza tastes like.
I'll close the oven for you.

Reply to SyPheR
- 0 +




......after you've taken out the pizza? ;)

Reply to SyPheR

That does not make any logical sense.

Reply to Vokofpolisiekar
- 0 +

Much like his existence.

------------------------------ 'Out of the abyss I come the avenger
shapeless and faceless - Yet I have a name,
I shall tighten my grip on your now flawed creation,
endeavour to show you the meaning of pain.'
Reply to RobD
- 0 +

True, that.

------------------------------ http://www.catb.org/~esr/faqs/smart-questions.html - I WISH PEOPLE WOULD APPLY THIS!
Reply to mugz
Tom's Hardware > Forum > Old Man/Woman's Club > Other > Internet encryption allready possible but where is it?
Go to:

There are 1298 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them