• thawed_caveman@lemmy.world
    link
    fedilink
    arrow-up
    30
    ·
    5 months ago

    Does this matter if the traffic is encrypted, such as an https website instead of http? Like, really how often is internet traffic unencrypted?

    • beveradb@lemm.ee
      link
      fedilink
      arrow-up
      20
      ·
      5 months ago

      Yes, back when I was playing around with my WiFi pineapple there were a wide variety of tricks to break SSL authentication without it being obvious to users. Easiest was to terminate the SSL connection on the pineapple and re-encrypt it with a new SSL cert from there to the users browser, so to the user it looked like everything was secure but in reality their traffic was only encrypted from them to the pineapple, then decrypted, sniffed and re-encrypted to pass along to the target websites with normal SSL.

      Man in the middle attacks really do give the attacker tons of options

      • kahdbrixk@feddit.de
        link
        fedilink
        arrow-up
        17
        ·
        5 months ago

        That kind of ssl interception would normally be quite visible without your client device having the pineapples cert in your devices trust store, or am I wrong?

        • beveradb@lemm.ee
          link
          fedilink
          arrow-up
          8
          ·
          edit-2
          5 months ago

          I’m sure a lot has changed in 10 years ago so this won’t be relevant today, but back when I was last playing with this, sslstrip was the tool I was using on the pineapple to enable SSL mitm attacks - https://github.com/moxie0/sslstrip

          I’d imagine there are new techniques to counteract new defenses - this stuff is always cat & mouse

    • rmuk@feddit.uk
      link
      fedilink
      English
      arrow-up
      19
      ·
      5 months ago

      Not often. For web browsing - and the majority of apps - your session is encrypted and certified. Breaking SSL is possible but you’ll know about it due to the lack of certs.

    • SpaceCowboy
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      Yeah they probably wouldn’t get your passwords, but they would know you’re browsing pornhub or whatever. They know who you’re connecting to but don’t know the data being transferred.

      And pretty much everything is https nowadays.

      But still… I’d be using a VPN.