Date: Wed, 21 Jun 2006 00:20:36 -0700 From: Luigi Rizzo <rizzo@icir.org> To: John Birrell <jb@what-creek.com> Cc: freebsd-current@freebsd.org, Harti Brandt <harti@freebsd.org> Subject: Re: ~/.hosts patch Message-ID: <20060621002036.A6576@xorpc.icir.org> In-Reply-To: <20060621070739.GB35132@what-creek.com>; from jb@what-creek.com on Wed, Jun 21, 2006 at 07:07:39AM %2B0000 References: <C41481BC-89F3-457E-9FD0-CB85CE7B93E7@eecs.cwru.edu> <4498D108.90907@rogers.com> <20060621053007.GA3320@odin.ac.hmc.edu> <4498DF20.8020803@rogers.com> <1150870137.78122.14.camel@spirit> <20060621082734.Q24109@beagle.kn.op.dlr.de> <20060621063816.GA32889@what-creek.com> <20060621000250.A6468@xorpc.icir.org> <20060621070739.GB35132@what-creek.com>
next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Jun 21, 2006 at 07:07:39AM +0000, John Birrell wrote: > On Wed, Jun 21, 2006 at 12:02:50AM -0700, Luigi Rizzo wrote: > > On Wed, Jun 21, 2006 at 06:38:16AM +0000, John Birrell wrote: > > > On Wed, Jun 21, 2006 at 08:31:36AM +0200, Harti Brandt wrote: > > > > Wouldn't this enable the same kind of phishing attacks there are under > > > > windows? As far as I remember there are attacks where the hosts file > > > > (don't remember how its called under windows) is rewriten by a virus/java > > > > script/whatever to contain a different IP address for a given hostname? > > > > Suppose someone fakes the website of www.foobank.com, then manages to > > > > insert www.foobank.com with the wrong IP address into ~/.hosts? > > > > > > Ugh. Now that is a scary thought. > > > > and that's why people use https and certificates! > > what's the concern here ? > > The fact that a lot of innocent (naive) people don't use https and certificates?! and so they would happily click on <a href="http://www.666.org/gimmeyourmoney">Secure Link to Your Bank</a> so we are not opening much in terms of security holes... cheers luigi
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060621002036.A6576>