Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: goldstategop; OL Hickory; Darksheare
In plain English, FR lost its connection to the Internet for several hours.

But how can we be sure this is the real Free Republic? It could be a dirty imposter and the real Free Republic could be bound in duct tape and locked in a closet somewhere!

56 posted on 01/05/2011 8:33:12 PM PST by Grizzled Bear ("Does not play well with others.")
[ Post Reply | Private Reply | To 10 | View Replies ]


To: Grizzled Bear
But how can we be sure this is the real Free Republic? It could be a dirty imposter and the real Free Republic could be bound in duct tape and locked in a closet somewhere!

We can't, unless FR switches from HTTP to HTTPS.

But simulating FR would be a big job for a phisher. The average phisher is much more interested in arranging a wire transfer from your bank to Lagos or Semipalatinsk. That's why banks use HTTPS — your browser will complain that the SSL certificate the phisher is using doesn't match the bank's and will refuse to complete the connection unless you approve an exception. My bank goes even further. It shows me a secret picture every time I log in. A phisher might have every detail about my bank's web site down pat, but he still wouldn't know which picture to show me.

A simpler hack on FR, which requires the real FR to be running, would be to hack your DNS so that FR goes to the phisher's proxy server, which faithfully relays (and logs) all communication between you and the real FR, except when it doesn't.

537 posted on 01/07/2011 8:17:00 AM PST by cynwoody
[ Post Reply | Private Reply | To 56 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson