Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Assl
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  11 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
shawn wilson  
View profile  
 More options Apr 28 2012, 4:32 am
From: shawn wilson <ag4ve...@gmail.com>
Date: Sat, 28 Apr 2012 04:32:56 -0400
Local: Sat, Apr 28 2012 4:32 am
Subject: Assl

Anyone seen this?
http://assl.sullof.com/assl/

Is there any work to get this working with node? Any interest?


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
akira  
View profile  
 More options Apr 28 2012, 8:19 am
From: akira <nhy...@googlemail.com>
Date: Sat, 28 Apr 2012 05:19:28 -0700 (PDT)
Local: Sat, Apr 28 2012 8:19 am
Subject: Re: Assl
Very interesting, it would be great to get it to work with Node or
Python. The project looks dormant. It might be taken up again if
interest is shown.

On Apr 28, 10:32 am, shawn wilson <ag4ve...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Oleg Efimov (Sannis)  
View profile   Translate to Translated (View Original)
 More options Apr 28 2012, 9:21 am
From: "Oleg Efimov (Sannis)" <efimo...@gmail.com>
Date: Sat, 28 Apr 2012 06:21:24 -0700 (PDT)
Local: Sat, Apr 28 2012 9:21 am
Subject: Re: Assl

Oops:  http://assl.sullof.com/assl/securityfaq.asp

I can't  feign any situation, when it is useful. It is not so problem to
buy sertificate and enable HTTPS on server today.

суббота, 28 апреля 2012 г., 12:32:56 UTC+4 пользователь shawn wilson
написал:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
akira  
View profile  
 More options Apr 28 2012, 4:06 pm
From: akira <nhy...@googlemail.com>
Date: Sat, 28 Apr 2012 13:06:37 -0700 (PDT)
Local: Sat, Apr 28 2012 4:06 pm
Subject: Re: Assl
Well, wildcard certs are expensive. Its would be good for apps that
have little or no funding but need security od some kind

On Apr 28, 3:21 pm, "Oleg Efimov (Sannis)" <efimo...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
shawn wilson  
View profile  
 More options Apr 28 2012, 9:03 pm
From: shawn wilson <ag4ve...@gmail.com>
Date: Sat, 28 Apr 2012 21:03:07 -0400
Local: Sat, Apr 28 2012 9:03 pm
Subject: Re: [nodejs] Re: Assl
right, it might also be good if you want secure transfers but don't
want to buy *any* cert. ie, you don't want the browser to say 'this is
an untrusted site, continue' or whatever. i realize there are inherent
risks in this. but, not much more of a security risk than ssh as long
as you store the pub key in a cookie.

2012/4/28 akira <nhy...@googlemail.com>:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
mscdex  
View profile  
 More options Apr 28 2012, 11:39 pm
From: mscdex <msc...@gmail.com>
Date: Sat, 28 Apr 2012 20:39:18 -0700 (PDT)
Local: Sat, Apr 28 2012 11:39 pm
Subject: Re: Assl
On Apr 28, 9:03 pm, shawn wilson <ag4ve...@gmail.com> wrote:

> right, it might also be good if you want secure transfers but don't
> want to buy *any* cert. ie, you don't want the browser to say 'this is
> an untrusted site, continue' or whatever. i realize there are inherent
> risks in this. but, not much more of a security risk than ssh as long
> as you store the pub key in a cookie.

Startssl.com has free SSL certificates.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Michael W  
View profile  
 More options Apr 30 2012, 2:53 pm
From: Michael W <hotdog...@gmail.com>
Date: Mon, 30 Apr 2012 11:53:51 -0700 (PDT)
Local: Mon, Apr 30 2012 2:53 pm
Subject: Re: Assl

Ew. I think this project is harmful because it offers a false sense of
security. How is the client-side encryption javascript sent to the browser
in the first place? If it's not already sent over SSL, it can be
intercepted and modified by attackers to send a copy of the cleartext to
the attacker, for example.

The reason why SSL is secure is because it's already baked into the browser
and attackers can't tamper with that machinery. This project removes that.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
shawn wilson  
View profile  
 More options Apr 30 2012, 3:10 pm
From: shawn wilson <ag4ve...@gmail.com>
Date: Mon, 30 Apr 2012 15:10:25 -0400
Local: Mon, Apr 30 2012 3:10 pm
Subject: Re: [nodejs] Re: Assl

Hummm, that's probably a good point. I can't wait to get back to a computer
and see what the code says about that.
On Apr 30, 2012 2:53 PM, "Michael W" <hotdog...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jeff Barczewski  
View profile  
 More options May 1 2012, 11:50 am
From: Jeff Barczewski <jeff.barczew...@gmail.com>
Date: Tue, 1 May 2012 08:50:58 -0700 (PDT)
Local: Tues, May 1 2012 11:50 am
Subject: Re: Assl

From the main page, it looks like it is using the server's public key to
encrypt the random session key which only the server can decrypt using its
private key, then uses the session key with AES for the duration of the
session.

So it doesn't sound like anything is sent over in the clear.

However you are correct in that it doesn't have as many safe guards as SSL
in that you don't have any independent verification that the server you are
talking to really is the legitimate server. All you know is that your
communications with this unverified server are reasonably secure. Kind of
similar to the same security we have when people generate their own
unregistered SSL certs and tell people to just accept the security warning
the browser pops up (encryption but not verification).


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Richard Marr  
View profile  
 More options May 2 2012, 7:39 am
From: Richard Marr <richard.m...@gmail.com>
Date: Wed, 2 May 2012 12:39:21 +0100
Local: Wed, May 2 2012 7:39 am
Subject: Re: [nodejs] Re: Assl

On 1 May 2012 16:50, Jeff Barczewski <jeff.barczew...@gmail.com> wrote:

> All you know is that your communications with this unverified server are

reasonably secure

You as the developer of the site might know that the data is secure. Your
users would have to take your unverified server's word for it... which I'm
sure you agree is a Bad Thing from the perspective of encouraging internet
safety.

It's an interesting lib though, it'd work for internal company apps where
there's an established level of trust/auditing/accountability.

On 1 May 2012 16:50, Jeff Barczewski <jeff.barczew...@gmail.com> wrote:

--
Richard Marr

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Felipe Sateler  
View profile  
 More options May 2 2012, 10:36 am
From: Felipe Sateler <fsate...@gmail.com>
Date: Wed, 2 May 2012 07:36:49 -0700 (PDT)
Local: Wed, May 2 2012 10:36 am
Subject: Re: Assl

On Tuesday, May 1, 2012 11:50:58 AM UTC-4, Jeff Barczewski wrote:

However you are correct in that it doesn't have as many safe guards as SSL

> in that you don't have any independent verification that the server you are
> talking to really is the legitimate server. All you know is that your
> communications with this unverified server are reasonably secure. Kind of
> similar to the same security we have when people generate their own
> unregistered SSL certs and tell people to just accept the security warning
> the browser pops up (encryption but not verification).

You also lose because you cannot control for the fact that it is actually
assl that it is running. Code can be injected (dns spoofing, browser
extensions, whatever), resulting in text not being encrypted.
Others have already explained why browser-javascript encryption is doomed
to fail, so I leave you this link:
http://www.matasano.com/articles/javascript-cryptography/

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »