@jpgoldberg Can't you use HTTPS with a private key that's protected by root perms or something?
-
-
@JudeCNelson Let me double check the necessity of root before I contradict you again. /c@taoeffect -
@jpgoldberg@taoeffect Privilege is needed to put the iface into promisc mode. But that's not necessary to impersonate if you use port >1024 -
@JudeCNelson tl;dr. We are (still) working on this. /c@taoeffect -
@jpgoldberg@taoeffect Gotcha; thanks for the links! -
@JudeCNelson This is why unauthenticated DH isn’t a solution. Mutual authentication is what we really need. /c@taoeffect -
@jpgoldberg@JudeCNelson@muneeb err, ignore deleted tweet re tcpdump. It does require root, but not if you installed Wireshark apparently -
@taoeffect@jpgoldberg@muneeb Moreover, a setuid/setgid-root program can still be run by an unprivileged user.
End of conversation
New conversation -
-
-
@JudeCNelson I’m standing by root required unless you’ve lowered requirements. Perhaps when installing Wireshark? /c@taoeffect -
@jpgoldberg@JudeCNelson Root isn't required for the impersonation attack (launch b4 1pw, bind, wait for pw)
End of conversation
New conversation -
-
-
@JudeCNelson Impersonation is the tricky part. We’ve got defeasible “tricks” and “hacks” for that. … /c@taoeffectThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.