{"id":3857,"date":"2023-07-29T06:37:32","date_gmt":"2023-07-29T06:37:32","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=3857"},"modified":"2023-07-29T06:42:53","modified_gmt":"2023-07-29T06:42:53","slug":"what-can-people-really-see-when-you-use-un-encrypted-connections","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=3857","title":{"rendered":"What can people really see when you use un-encrypted connections?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Although its becoming increasingly rare nowadays to be using un-encrypted connections, let&#8217;s see what it really means at the network level. Un-encrypted connections on their own are not necessarily a problem, its all about what value what you are sending has and therefore what could be exposed to a nefarious actor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are viewing the weather information from a public website does it matter if this content is un-encrypted? probably not its not of any value, what would a hacker gain by reading this content, which they could just get themselves!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But taking another example, what if you were logging onto that same website with a username and password to get the weather information, would you want that username and password exposed? Maybe, maybe not, what if you&#8217;ve used that same username and password on another website, you don&#8217;t right? :), perhaps a website you&#8217;re more concerned about?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">All Clear?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This week I was showing other engineers what un-encrypted really means in practice, sure this is a simple demonstration and requires the network traffic from the monitored machine to be intercepted physically, via a spanned\/mirrored switch port; but you can clearly see the implications, think if you were sending traffic un-encrypted on a wireless link in a coffee shop, or worse if it was an evil twin!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I challenged an engineer to use an un-encrypted protocol e.g. Telnet to attempt to login to a switch, of course they were told not to use their real credentials, I just wanted them to use a password\/phrase and i&#8217;d be able to tell them what they typed without seeing it directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using Wireshark the packet capture was taken, and well its quite clear what the passwords used were: &#8220;mypassword&#8221; and &#8220;cheese&#8221;.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"778\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11-1024x778.png\" alt=\"\" class=\"wp-image-3858\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11-1024x778.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11-300x228.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11-768x584.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11-136x102.png 136w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2023\/07\/image-11.png 1333w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, what can people really see? Well everything, it means its completely &#8220;cleartext&#8221;, sure it might be mixed up with control characters and\/or split across many packets, but the information is there and available for anyone who has access to the packets to read.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, ensure you use protocols that are encrypted and when using a website where you need to log in ensure you&#8217;re seeing the &#8220;padlock&#8221; so you&#8217;re using HTTPS which is encrypted and not HTTP which is not and especially when you&#8217;re on a public or un-trusted network.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Although its becoming increasingly rare nowadays to be using un-encrypted connections, let&#8217;s see what it really means at the network level. Un-encrypted connections on their own are not necessarily a problem, its all about what value what you are sending has and therefore what could be exposed to a nefarious actor. If you are viewing &#8230; <a title=\"What can people really see when you use un-encrypted connections?\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=3857\" aria-label=\"Read more about What can people really see when you use un-encrypted connections?\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":3860,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31,20,47],"tags":[],"class_list":["post-3857","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fundamentals","category-random","category-wireshark"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/3857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3857"}],"version-history":[{"count":3,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/3857\/revisions"}],"predecessor-version":[{"id":3862,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/3857\/revisions\/3862"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/3860"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3857"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}