Re: [Fed-Talk] iChat Encryption in Lion
Re: [Fed-Talk] iChat Encryption in Lion
- Subject: Re: [Fed-Talk] iChat Encryption in Lion
- From: Joel Esler <email@hidden>
- Date: Tue, 03 Jan 2012 12:06:58 -0500
Not it is not safe. I think the 443 may be the authentication piece.
As one of the people that writes detection for Snort, no, AIM is not encrypted.
J
On Dec 20, 2011, at 12:04 PM, Pike, Michael (IHS/HQ) wrote:
> but it is safe to say that local sniffing is not possible?
>
> On Dec 20, 2011, at 7:52 AM, Danziger, Alan D. wrote:
>
>> Not really - you're conflating "travels over encrypted pipe" (SSL) vs.
>> "Contents are encrypted between sender and recipient" (secure chat).
>>
>> Misleading would be implying that you ARE fully secured, just because the
>> pipe between you and the chat server is secure. If a vendor is to err, I
>> strongly prefer they imply something is less secure than it actually is,
>> than the vice versa.
>>
>> -=Alan
>>
>> On 12/19/11 11:04 PM, "Pike, Michael (IHS/HQ)" <email@hidden>
>> wrote:
>>
>>> The why does it communicate with Oscar.aol.com<http://Oscar.aol.com> on
>>> SSL? Port 443?
>>>
>>> Isn't that misleading?
>>>
>>> Transcribed by Siri on my iPhone 4S
>>>
>>> On Dec 19, 2011, at 7:19 PM, "Ruben Brochner"
>>> <email@hidden<mailto:email@hidden>> wrote:
>>>
>>> For OS X Lion, see:
>>> "MobileMe: 'Secure iChat' is unavailable in OS X Lion"
>>> http://support.apple.com/kb/TS3902
>>>
>>> For 10.4.3 through 10.6.8, see:
>>> "MobileMe: Setting up and troubleshooting secure iChat"
>>> http://support.apple.com/kb/HT1952
>>>
>>> - Ruben
>>>
>>> On Dec 19, 2011, at 5:42 PM, Pike, Michael (IHS/HQ) wrote:
>>>
>>> I looked all around, and there was a support article on Apple¹s website
>>> which is now gone, so I am hoping someone here can answer it.
>>>
>>> iChat used to have an encryption mechanism, however, since upgrading to
>>> Lion it is gone. I did however notice SSL on port 443 is used for the
>>> Oscar aim serverŠ
>>>
>>> Can anyone on here confirm or deny that traffic is being encrypted
>>> between chats? Or is it subject to network sniffing?
>>>
>>> Thanks,
>>> Mike
>>>
>>> _______________________________________________
>>> Do not post admin requests to the list. They will be ignored.
>>> Fed-talk mailing list
>>> (email@hidden<mailto:email@hidden>)
>>> Help/Unsubscribe/Update your Subscription:
>>>
>>> This email sent to email@hidden<mailto:email@hidden>
>>>
>>> _______________________________________________
>>> Do not post admin requests to the list. They will be ignored.
>>> Fed-talk mailing list (email@hidden)
>>> Help/Unsubscribe/Update your Subscription:
>>>
>>> This email sent to email@hidden
>>
>
> _______________________________________________
> Do not post admin requests to the list. They will be ignored.
> Fed-talk mailing list (email@hidden)
> Help/Unsubscribe/Update your Subscription:
>
> This email sent to email@hidden
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden