Re: No SSL Should I care?



Thanks. I am sufficiently scared to not try it then. I'll either fix my
server issue or keep using Verizon's Wireless Sync which does use AES
encryption.

Thanks for the reply.


"Chris De Herrera" <spam@xxxxxxxxxxxxxxxx> wrote in message
news:uD3yYoMHJHA.1160@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
You are asking an statistics question about security now. I do not know
all the companies that your data will flow through unprotected starting in
the US, across the ocean and then to your destination.

Let me put it different way, any individual that has access to capture
data can get your username, password and e-mail. Since the username and
password are the same for your network, then the network is also
vulnerable.

--
Chris De Herrera
http://www.pocketpcfaq.com
http://www.pocketpctalk.com
http://www.tabletpctalk.com
http://www.mobilitytalk.com



"JRB" <JRBf@xxxxxxxxxx> wrote in message
news:OZymgaCHJHA.4600@xxxxxxxxxxxxxxxxxxxxxxx
Thanks for the reply.

I was going to use activesync over wifi in europe since my 730 won't work
there. Will I have issues with people able to steal usernames/passwords
etc as I log in using wifi with no SSL? Is that likely? What do they
have to do to get the data since I will be on a boat using their wifi and
using brand name hotels wifi.

I can't use a local cert because I have an invalid common name in my host
name field or some such thing. I also have a samsung I760 running WM
6.1 and I couldn't get that to work using SSL either.


"Chris De Herrera" <spam@xxxxxxxxxxxxxxxx> wrote in message
news:OoOV323GJHA.3628@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
Yes you should care about not having SSL to sync with SBS. SSL secures
your data from being accessible over the internet by others because it
is encrypted. The risk depends on where and how you connect to the
internet and the people that have access to those systems including all
the communications from each site to your server. Any one of them could
capture your data.

You can always use a locally issued cert on the SBS server, export it on
your PC and install it on your i730.

--
Chris De Herrera
http://www.pocketpcfaq.com
http://www.pocketpctalk.com
http://www.tabletpctalk.com
http://www.mobilitytalk.com

"JRB" <JRBf@xxxxxxxxxx> wrote in message
news:%23wkbXzwGJHA.728@xxxxxxxxxxxxxxxxxxxxxxx
I have a server running SBS 2003. I have a Samsung I760 pocket pc
running WM 6.0 and a Samsung I730 running WM 5. Verizon is my carrier.

Normally, I run Verizon's wireless sync program and as I understand it,
that provides SSl encryption between my server and the verizon web
pages it syncronizes with and verizon itself provides some encryption
while my data is being transmitted between towers.

I just started using my 730 as a wifi only phone. I had to activate
activesync since I can only have 1 active phone. Problem is that I am
not a tech guy and have never been able to correctly install a
certificate on my server so I have to leave the SSL box unchecked on my
730. It works fine and synchronizes fine also.

My question is do I really care that SSL is unchecked? What are the
possible security problems and what is the REALISTIC risk that
something bad will happen? What kind of bad things can happen? You
get the point <G> Can I just keep using activesync over wifi since the
risks are so small? I know the official microsoft position has to be
to use SSL but I just want to know the risks and likely outcome of this
choice.

Thanks in advance for any help you can offer.







.



Relevant Pages

  • Re: encrypt password for webservices
    ... When you say about limitation of IIS/SLL (I assume it should be SSL) ... > 3) Requests can be multi-threaded, and some requests can even be droped if ... which allows the server to find appropriate EncryptionKey ... > encryption. ...
    (microsoft.public.dotnet.security)
  • Help with SSL for Exchange 2003
    ... I hope somebody could help me with SSL. ... and Outlook, however, I cannot get SMTP to work properly. ... If I select SSL encryption the error I get is: "Your server does not ...
    (microsoft.public.exchange.admin)
  • Re: Can encryrpted packets be cracked by middle man?
    ... But when you add that "someone who has complete control ... ssl connection to the proxy server which then communicates with the web ... server which could be either http or https as is that possibility with ISA. ... > This is a question about how secure encryption is. ...
    (microsoft.public.security)
  • Re: SSL Encryption Test
    ... Client side initiated SSL encryption and server-side SSL encryption. ... Server side SSL encryption is enabled via the "Force Protocol Encryption" ...
    (microsoft.public.sqlserver.security)
  • Re: criticism of web based password manager requested
    ... going to work (different encryption key (obvious because you can't ... The js being untrustworthy on a server you don't maintain is agan the ... With the correct js in place i don't have to trust ANYTHING ... Yes I can throw ssl on it and use ...
    (sci.crypt)

Loading