Select your localized edition:

Close ×

More Ways to Connect

Discover one of our 28 local entrepreneurial communities »

Be the first to know as we launch in new countries and markets around the globe.

Interested in bringing MIT Technology Review to your local market?

MIT Technology ReviewMIT Technology Review - logo


Unsupported browser: Your browser does not meet modern web standards. See how it scores »

{ action.text }

Marlinspike admits that some users might notice that something is wrong because browsers often show that a connection is encrypted by placing a lock in the corner, and that would be absent. However, he says that many sites feature confusing design elements that could easily make users think that a connection is secure when it isn’t. For instance, some sites show the lock icon in the login window, informing the user that the link is supposed to lead to an encrypted page. Certain banking websites also provide no indication that they are about to switch to an encrypted connection, meaning the user may not realize that anything has gone awry. Marlinspike even showed several ways that the attack could be made more covert, by creating an encrypted link with the user.

Marlinspike tested sslstrip by collecting data from Tor, an openly accessible network for anonymizing Web traffic. Over 24 hours, he collected login details for 117 e-mail accounts, 16 credit-card numbers, 7 PayPal logins, and 300 other postings that were intended to be secure. He monitored to see if anyone would balk at using an insecure connection; no one did.

Dan Kaminsky, a well-known security researcher and director of penetration testing for the Seattle-based security company IOActive, says that Marlinspike has expertly exploited several problems that have been known about for years. “It’s not like [those problems are] going away,” Kaminsky says, “and that matters.”

Kaminsky adds that the problem does not lie with Web browsers, website owners, or users. “What we’re doing isn’t working,” he says. “I think we’re missing critical pieces of infrastructure that we need to secure the Internet.”

One way to add another layer of security to the Internet, Kaminsky argues, would be to introduce a new secure protocol called DNSSEC, for linking Web servers to domain names. He believes that DNSSEC could be configured to instruct browsers to connect to certain sites using only an “https” connection.

Marlinspike is skeptical that such a major overhaul of the Web’s existing structure would work. He also says that owners of websites could introduce design changes to help make the difference between a secure connection and an insecure one clearer. Ultimately, however, he believes that a proper solution will be elusive so long as most traffic is sent over the Internet in an insecure fashion.

2 comments. Share your thoughts »

Credit: Technology Review

Tagged: Computing, security, Internet, browser

Reprints and Permissions | Send feedback to the editor

From the Archives


Introducing MIT Technology Review Insider.

Already a Magazine subscriber?

You're automatically an Insider. It's easy to activate or upgrade your account.

Activate Your Account

Become an Insider

It's the new way to subscribe. Get even more of the tech news, research, and discoveries you crave.

Sign Up

Learn More

Find out why MIT Technology Review Insider is for you and explore your options.

Show Me