<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How Do Transcoders Affect HTTPS?</title>
	<atom:link href="http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/</link>
	<description>The ticket machine in your pocket</description>
	<lastBuildDate>Sat, 23 Jan 2010 20:27:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Martin</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-60</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Fri, 30 Jan 2009 07:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-60</guid>
		<description>Hi Tom,&lt;br/&gt;&lt;br/&gt;the APN config had no Web proxy configuration so I guess it is the &quot;Internet&quot; configuration.&lt;br/&gt;&lt;br/&gt;Kind regards,&lt;br/&gt;Martin</description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>the APN config had no Web proxy configuration so I guess it is the &#8220;Internet&#8221; configuration.</p>
<p>Kind regards,<br />Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Godber</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-59</link>
		<dc:creator>Tom Godber</dc:creator>
		<pubDate>Wed, 28 Jan 2009 11:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-59</guid>
		<description>Hi Martin,&lt;br/&gt;&lt;br/&gt;I can actually quite believe that the bank is being whitelisted by the transcoder, however I doubt Bugzilla is.  Do you know which network settings your browser was using - Wap or Internet?  I believe that only one of these (Wap?) uses the Novarra transcoder, the other does not.&lt;br/&gt;&lt;br/&gt;As I said I&#039;m going to plan some more research of this and will post up the results, but all interesting to know!&lt;br/&gt;&lt;br/&gt;Tom</description>
		<content:encoded><![CDATA[<p>Hi Martin,</p>
<p>I can actually quite believe that the bank is being whitelisted by the transcoder, however I doubt Bugzilla is.  Do you know which network settings your browser was using &#8211; Wap or Internet?  I believe that only one of these (Wap?) uses the Novarra transcoder, the other does not.</p>
<p>As I said I&#8217;m going to plan some more research of this and will post up the results, but all interesting to know!</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-58</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 27 Jan 2009 22:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-58</guid>
		<description>Hi Tom, thanks for the feedback! &lt;br/&gt;&lt;br/&gt;I have checked with a Vodafone UK prepaid SIM (APN: pp.vodafone.co.uk), a Nokia N95 and the S60 browser and the mobile banking portal of the German postbank (https://mobile.postbank.de). The https connection was established end to end and the certificate shown in &quot;tools - page info&quot; showed the correct owner (mobile.postbank.de, Deutsche Postbank AG) and the correct Issuer (VeriSign Trust Network). &lt;br/&gt;&lt;br/&gt;I cross-checked with Firefox on the PC and the certificate information including the fingerprint were the same. So if the prepaid connection uses a transcoder, it doesn&#039;t brake into this connection. Also, it seems unlikely, Voda UK &quot;whitelists&quot; the German postbank. Not impossible, but unlikely :-)&lt;br/&gt;&lt;br/&gt;I also tried with https://bugzilla.mozilla.org and the https certificate in the S60 browser was also o.k. so the connection was end to end.&lt;br/&gt;&lt;br/&gt;Do you know specific operators who break into HTTPS connections?&lt;br/&gt;&lt;br/&gt;Cheers,&lt;br/&gt;Martin</description>
		<content:encoded><![CDATA[<p>Hi Tom, thanks for the feedback! </p>
<p>I have checked with a Vodafone UK prepaid SIM (APN: pp.vodafone.co.uk), a Nokia N95 and the S60 browser and the mobile banking portal of the German postbank (<a href="https://mobile.postbank.de)" rel="nofollow">https://mobile.postbank.de)</a>. The https connection was established end to end and the certificate shown in &#8220;tools &#8211; page info&#8221; showed the correct owner (mobile.postbank.de, Deutsche Postbank AG) and the correct Issuer (VeriSign Trust Network). </p>
<p>I cross-checked with Firefox on the PC and the certificate information including the fingerprint were the same. So if the prepaid connection uses a transcoder, it doesn&#8217;t brake into this connection. Also, it seems unlikely, Voda UK &#8220;whitelists&#8221; the German postbank. Not impossible, but unlikely <img src='http://www.masabi.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>I also tried with <a href="https://bugzilla.mozilla.org" rel="nofollow">https://bugzilla.mozilla.org</a> and the https certificate in the S60 browser was also o.k. so the connection was end to end.</p>
<p>Do you know specific operators who break into HTTPS connections?</p>
<p>Cheers,<br />Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Godber</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-57</link>
		<dc:creator>Tom Godber</dc:creator>
		<pubDate>Tue, 27 Jan 2009 12:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-57</guid>
		<description>Hi Martin,&lt;br/&gt;&lt;br/&gt;I think the sad truth here is that you are absolutely right, a mobile browser *should* make the user aware of a man in the middle attack and a transcoder. However we know a number do not actively do this (the user has to know to check the certificate).&lt;br/&gt;&lt;br/&gt;I am going to do a follow-up post after looking into this in more detail, hopefully showing what browsers do show with and without transcoders on mainstream handsets.&lt;br/&gt;&lt;br/&gt;Tom</description>
		<content:encoded><![CDATA[<p>Hi Martin,</p>
<p>I think the sad truth here is that you are absolutely right, a mobile browser *should* make the user aware of a man in the middle attack and a transcoder. However we know a number do not actively do this (the user has to know to check the certificate).</p>
<p>I am going to do a follow-up post after looking into this in more detail, hopefully showing what browsers do show with and without transcoders on mainstream handsets.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-55</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Mon, 26 Jan 2009 16:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-55</guid>
		<description>Hi,&lt;br/&gt;&lt;br/&gt;Very interesting post, thanks for that! I have one question which you might be able to answer:&lt;br/&gt;&lt;br/&gt;In case a transcoder would try to put itself in the middle of a HTTPS connection, doesn&#039;t the mobile web browser issue a certificate warning? If not then how can it differentiate between a transcoder and a man in the middle attack?&lt;br/&gt;&lt;br/&gt;Thanks,&lt;br/&gt;Martin</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Very interesting post, thanks for that! I have one question which you might be able to answer:</p>
<p>In case a transcoder would try to put itself in the middle of a HTTPS connection, doesn&#8217;t the mobile web browser issue a certificate warning? If not then how can it differentiate between a transcoder and a man in the middle attack?</p>
<p>Thanks,<br />Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: srowen</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-54</link>
		<dc:creator>srowen</dc:creator>
		<pubDate>Sat, 24 Jan 2009 12:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-54</guid>
		<description>Well explained, great post.</description>
		<content:encoded><![CDATA[<p>Well explained, great post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anna Gudmundson</title>
		<link>http://www.masabi.com/2009/01/23/how-do-transcoders-affect-https/comment-page-1/#comment-53</link>
		<dc:creator>Anna Gudmundson</dc:creator>
		<pubDate>Fri, 23 Jan 2009 13:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://masabi.com/2009/01/how-do-transcoders-affect-https.html#comment-53</guid>
		<description>Thanks for good post. It&#039;s important to spread awareness of these fundamental matters. &lt;br/&gt;I&#039;ll pass it on. Cheers.</description>
		<content:encoded><![CDATA[<p>Thanks for good post. It&#8217;s important to spread awareness of these fundamental matters. <br />I&#8217;ll pass it on. Cheers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
