Skip to content
This repository has been archived by the owner on Nov 21, 2019. It is now read-only.

Man in the Middle Attacks possible! Proof is attached #804

Closed
Zwilla opened this issue Aug 2, 2017 · 4 comments
Closed

Man in the Middle Attacks possible! Proof is attached #804

Zwilla opened this issue Aug 2, 2017 · 4 comments

Comments

@Zwilla
Copy link
Contributor

Zwilla commented Aug 2, 2017

Dear Team,
as you know I worked since one month on a high security fork of MEW, called MTW.

All my research you can find here: https://github.com/Zwilla/mytokenwallet.com/blob/master/New_Features_on_MyTokenWallet.md
see No. 10 Man-in-The-Middle-Attack possible - proof!

New release is in online: https://myTokenWallet.com

Proof! Test it by your self! MITM-Attack

  • on that case google itself plays the man in the middle: Try translate MEW
  • MTW is resistant - MTW
  • A google security issue, can someone tell google translator team to stop hacking our code?

Dear Team,
If you want to learn about how to protect read this:
https://en.wikipedia.org/wiki/Man-in-the-middle_attack#Defense_and_detection


p.s. Your current code is also not resistant against MITB Attacks- PDF of Sans.org! USERS - Stop using Safari browser <= Version 10.1.2 (12603.3.8), yes it is the current version. Only on the Safari Technology Preview the bug is fixed!

Today I will make a video to proof that Safari is an infected and buggy browser <= Version 10.1.2 (12603.3.8)

@Zwilla Zwilla changed the title Man in the Middle Attacks possible! Man in the Middle Attacks possible! Proof is attached Aug 2, 2017
@409H
Copy link
Contributor

409H commented Aug 2, 2017

I'm unsure you understand the function and communication layers of Google Translate.
It's simply a HTTPS proxy - not really a MiTM attack.

MEW has a (EV) ssl cert also, so if the certificate is invalid, it will prevent communication.

@Zwilla
Copy link
Contributor Author

Zwilla commented Aug 2, 2017

  1. Did I wrote MiTM attack or did I wrote MiTM attack - possible?
  2. If a proxy cracks files and serve them later to you and the browser executes them, then we talk from a MiTM job.

Sorry 409h, but I think you did not fully understand this.

@409H
Copy link
Contributor

409H commented Aug 2, 2017

If a proxy cracks files

What do you mean?

I think this is a non-issue to be honest. Who runs MyEtherWallet via proxy/Google Translate when;

  1. MyEtherWallet is supported in a lot of languages.
  2. The official site is served over SSL.
  3. You can download and run it locally.

I feel your argument is just against using MyEtherWallet over Google Translate, which is limited and probably not happening by anyone, so a non-issue.

Can you expand, please.

@MyEtherWallet MyEtherWallet deleted a comment from kevinmonahan Aug 2, 2017
@gamalielhere
Copy link
Collaborator

Closing this issue. Don't hesitate to reopen if needed.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants