<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Yubikey, Trojans and Twitter</title>
	<atom:link href="http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/#comment-36696</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 03 Dec 2009 17:19:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1684#comment-36696</guid>
		<description><![CDATA[OTPs have to be intercepted and queued for this to work. If you exclude trojans and HTTP(S) man-in-the-middle, then yes, it will not work.]]></description>
		<content:encoded><![CDATA[<p>OTPs have to be intercepted and queued for this to work. If you exclude trojans and HTTP(S) man-in-the-middle, then yes, it will not work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger Heathcote</title>
		<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/#comment-36672</link>
		<dc:creator><![CDATA[Roger Heathcote]]></dc:creator>
		<pubDate>Thu, 03 Dec 2009 04:35:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1684#comment-36672</guid>
		<description><![CDATA[If Alice or Bob have a local keylogging trojan on their machines then yes, I can see how it&#039;s game over for them but I meant solve in the context of the local LAN or wider internet.

I was under the impression that as the latest TLS revision fixes https&#039; arp poisoning vulnerability in a local LAN context that once a secure connection is established by visiting the logon page then no further snooping / interference would be possible from machines on the LAN or the internet. Is this not correct? Sorry if I&#039;m being dense but I&#039;d like to understand the threat as I&#039;m considering creating a yubikey secured product sometime next year!

Thanks,

Roger.]]></description>
		<content:encoded><![CDATA[<p>If Alice or Bob have a local keylogging trojan on their machines then yes, I can see how it&#8217;s game over for them but I meant solve in the context of the local LAN or wider internet.</p>
<p>I was under the impression that as the latest TLS revision fixes https&#8217; arp poisoning vulnerability in a local LAN context that once a secure connection is established by visiting the logon page then no further snooping / interference would be possible from machines on the LAN or the internet. Is this not correct? Sorry if I&#8217;m being dense but I&#8217;d like to understand the threat as I&#8217;m considering creating a yubikey secured product sometime next year!</p>
<p>Thanks,</p>
<p>Roger.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/#comment-36656</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 02 Dec 2009 21:33:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1684#comment-36656</guid>
		<description><![CDATA[No, as a Trojan can intercept HTTPS before the data stream gets encrypted.]]></description>
		<content:encoded><![CDATA[<p>No, as a Trojan can intercept HTTPS before the data stream gets encrypted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger Heathcote</title>
		<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/#comment-36649</link>
		<dc:creator><![CDATA[Roger Heathcote]]></dc:creator>
		<pubDate>Wed, 02 Dec 2009 06:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1684#comment-36649</guid>
		<description><![CDATA[If the client and server are using the latest TLS (that fixes the recent session renegotiation bug similar to the attack you describe above) then wouldn&#039;t ensuring the server only offers sensitive pages over https solve the problem?

Roger Heathcote.]]></description>
		<content:encoded><![CDATA[<p>If the client and server are using the latest TLS (that fixes the recent session renegotiation bug similar to the attack you describe above) then wouldn&#8217;t ensuring the server only offers sensitive pages over https solve the problem?</p>
<p>Roger Heathcote.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Hay &#187; Blog Archive &#187; links for 2009-08-26</title>
		<link>http://blog.didierstevens.com/2009/08/26/yubikey-trojans-and-twitter/#comment-35534</link>
		<dc:creator><![CDATA[Andrew Hay &#187; Blog Archive &#187; links for 2009-08-26]]></dc:creator>
		<pubDate>Wed, 26 Aug 2009 20:05:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1684#comment-35534</guid>
		<description><![CDATA[[...] Yubikey, Trojans and Twitter « Didier Stevens (tags: yubikey otp) [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Yubikey, Trojans and Twitter « Didier Stevens (tags: yubikey otp) [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

