<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Nokia Xpress Browser servers found to decrypt HTTPS traffic, an update issued</title>
	<atom:link href="http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/</link>
	<description>GSMArena Blog: Geeks at large is a project of GSMArena.com team, discussing all things high-tech - mobile phones, computers, digcams and more...</description>
	<lastBuildDate>Wed, 22 May 2013 21:07:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Ahmed Mustafa Nematallah</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-699301</link>
		<dc:creator>Ahmed Mustafa Nematallah</dc:creator>
		<pubDate>Mon, 14 Jan 2013 13:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-699301</guid>
		<description><![CDATA[well, think about it, the browser doesn&#039;t use SSL at all, it&#039;s nokia&#039;s servers that do during the connection with the website, but when connecting to you, it&#039;s insecure, that&#039;s the problem, nokia&#039;s servers MUST decrypt the message before sending it to you in order to be able to compress it, it&#039;s not a real browser, it&#039;s a special browser that doesn&#039;t work with HTTP, HTML, SSL, FTP or any web standards, it mainly deals with some compressed format that nokia makes (and I think it&#039;s prerendered too), so simply

You-------&gt;Nokia&#039;s server (not SSL, a missing feature in nokia&#039;s browser)

Nokia&#039;s server------&gt;website (Encrypted, because that&#039;s the real connection, the one that relies on web standards)

to make it even simpler it&#039;s like downloading a webpage on your computer then copying it to your mobile phone, so the computer&#039;s connection to the server is encrypted, but the connection between the mobile phone and the computer isn&#039;t


BTW what would nokia do with your data, they don&#039;t sell it to advertisers like google and facebook]]></description>
		<content:encoded><![CDATA[<p>well, think about it, the browser doesn&#8217;t use SSL at all, it&#8217;s nokia&#8217;s servers that do during the connection with the website, but when connecting to you, it&#8217;s insecure, that&#8217;s the problem, nokia&#8217;s servers MUST decrypt the message before sending it to you in order to be able to compress it, it&#8217;s not a real browser, it&#8217;s a special browser that doesn&#8217;t work with HTTP, HTML, SSL, FTP or any web standards, it mainly deals with some compressed format that nokia makes (and I think it&#8217;s prerendered too), so simply</p>
<p>You&#8212;&#8212;-&gt;Nokia&#8217;s server (not SSL, a missing feature in nokia&#8217;s browser)</p>
<p>Nokia&#8217;s server&#8212;&#8212;&gt;website (Encrypted, because that&#8217;s the real connection, the one that relies on web standards)</p>
<p>to make it even simpler it&#8217;s like downloading a webpage on your computer then copying it to your mobile phone, so the computer&#8217;s connection to the server is encrypted, but the connection between the mobile phone and the computer isn&#8217;t</p>
<p>BTW what would nokia do with your data, they don&#8217;t sell it to advertisers like google and facebook</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DumbFurfag</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-699199</link>
		<dc:creator>DumbFurfag</dc:creator>
		<pubDate>Sun, 13 Jan 2013 21:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-699199</guid>
		<description><![CDATA[Yes, they don&#039;t literally &quot;crack&quot; it. I should have used a different choice of words.

If I&#039;m right in guessing how it works, the browser forwards the https deciphering key to the servers. The servers decrypt your data (as if it were you doing it) and compress it and send it back to you. It&#039;s completely irrelevant if they re-encipher it, because the security was already compromised, even just in one point (on Nokia&#039;s servers).

No one spying on your connection can intercept https, unless your system is compromised too and they have full access to your computer&#039;s memory. Or unless they have a supercomputer to brute-force crack your encrypted data.]]></description>
		<content:encoded><![CDATA[<p>Yes, they don&#8217;t literally &#8220;crack&#8221; it. I should have used a different choice of words.</p>
<p>If I&#8217;m right in guessing how it works, the browser forwards the https deciphering key to the servers. The servers decrypt your data (as if it were you doing it) and compress it and send it back to you. It&#8217;s completely irrelevant if they re-encipher it, because the security was already compromised, even just in one point (on Nokia&#8217;s servers).</p>
<p>No one spying on your connection can intercept https, unless your system is compromised too and they have full access to your computer&#8217;s memory. Or unless they have a supercomputer to brute-force crack your encrypted data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Remus</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-699141</link>
		<dc:creator>Adrian Remus</dc:creator>
		<pubDate>Sun, 13 Jan 2013 19:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-699141</guid>
		<description><![CDATA[why are you a hater?]]></description>
		<content:encoded><![CDATA[<p>why are you a hater?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr_Data</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-699048</link>
		<dc:creator>Mr_Data</dc:creator>
		<pubDate>Sun, 13 Jan 2013 07:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-699048</guid>
		<description><![CDATA[Not the first idiotic act by Nokia:).]]></description>
		<content:encoded><![CDATA[<p>Not the first idiotic act by Nokia:).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr_Data</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-699047</link>
		<dc:creator>Mr_Data</dc:creator>
		<pubDate>Sun, 13 Jan 2013 07:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-699047</guid>
		<description><![CDATA[You don&#039;t have a clue! You don&#039;t even bother to read what the person before you wrote.]]></description>
		<content:encoded><![CDATA[<p>You don&#8217;t have a clue! You don&#8217;t even bother to read what the person before you wrote.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JK</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-698978</link>
		<dc:creator>JK</dc:creator>
		<pubDate>Sat, 12 Jan 2013 19:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-698978</guid>
		<description><![CDATA[What is the issue? Nokia already said they don&#039;t record the data - thats not how the system was designed.


You any of you seriously think you are being snooped on by Nokia? Get real. And get a life. Nokia has more pressing matters to attend to... such as evaluating their exclusive MS contract.]]></description>
		<content:encoded><![CDATA[<p>What is the issue? Nokia already said they don&#8217;t record the data &#8211; thats not how the system was designed.</p>
<p>You any of you seriously think you are being snooped on by Nokia? Get real. And get a life. Nokia has more pressing matters to attend to&#8230; such as evaluating their exclusive MS contract.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed Mustafa Nematallah</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-698972</link>
		<dc:creator>Ahmed Mustafa Nematallah</dc:creator>
		<pubDate>Sat, 12 Jan 2013 19:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-698972</guid>
		<description><![CDATA[why did you buy it (if you even have one)]]></description>
		<content:encoded><![CDATA[<p>why did you buy it (if you even have one)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple ® Royalty</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-698944</link>
		<dc:creator>Apple ® Royalty</dc:creator>
		<pubDate>Sat, 12 Jan 2013 16:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-698944</guid>
		<description><![CDATA[We have the iPhone, iPad, and Mac which are the magical things in our life
We see nothing is good beside Apple
We will destroy Samsung and others
We know this
We like this
We love that.





Posted from my iPhone 5.]]></description>
		<content:encoded><![CDATA[<p>We have the iPhone, iPad, and Mac which are the magical things in our life<br />
We see nothing is good beside Apple<br />
We will destroy Samsung and others<br />
We know this<br />
We like this<br />
We love that.</p>
<p>Posted from my iPhone 5.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed Mustafa Nematallah</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-698938</link>
		<dc:creator>Ahmed Mustafa Nematallah</dc:creator>
		<pubDate>Sat, 12 Jan 2013 15:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-698938</guid>
		<description><![CDATA[guys, it&#039;s not about spying, the HTTPS connection starts at nokia&#039;s servers and ends there, they fetch the page by their servers, so it&#039;s normal for the connection to end there, the connection between the nokia servers and the website is encrypted

the problem is that the connection between you and nokia&#039;s servers isn&#039;t encrypted, which means anyone spying on you can get your information (if they can decode the nokia xpress format), nokia fixed that error, or missing feature, or bug, whatever you call it

for those who think that it isn&#039;t normal, when there is a server between you and the website, the info. must be decrypted there, as it&#039;s resent in a format the application can understand, like in opera mini


to make it simpler, it&#039;s like you sending a mail to a translator, who translates it to another language, he must open it, even if it&#039;s secure, then resend it to your destination, now the translator forgot to resecure it again, so anyone along the path can read the translated unsecured message



BTW if the connection was as you guys thought, how would you know if nokia decrypted the stuff on their servers?]]></description>
		<content:encoded><![CDATA[<p>guys, it&#8217;s not about spying, the HTTPS connection starts at nokia&#8217;s servers and ends there, they fetch the page by their servers, so it&#8217;s normal for the connection to end there, the connection between the nokia servers and the website is encrypted</p>
<p>the problem is that the connection between you and nokia&#8217;s servers isn&#8217;t encrypted, which means anyone spying on you can get your information (if they can decode the nokia xpress format), nokia fixed that error, or missing feature, or bug, whatever you call it</p>
<p>for those who think that it isn&#8217;t normal, when there is a server between you and the website, the info. must be decrypted there, as it&#8217;s resent in a format the application can understand, like in opera mini</p>
<p>to make it simpler, it&#8217;s like you sending a mail to a translator, who translates it to another language, he must open it, even if it&#8217;s secure, then resend it to your destination, now the translator forgot to resecure it again, so anyone along the path can read the translated unsecured message</p>
<p>BTW if the connection was as you guys thought, how would you know if nokia decrypted the stuff on their servers?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed Mustafa Nematallah</title>
		<link>http://blog.gsmarena.com/nokia-xpress-browser-found-to-decrypt-https-traffic/comment-page-1/#comment-698937</link>
		<dc:creator>Ahmed Mustafa Nematallah</dc:creator>
		<pubDate>Sat, 12 Jan 2013 15:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.gsmarena.com/?p=42843#comment-698937</guid>
		<description><![CDATA[they didn&#039;t crack the HTTPS, they send it to you decrypted, that&#039;s the problem, anyone spying on your connection would get your personal info.


that was a missing feature, or a bug, whatever you call it, they should&#039;ve encrypted it from the beginning]]></description>
		<content:encoded><![CDATA[<p>they didn&#8217;t crack the HTTPS, they send it to you decrypted, that&#8217;s the problem, anyone spying on your connection would get your personal info.</p>
<p>that was a missing feature, or a bug, whatever you call it, they should&#8217;ve encrypted it from the beginning</p>
]]></content:encoded>
	</item>
</channel>
</rss>
