I was in an interview this morning. And all we discussed was around HSTS and SSL. I must say all Cyber Security folks should be aware of your channel. If I had watched this video earlier, I would rock the interview. Great videos mate!! Keep up the good work!! You are making the world better place.
@neuodev2 жыл бұрын
Did you get the job :)?
@Girry_4 жыл бұрын
Guy must be really fun to interact with. Great explainer!
@6s64 жыл бұрын
Fantastic video. As a professional software engineer, I appreciate having these concise videos on security to reference when I forget about concepts (particularly in security). Seeing as you're a software engineer as well, I would appreciate more videos on cybersecurity from a software engineering perspective e.g. How to properly secure Docker containers, tips on securing my Nginx server that's facing the public Internet, etc.
@zaheerkhan80974 жыл бұрын
yes please we need these videos!!
@veerendrasaikumar10083 жыл бұрын
SSL stripping was a great example to start with, which explains why do we need HSTS in the first place. Awesome video, Thank you!
@harshgupta94944 жыл бұрын
really good explanation. After going through the video, i was able to identify how HSTS works for the first time and how MITM attack works which i wasn't able to understand after looking at other people's video
@hnasr4 жыл бұрын
Harsh Gupta thanks ! Happy the content could help. Have a great day 😊
@binaryblog4 жыл бұрын
Your videos are very addicted :) Imo 80% tech videos on YT are garbage, another 15 are good and the last 5% are outstanding. Your videos are definitely in these 5% Keep up the good work sir!
@hnasr4 жыл бұрын
binaryblog thank you BinaryBlog!! Comment made my morning. So happy I can provide value 😊
@fb_a4 жыл бұрын
I just checked this channel content after seeing this video. This channel is super amazing 💥💥.
@hnasr4 жыл бұрын
🥳🥳🥳
@MM-by6qq2 жыл бұрын
sir I found your channel today, I have exam tomorrow and you helped me..you are talented in explaining thank you so much! +1sub
@jatinjindalj3 жыл бұрын
Keep up the good work Husain. I am learning a lot from your videos. Cheers!
@ishandhar28514 жыл бұрын
You keep the interest in IT alive 👍👍
@codyj071619892 жыл бұрын
Great video with clear explanation 10/10. thank you for making this!
@tommasocanepa5874 жыл бұрын
Neat and clear! Really informative, thank you sir!
@hnasr4 жыл бұрын
🙏🙏
@zaheerkhan80974 жыл бұрын
Brilliiant Hussein !. Keep up the good work. As told by @binaryblog your videos are very addictive coz they explain in detail with no doubts hence making them very catchy.
@hnasr4 жыл бұрын
Zaheer Khan thank you Zaheer! Can you share rhe binary blog link?
@zaheerkhan80974 жыл бұрын
@@hnasr its just below my comment
@Deekudla2 жыл бұрын
Great videos. Looking forward for some videos on "VPN" security related issues and mitigations around it.
@kaustuvkchattopadhyay85663 жыл бұрын
Love your enthusiasm. Thanks
@anshikagupta49313 жыл бұрын
This is a really cool video. I always heard this term bounce around in office, now I know what it meansssss
@brod5153 жыл бұрын
I don't understand why the user-agent/browser does not always just try connect to https regardles, to see if it exists first.
@softwarelivre23893 жыл бұрын
I agree! That should be the default. HTTPS first, HTTP second! On Firefox, we can enable the HTTPS-Only Mode, which will show an alert before accessing anything through HTTP. Pretty neat!
@hessamzahedi54132 жыл бұрын
Great video! quick question, regarding HTTPS interception attacks, what would be the best solution, HSTS or Certificate Pinning. -thanks
@hnasr2 жыл бұрын
I would choose certificate pinning Hessam. HSTS has still small window of attack.
@jlai3834 жыл бұрын
love this content. Very authentic and informative.
@hnasr4 жыл бұрын
J Lai thanks J Lai 😊 appreciate your comment
@Rocky-g2iАй бұрын
Let's say you create a new website and a client connects to that website for the first time does it mean for the first connection the client will make a http request first then switch to https , and after the website has been added to the hsts list will all the types of web browsers for every client across the world have that updated list or will it just affect only the client that connected to that website?
@whtht3 жыл бұрын
good explaining
@neadlead2621 Жыл бұрын
ssl striping is not what u said realy , it's when the client send a request as https but the attacker is in the middel and downgrade it saying that the server only use http , in the case that u mentioned the user in the begining send http which is simple for the attacker no need for striping he will respond instead of the server with an http resp. but thanks for the explanation
@ongayijohnian87876 ай бұрын
Slim Shady's Starbucks took a hit after this video
@fxstreamer2382 жыл бұрын
when i type my banks official address with https, it goes first to http and shows insecure connection then redirects to https. I find that very disturbing and strange. why does that happen? is it because they registered their dns with http first? im using google dns
@FuzzyCloud4 жыл бұрын
Thank you!
@hnasr4 жыл бұрын
You're welcome!
@mwir_993 жыл бұрын
Hi Hussein, what happens if you call an HTTP site, even the site is on the HSTS list? What's the answer?
@hnasr3 жыл бұрын
The browser will force HTTPS I believe, will need to check.
@dezuzdazriel42184 жыл бұрын
Hey, how do i get that kind of a mouse cursor with the trail like that? please reply =)
@hnasr4 жыл бұрын
Hello! oh thats just the google slides cursor not mac or windows. Open Google Slides, create a slide , go to presentation mode and turn on "pointer"
@AmineOnline4 жыл бұрын
NICE
@doomznyt4 жыл бұрын
well its hard to sniff to someone now! unless you have the power to connect to the main network switch! or create your own evil twin! the attack vector is hard!
@hnasr4 жыл бұрын
Correct, its very hard to perform MITM if the attacker is not in the line of sight.
@doomznyt4 жыл бұрын
@@hnasr hi hussein, subscribing to your channel, more TUTS to come.. stay safe
@StephenRayner4 жыл бұрын
subbed
@SADOKSADOK3 жыл бұрын
man make some schema please, is the purpose videos