elgato
Joined: 24 Feb 2005
Posts: 17240
Location: Texas
|
| Posted: Thu Oct 28, 2010 3:26 pm Post subject: Firesheep Exposes the Soft Underbelly of Website Security |
|
|
The new Firefox plug-in Firesheep is a tool that a public WiFi hotspot user can implement to snoop on the activities of other users of that hotspot. Mozilla says the flaw Firesheep exploits is not found in Firefox per se, but rather in the lax security standards to which many popular websites adhere. Firesheep will make it easier for malicious hackers to do their dirty work, but it also may motivate improvements.
Freelance software developer Eric Butler has released Firesheep, a plug-in to the Firefox Web browser that lets anyone capture cookies from an open WiFi network and possibly steal their owners' identities.
Firesheep is free and open source program available for the Mac OS X and Windows platforms. Butler is working on a Linux version.
Butler wrote that he released Firesheep to draw attention to the longstanding poor state of website security.
Encrypting logins, as many websites do, is not enough, because once the site sets a session cookie, it reverts to regular, unencrypted HTTP for the rest of the session, exposing the user to interception.
Butler did not respond to requests for comment by press time.
more.. link to news article |
|