Posted October 25, 2010
Just came across this, Firesheep is a Firefox extension which when enabled, lets you connect to any wifi network, and someone will visit a site known to Firesheep (Twitter, Facebook, you know, those kinds). It will capture logged in accounts to those sites on the network, double-click and you're logged in AS THEM.
Why?
Because these sites don't use SSL. Quoting from the developer:
Facebook is constantly rolling out new "privacy" features in an endless attempt to quell the screams of unhappy users, but what's the point when someone can just take over an account entirely? Twitter forced all third party developers to use OAuth then immediately released (and promoted) a new version of their insecure website. When it comes to user privacy, SSL is the elephant in the room. Oh. Shit.
Why?
Because these sites don't use SSL. Quoting from the developer:
Facebook is constantly rolling out new "privacy" features in an endless attempt to quell the screams of unhappy users, but what's the point when someone can just take over an account entirely? Twitter forced all third party developers to use OAuth then immediately released (and promoted) a new version of their insecure website. When it comes to user privacy, SSL is the elephant in the room.