Latest news
HTTP session hijacking as a possibility and tools to execute it have been around for more than half a decade, but it took an easy-to-use Firefox add-on like Firesheep to point out "the elephant in the room" - the lack of full-end encryption on popular sites such as Facebook, Twitter, Yahoo, Bing, and many others."Sniffing out" unencrypted HTTP sessions on a network segment, hijacking them and impersonating the user has suddenly become possible for everyone - even for those who know next to nothing about the underlying technology or are the most low-level users.
Four days after Firesheep has been made available, over 400,000 users have downloaded it and satisfied their curiosity. Some of them have probably used it for more than that - who knows how many unethical and illegal things were done with the information that was accessed through its use? But that is beside the point, because things like that happened before Firesheep - the only difference was that one had to be moderately tech-savy to do it.
"Websites have a responsibility to protect the people who depend on their services. They've been ignoring this responsibility for too long, and it's time for everyone to demand a more secure web. My hope is that Firesheep will help the users win," says Eric Butler, one of the developers of the add-on.
"The real story here is not the success of Firesheep but the fact that something like it is even possible, says Ian Gallagher, Butler's co-presenter of Firesheep at Toorcon. "The same can be said for the recent news that Google Street View vehicles were collecting web traffic. It should not be possible for Google or anybody to collect this data, whether intentional or not. Going forward the metric of Firesheep’s success will quickly change from amount of attention it gains, to the number of sites that adopt proper security. True success will be when Firesheep no longer works at all."
Both of them might just see their wish fulfilled. According to a NetworkWorld blogger, Microsoft is looking into implementing SSL in future release of Bing. And I'm betting that other companies and online services are looking into it.
As stated before HTTP session hijacking is not a new thing, and many tools that make it possible have surfaced over the years. "Firesheep is doing the exact same thing as these other tools, but with a simpler user interface," says Gallagher. "Because of its simplicity, Firesheep has already succeeded in demonstrating the risks of insecure websites to a much wider audience than any previous tool, in a single day."
And that, my friends, is the real value of this controversial extension.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





