Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Firesheep In Wolves’ Clothing: Extension Lets You Hack Into Twitter, Facebook Accounts Easily

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
Xipe Totec Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 07:44 AM
Original message
Firesheep In Wolves’ Clothing: Extension Lets You Hack Into Twitter, Facebook Accounts Easily
Source: Tech Crunch

It seems like every time Facebook amends its privacy policy, the web is up in arms. The truth is, Facebook’s well publicized privacy fight is nothing compared to the vulnerability of all unsecured HTTP sites — that includes Facebook, Twitter and many of the web’s most popular destinations.

Developer Eric Butler has exposed the soft underbelly of the web with his new Firefox extension, Firesheep, which will let you essentially eavesdrop on any open Wi-Fi network and capture users’ cookies.

As Butler explains in his post, “As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed” in the window. All you have to do is double click on their name and open sesame, you will be able to log into that user’s site with their credentials.

Read more: http://techcrunch.com/2010/10/24/firesheep-in-wolves-clothing-app-lets-you-hack-into-twitter-facebook-accounts-easily/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+Techcrunch+%28TechCrunch%29
Printer Friendly | Permalink |  | Top
StandingInLeftField Donating Member (382 posts) Send PM | Profile | Ignore Mon Oct-25-10 08:18 AM
Response to Original message
1. I wonder if this is what happened to John Daly (the pro golfer) this week.
His FaceySpace, Twattler, and email accounts were hacked and threats against his family were made.
Printer Friendly | Permalink |  | Top
 
onehandle Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 08:30 AM
Response to Original message
2. Link? I went to techcrunch, but could not find this article.
Only this article on how to protect yourself:

http://techcrunch.com/2010/10/25/firesheep

Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 08:34 AM
Response to Reply #2
4. Here:
Printer Friendly | Permalink |  | Top
 
onehandle Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 08:36 AM
Response to Reply #4
5. uh... nt
Printer Friendly | Permalink |  | Top
 
Xipe Totec Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 09:36 AM
Response to Reply #4
11. Thanks, I was rushing to a meeting so I did not vet the link very well
:hi:
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 09:39 AM
Response to Reply #11
12. De nada. nt
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 08:31 AM
Response to Original message
3. You have no privacy on the web (without encryption).
If you care about your "private information", don't put it on the web, don't talk about it on the web, etc.

"Facebook Privacy" is an oxymoron, that's not what Facebook is about.
Printer Friendly | Permalink |  | Top
 
Xipe Totec Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 09:33 AM
Response to Reply #3
10. This goes a little beyond; we're talking about hijacking the account itself nt
Printer Friendly | Permalink |  | Top
 
KeepItReal Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 09:00 AM
Response to Original message
6. Here's a link to protect your info if you use Firefox
"Force-TLS allows web sites to tell Firefox that they should be served via HTTPS in the future; this helps secure you from accidentally negotiating an insecure session with certain sites."

https://addons.mozilla.org/en-US/firefox/addon/12714/
Printer Friendly | Permalink |  | Top
 
herbm Donating Member (980 posts) Send PM | Profile | Ignore Mon Oct-25-10 09:08 AM
Response to Reply #6
7. I hope this doesn't lull any false sense of security. Its an example doing the beta work after the p
roduct's been released. Even worse than Microstiff.
Printer Friendly | Permalink |  | Top
 
KeepItReal Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 09:16 AM
Response to Reply #7
8. Actually Force TLS has been out since '09. The extension to see unsecured info is new.
eom
Printer Friendly | Permalink |  | Top
 
herbm Donating Member (980 posts) Send PM | Profile | Ignore Mon Oct-25-10 09:20 AM
Response to Reply #8
9. As a computer truck driver it scares me. Thank the Lord there are savys out there like you to protec
t the most of us out here like me.
Printer Friendly | Permalink |  | Top
 
herbm Donating Member (980 posts) Send PM | Profile | Ignore Mon Oct-25-10 01:55 PM
Response to Reply #8
15. Users are always the last to know. Hackers and phishers, one of the first.
Printer Friendly | Permalink |  | Top
 
pschoeb Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 10:33 AM
Response to Original message
13. On most commercial public wifi this firefox extension wouldn't work
As their wifi is set up with layer 2 isolation, so each connection is a separate virtual network, and can't see the traffic of other connections.
Printer Friendly | Permalink |  | Top
 
Edweird Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Oct-25-10 10:39 AM
Response to Original message
14. As a user of Wifizoo & Scapy this is nothing new - what is new is that it's for Windows.
That makes it available to every jerk out there. I suppose this will have an unintended effect of increasing everyone's awareness of internet security - for a while anyway.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 03:05 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC