3 ms·
The most surprising thing about this to me is how long it took to have a new cycle about it. Firesheep was a 2010 invention. Once that happened, anyone could c
by zethraeus 9y ago
The most surprising thing about this to me is how long it took to have a new cycle about it.
Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by.
... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.
- schoen 9y agoJust a note, Firesheep didn't implement generic traffic sniffing, just cookie-cloning, and that only when someone implemented a Firesheep plugin with an appropriate regular expression or whatever for a given site. So the existence of Firesheep itself wouldn't allow people to passively watch traffic for arbitrary sites, and not even to perform attacks against newly popular sites if no community kept it up to date for those sites.
- IncRnd 9y ago> Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by. That's incorrect. Firesheep performed session hijacking using unencrypted session cookies.
- joombaga 9y agoWhich part of the comment is incorrect?
- IncRnd 9y ago> Which part of the comment is incorrect? I quoted the incorrect part of the comment. Then, I posted a correction to the comment that is incorrect. Firesheep doesn't display the HTTP traffic whizzing by but steals cookies for a session - allowing the malicious party to view information from the server, not the information between the sever and client.
- lucideer 9y ago> ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model. This presumes users are aware of whether an app's traffic is encrypted or not. It's interesting how much thought goes into the UX of browser address bar security indicators, while everyone happily uses apps with no visual indicators of network connection security of any kind.
- noobermin 9y agoOr whether users know what encryption really means or not. Users don't chose between apps based on a laundry list of features like security consciousness of the developers. They know tinder is where you get dates and they download and use that.
- lucideer 9y agoMost users, yes. But even those who do care, and know a little about it, don't necessarily have any obvious path to verify which apps do/don't encrypt their traffic. I'm a mobile app developer, and if I were downloading Tinder I am actually naïve enough that I would have presumed its network traffic would be. It just seems so matter of course to me that network requests written into any app being developed would just use HTTPS.