10 ms·
Herding Firesheep in a NYC Starbucks: Do Users Care?
- cschep 16y agoI know about it the vulnerability and I still login to facebook in public places. It's like the locks on our front doors.. you don't break into everyone's house just to prove they aren't very good do you? I know you could just smash my windows, but you don't, and I appreciate it. It's facebook that needs to fix the bug, not me. Maybe send the first message, but don't be obnoxious on purpose. I dunno.
- gloshuertos 16y agoIf you walked by someone's house and their car was sitting in their driveway with all the doors wide open and a box of personal documents in the back seat, you'd probably knock on their door. If the car was still there after an hour, you'd probably knock again. I sent only two messages, and they were short and to the point. (edit) What I mean here, is that to know that someone's door is unlocked, you have to check each house. To pick a lock, you need some rudimentary skill. Firesheep (and the underlying vulnerability) is wide open and requires 0 skill to operate.
- marcusbooster 16y agoIt's one thing to politely knock on the door, it's another to keep banging on their kitchen window when they are obviously ignoring you. The users probably feel helpless and just want to be left alone. For a non-tech person it's a pretty big jump from surfing Facebook at Starbucks to setting up a VPN.
- Tichy 16y agoThe difference is, so far there are no robots that automatically break into your house. Since your info can be harvested automatically, not sticking out as a target does not help. It is nothing personal - a script will simply steal your info automatically. Edit: waiting for the Starbug - small devices you stick to the bottom of a desk in starbucks that stream user data to your hacker home.
- bilban 16y agoStarbug! Suitably geeky.
- bilban 16y agoI totally get where you are coming from with this. If I have a bag with me in a public space, or if I left my email open on my laptop and left the room I would not expect anyone to help themselves to the content. It's a trust issue. I guess the difference here is that someone could go unnoticed in our midsts.
- chaosmachine 16y agoI imagine some people, having seen spyware popups one too many times, just thought they were infected again. "You're in Toronto, your IP is 99.12.34.56, your ISP is Rogers, you're using Windows XP! Thieves can steal your info! Download our antivirus now!"
- gloshuertos 16y agoThis is exactly what I thought when I saw the same people still online -- which brought about the second round of messages. I hoped my frankness and lack of any links would make the message seem more sincere, but perhaps at this I failed.
- koski 16y agoMaybe you could have told them what they were wearing and what they were drinking. Could have been a bit too much maybe.
- gloshuertos 16y agoI may have spent 2 hours in a Starbucks to do this, but I do actually have a life. Sometimes. So yeah, a bit much. Also: follow-you-home creepy instead of just creepy.
- charltones 16y agoI think if I was unaware of the technology behind this then even if you had come up to me and patiently explained it I would probably not have changed my behaviour. Until it is explained in the mainstream press or until a wide scale "fuss" is made then I suspect most people would do the same. My guess would be that anyone who is told there is a problem and they can fix it by subscribing to a VPN service would assume they were being scammed. I think your average internet user would feel this was primarily Facebook's (and other sites) problem to fix first. A distant second might be that there was a problem with their browser. It would barely register that they should change their behaviour or pay for a service they've not heard of before.
- 16y ago
- cloudwalking 16y agoThis really needs to be on CNN and such for people to actually think about it. And realistically it looks like we all need to start using SSL - people aren't going to change their browsing habits.
- gloshuertos 16y agoUnfortunately the few non-tech news sites that I've read have covered it with blatant disregard for the underlying cause. It's been Firesheep that's pointed at as the issue, not Facebook and Twitter and Amazon ad infinum.
- edwtjo 16y agoAt least here, in Sweden, it was covered by "mainstream media" but now its yesterdays news which means that any point that was actually conveyed about the risks to personal security is now long forgotten.
- adbge 16y ago> This really needs to be on CNN and such for people to actually think about it. People see starving children on CNN and they think "Oh, how awful!" Then they turn off the TV, eat dinner, and go on with their lives. Further, the media as a whole runs so many scare articles to increase views, I think the public is jaded. How is the common man supposed to tell the difference between articles about the threat of bedbugs and the very real threat of this sort of identify theft?
- lowglow 16y agoWhat are the legal ramifications of running firesheep on a public network?
- helwr 16y ago"Google, in response to government inquiries and lawsuits, claims it is lawful to use packet-sniffing tools readily available on the internet to spy on and download payload data from others using the same open Wi-Fi access point." will see who wins in the court :http://www.wired.com/threatlevel/2010/06/packet-sniffing-laws-murky/ http://www.wired.com/threatlevel/2010/06/packet-sniffing-law... see also : http://blogs.forbes.com/kashmirhill/2010/10/28/firesheep-users-may-be-breaking-the-law/ http://blogs.forbes.com/kashmirhill/2010/10/28/firesheep-use...
- jozo 16y agoYou should note that firesheep, besides sniffing packets, also lets you use other peoples sessions. Which probably has other legal implications.
- jasondavies 16y agoPassive sniffing is one thing. Active unauthorised access to a computer using FireSheep is definitely illegal in the UK according to the Computer Misuse Act: (1) A person is guilty of an offence if— (a) he causes a computer to perform any function with intent to secure access to any program or data held in any computer, or to enable any such access to be secured; (b) the access he intends to secure, or to enable to be secured, is unauthorised; and (c) he knows at the time when he causes the computer to perform the function that that is the case. (2) The intent a person has to have to commit an offence under this section need not be directed at— (a) any particular program or data; (b) a program or data of any particular kind; or (c) a program or data held in any particular computer. I think passive sniffing may also be illegal in the UK according to RIPA [1] as it is unauthorised interception of public telecommunications. [1]: http://www.legislation.gov.uk/ukpga/2000/23/part/I/chapter/I/crossheading/unlawful-and-authorised-interception http://www.legislation.gov.uk/ukpga/2000/23/part/I/chapter/I...
- johnglasgow 16y agoThe users are not at fault here. Even a SSH or VPN will leave them vulnerable to attacks. Companies (Facebook, Twitter, etc.) have to increase their own security, because they are the only ones that can fix this problem.
- gloshuertos 16y agoI absolutely agree on fault. My initial recommendation was for them to refrain from using Facebook at Starbucks until that happens -- regardless of fault, users are the ones that are vulnerable.
- gojomo 16y agoSending your HTTP through an SSH tunnel or a VPN will protect against the stranger-at-Starbucks attack.
- BrandonM 16y agoBut not against the stalker-techie-at-your-ISP attack.
- gojomo 16y agoSure, but there are about a million times as many people able and motivated to do the wifi-neighbor attack than the stalker-ISP-gnome attack. And as people with true identities in a stable position of authority at as service provider, the gnomes are easier to find and hold accountable. This difference -- from random anonymous stranger whose only invested in software, to physical infrastructure with paid staff -- is also one reason bank phishing attacks happen via websites and not actual storefronts made to look like real banks. If the only threat to Twitter and Facebook users was ISP-gnomes, the websites could put off fixing the issue for another decade.
- c1sc0 16y agoDoesn't surprise me all that much since most 'normal' people absolutely don't care about security. Passwords are meant to be written on sticky notes. Identity theft is too complicated for them to care about. And credit card fraud is easily solved by reversing the charges. It takes a massive, automated exploit & MSM coverage before they'll start caring.
- deleted 16y ago[deleted]
- cduan 16y agoI suppose the saving grace is that it would be pretty difficult--not impossible, but pretty difficult--to truly get away with this without detection. With all the logging that goes on, chances are that you could be identified by a MAC address, a web login of your own, a credit card swipe nearby, a surveillance camera, a cell phone in your pocket, or who knows what. There is a lot of information to be gotten with the right subpoenas.
- c1sc0 16y agoIt's not the lone Starbucks hacker with a laptop you need to be worried about. It's the wardrivers & honeypotters & people sophisticated enough to do a coordinated automatic harvesting effort.
- gloshuertos 16y agoOn many machines, MAC addresses can be changed. I obviously wasn't attempting to avoid detection since I posted about it under my real name, but anyone could pick up a $200 netbook, pay cash, walk into a Starbucks with sunglasses on, do their business and leave undetected. MAC addresses are useless if they don't tie to anything else and aren't fixed.
- netaddict 16y agoNot just on many machines. You can change your MAC address on any manchine using GNU macchanger http://www.alobbs.com/macchanger/ http://www.alobbs.com/macchanger/
- koevet 16y agoI understand that getting your Amazon account hacked can lead to some head scratching situations and Amazon should really implement full SSL encryption. Having said that, what are the implications of getting your FB or Twitter or Flickr account hacked? Personally, even if annoying, I wouldn't consider it as a major issue in my digital life. I try not to mix business and private life (for instance, my FB friends are only friends, not colleagues. Same goes for Twitter) so do you see any other issue, a part from the "annoyng" factor?
- raesene 16y agoThere have been some interesting cases where fraudsters have hijacked facebook accounts and then used them for targeted phishing attacks. One example of the attack http://techcrunch.com/2009/01/20/latest-facebook-scam-phishers-hit-up-friends-for-cash/ http://techcrunch.com/2009/01/20/latest-facebook-scam-phishe... In those cases the fraudsters have stolen the account completely and locked the original user out, but I guess it's that kind of attack + the information leakage aspect that could be a concern..
- koevet 16y agoYes, true. Something similar happened to me when a I have received an email (gmail) from a friend asking for money because she was stuck somewhere. Similar pattern. It's interesting to notice that this social engineering attacks are easy to carry in a place like US, where there is one common language. I immediately detected that the mail was a fraud, because this person would have never write to me in English.
- pilif 16y agoit's funny how everyone says "just use SSL - that'll fix it", soon followed by "the SSL computation overhead isn't significant any more" which is totally true, but probably not the reason why SSL isn't more widely used. Smaller sites will suffer from the fact that SSL requires an IP address per server. Name based virtual hosting is out of the question (at least as long as Windows XP is still around). Combine this with the IP address pool quickly getting smaller and smaller and you'll see that for smaller sites, it might be impossible to get the needed amount of addresses for a reasonable price. For large sites, there's the problem of the various CDNs which are not always under the control of the site and might not be prepared for SSL. Remember: All assets of an encrypted page must also be encrypted, otherwise the browsers display a nasty warning (even though unencrypted assets, when served from a different domain would not be a problem what's session hijacking is concerned). "just use SSL" might just not be possible in some cases.
- newman314 16y agoSSL does not necessarily need one IP per server. https://secure.wikimedia.org/wikipedia/en/wiki/Server_Name_Indication https://secure.wikimedia.org/wikipedia/en/wiki/Server_Name_I... Unforunately, support is not sufficiently widespread at this time.
- pilif 16y agoas I said: "at least as long as Windows XP is still around". Internet Explorer under XP doesn't support the extension.
- gloshuertos 16y agoIn addition to the IP address per server problem and coordinating with CDNs, the CDNs often charge quite a bit more money for secure content.
- mseebach 16y agoThe GitHub solution seems reasonable: Use HTTPS for writes and truly sensitive stuff, and unencrypted for the rest. CDNs aren't a problem since your write-requests won't have any external resources on them (they'll just redirect back to HTTP). Then the HTTPS could even be handled on a third-party gateway provider (yes, then there's a weak spot between your servers and the third party, but that's much harder to penetrate than the wifi at Starbucks.). Your read-only session might still be high-jacked, but that's relatively low impact, (since someone could simply sniff what you're reading anyway).
- joeuser12 16y agoNothing is ever really secure. Yes, non-technical Starbucks users are easy targets, but so are most web sites. The last couple of "Review my startup/app" HN posts have all had very obvious XSS holes, for example, and many others have completely insecure session handling even if they do send them over HTTPS. We all tend to wonder just how lame less technical users are and forget that someone else is probably wondering right now how we, ourselves, can be so lame and not understand basic Web security for our own sites.
- paulbaumgart 16y agoWould this work as a cheaper alternative to SSL for preventing session hijacking? 1. During the HTTPS part of the communication, the server sends a long list of random strings. 2. The client stores all these strings in localStorage. 3. On every request, the client sends one of the strings from the list, the server validates that it is in fact a valid string for that session, and both remove that string from their lists. 4. When the list runs out, you have to go back to SSL to exchange a new list of strings. Is there a flaw I'm overlooking (beyond the reliance on localStorage) that keeps people from using this? If not, is there a technical term for this technique so I can Google it?
- jgrahamc 16y agoThat's essentially a one time pad where you are using SSL for pad distribution.
- caf 16y agoIt's not a one-time-pad, it's a one-time-password system. (Just like the SAS codes that are used by STRATCOM to authenticate nuclear launches! ;)
- chrischen 16y agoThat's kind of like refreshing the session key on every page request except you send over a list of session keys that will be used on subsequent requests. Probably not done since it's usually a hit to the session storage on every page request. Still doesn't encrypt the actual content though, and since SSL would encrypt it and make this unnecessary that's probably why it's not done.
- nodata 16y agoHow does this prevent a MITM attack?
- paulbaumgart 16y agoIt doesn't. Is it possible to do a MITM attack on the person at the neighboring coffee-shop table? The only way I can think of involves being really clever about timing and being physically between the other wireless client and the AP: create enough interference to prevent their transmission from getting through to the AP right after you read the transmission, then quickly forge a request using the same one-time key. Of course, if someone has access to the packets upstream from the AP, you're always hosed if you're not using encryption. This certainly isn't meant as a replacement for AES. :)
- DufusM 16y agoWhat I find surprising is that insecure email and wireless had existed for quite some time before this. Almost all IMAP/POP/Gmail used to flow over regular HTTP. It is only recently (read, last year) that a lot of major email traffic has been https-ified. Why suddenly jump on FB, Twitter etc with self-righteous anger when many of these same geeks were using insecure email until less than a year ago?
- deleted 16y ago[deleted]
- Tyrannosaurs 16y agoOut of interest has there been any response from Facebook, Twitter, Amazon and so on? I've had a quick look and not seen anything but it's entirely possible I've missed something.
- defdac 16y ago1) Install WinSSHD on your home computer/server. Open port 22 in your home firewall/router. 2) Install Tunnelier on your laptop, flip to the Services tab and enable SOCKS at 127.0.0.1 and port 1337. Login in to your home computer. 3) Change Chrome target to chrome.exe --proxy-server=socks5://127.0.0.1:1337 Mostly used for obtrusive proxies though it will make you as secure as you are at your home network..
- bilban 16y agoNot a very 'green' solution!
- bilban 16y agoMy point was that having a computer running 24/7 at home to use as a secure proxy when you are out in the field is a bit wasteful. The technical solution was fine - though I can't see many non-techies getting their heads around this. Why the down vote - pffffh.
- edwtjo 16y agoThis is exactly what I do (but with OpenSSH) its even the same port :P
- ANH 16y agoAn alternative to the chrome command line option is the Proxy Switchy extension: https://chrome.google.com/extensions/detail/caehdcpeofiiigpdhbabniblemipncjj https://chrome.google.com/extensions/detail/caehdcpeofiiigpd...
- Splines 16y agoIf you have an Alchemy-based firmware running on your home router, you can enable sshd so you can have an always-on ssh tunnel wherever you go. I did this to my home router and had it all working in about 30 minutes. Most of that time was trying to figure out how to get putty to open a tunnel (and registering/configuring a No-IP dynamic dns account).
- GHFigs 16y agoI included no clues as to my identity, less because of fear of retribution, and more because invasion of privacy is all the more frightening when it is committed by an absolute stranger with no chance of discovering their identity. Disgusting. Sowing fear is not education.
- gloshuertos 16y agoReally? Users shouldn't be afraid of the consequences of something they believe to be benign? I didn't send Starbucks patrons home weeping to cry themselves to sleep. I fully concealed my identity in the same way an actual attacker would.
- GHFigs 16y agoThere is no distinction between you and an "actual" attacker. You seem to have labored within a nimbus of self-righteous nerd egotism that someone more criminally minded might not have but you are not in any way more entitled to violate a person's expectation of privacy. You are not a hero. You have not done anybody a favor. You did this for the same perennial excuse of "spreading awareness" trotted out by any number of noxious social irritants and did so not by the means most efficient or effective, but the means readily available and most likely to satisfy your urge to feel superior to your fellow man. You may actually care about the problem and take it seriously in other circumstances, but that is not reflected here. There is no security problem for which "exploit the problem to harass strangers in coffee shops" is the solution.
- mike-cardwell 16y agoIs there also no difference between somebody entering your house without your permission to warn you about something, because they fear for your safety, and somebody entering your house to burgle it? You should probably replace "harass" with "inform" in your comment. It would be more accurate, and less emotive.
- GHFigs 16y ago
- nodata 16y agoWhat does he expect the users to do? Not use Facebook? Right...
- gloshuertos 16y agoThat's the point. It's empirical (albeit, not scientific) evidence that even when presented with the risks, users will still choose to do things that are dangerous.
- georgemcbay 16y agoWhy would you expect most people to do otherwise? I fully know the risks of using open hotspots on many websites and I do it anyway because the convenience outweighs the risks for me. Obviously I'd think twice about logging into my bank over a non-secure connection (though I'd be mad to bank with a company that doesn't secure all connections by default, of course), but open-wifi Facebook? Sure, why not? This behavior extends beyond Internet usage. I (and probably most of you reading this) hand my credit/debit cards over to waiters several times per month knowing full well they could jot down enough information while out of my sight to make illegal charges on that card (if not do far worse via more elaborate identity theft schemes). Risky? Yes, but the extreme convenience outweighs the potential pain due to the low chance of actually being one of the people that gets exploited in this way, and thus it is with open hotspots and most Internet sites.
- mike-cardwell 16y agoIn the UK, waiters bring over a portable card reader to your table, you stick your card in and enter your pin. No need to physically hand over your card to them.
- dedward 16y agoMy credit card has legally builtin insurance against fraudulent use - I'm not liable for a penny of that use if it was used illegally - unless the card itself was stolen and I failed to report it - in which case i'm liable for up to $50. (As soon as I report it stolen, I'm not liable for anything) I use a credit card because it's safer and offers me options - someone snarfing the number would be a nuisance, because I'd need a new card, but that's it. Let's please not forget (Sight.. I know - everyone already has) that charge-cards were pushed onto the market as a safe, convenient alternative to using cash - not a walking liability - don't let the issuers turn them into one on us. As to the analogy - it's quite different. I'm very security conscious, and I generally don't do certain types of activity on uncontrolled or unknown networks (banking - home or somewhere else safe - but facebook at starbucks, okay) IT's not just a problem with open hotspots, it's with any network you are on, anywhere - an open hotspot is just the easiest place for someone to try this on. An employee at an ISP could snarf data from millions of users easily...
- pluies_onpublic 16y agoIsn't it ironic that we're discussing it on a website that doesn't have https at all, not even on the login page?
- robryan 16y agoWhat are you going to do, having someones account though, possibly if they are well known attempt to changes peoples perceptions of them/ get people to believe something? You can't delete comments older than like a day so trashing the account is mostly out. Once they noticed they could invalidate that session, mention it wasn't them and it would be the end of it. I feel mostly the same way about Facebook, those so inclined could do more damage un-friending everyone, at which point I could thank them for cleaning out old contents and organically readd those who I still speak to.
- c4urself 16y agoCould it be that the persons thought it was some kind of automatically-generated message? Maybe a you're wearing a red shirt that says ... would get the point across?
- gloshuertos 16y agoIs a machine breaking into your account any less scary than a person doing it?
- deleted 16y ago[deleted]
- jozo 16y agoWhile it's nice that this gets some attention and not very nice of facebook to automatically revert you back to an unencrypted connection, this is not a facebook specific problem. Anytime you use a wireless network, where you don't have control over the access point, you need to secure everything you want to keep private. This goes for everything from google searches and files transfers to instant messaging and e-mail. The proven solution is to use a VPN tunnel, which even many home routers support nowadays. Of course there's still a bigger problem with arp spoofing and other attacks, which in the long term will need to be solved. Maybe with something like DNSSEC DKI.
- robryan 16y agoIt is weird it hasn't been covered more, usually here in Australia the media run scare stories on the most insignificant of Facebook flaws. I wouldn't be in a hurry to point it out to them this new one either, it would be sensationalized into some kind of no cafe is safe without any technical details.
- ghiculescu 16y agoThe problem being that no cafe IS safe - what people have posted on their Facebook is important, and some of the websites Firesheep attacks can be even more damaging for the user - until everyone runs VPNs or websites get their act together.
- lhnz 16y ago> What's absolutely incomprehensible is that after someone has been alerted to the danger (from their own account!) that they would casually ignore the warning, and continue about their day. That's not incomprehensible. They have trust. And they don't consider what they're doing particularly private.
- points 16y agoJust don't do 'login' type work at public wifi :/ is that so hard? Do people not know this already? Did some people ever think it was safe to use public wifi for anything other than general browsing? Please HN: Stop getting outraged by stuff that doesn't really matter. You're turning into Reddit, and just like them, you will have forgotten all about this by next week, and be on to the next topic you need to be outraged about. It's depressing. Angelgate? No one cares any more. No one should have cared in the first place.
- Confusion 16y agoI don't know where you see 'outrage'. I only see someone investigating the security concerns of users of a Starbucks' wifi and being worried that they don't care about their privacy.
- gdl 16y agohttp://ycombinator.com/newsguidelines.html http://ycombinator.com/newsguidelines.html : "If your account is less than a year old, please don't submit comments saying that HN is turning into Reddit. (It's a common semi-noob illusion.)"
- points 16y agoI created this account after a couple of years. My main account is 1000+ days old. Seriously. This summer has been depressing to watch HN go down the pan.
- roadnottaken 16y agoWhy is this so surprising? Most people I know don't really care about internet privacy. Most people I know don't post anything sensitive to their facebook pages. I don't use facebook and when I mention that I think it's weird to put personal stuff on the internet (which always has the potential to be public) they think I'm a paranoid nut. Let's admit that it's not really an unreasonable position, provided you don't work at the NSA.
- uptown 16y agoWhat was your game-plan if you'd stumbled upon something highly personal and sensitive in their mailboxes? Or if one of their friends had sent them a person IM while you were logged in as them? The fact is, you could have easily approached these people face-to-face, offered to show them the risks they were exposing themselves to using your laptop, and give them the choice as to whether you took control of their accounts. While it appears that you did what you did with the best of intentions, you violated the privacy of the people whose accounts you accessed; broke a variety of laws; then documented your crime in your personal blog. You describe your targets as lacking judgment. Maybe you should consider your own.
- dedward 16y agoAbsolutely. This may even be criminal, unfortunately.
- dinedal 16y agoExactly. Just because there's a rock next to a window doesn't mean you should throw the rock through the window to prove a point that people shouldn't leave rocks near windows.
- gloshuertos 16y agoActually, whether or not I broke any laws (in the US) is not clear. I deliberately did not look at anything in their account while I was in it, so privacy was not actually compromised. The folks I recognized on my way out were people with large profile pictures of their faces. In general, this wasn't the case. I'd have had to do a lot more rifling through accounts to be able to identify someone face-to-face, and would have risked someone having a bad reaction. So, unlike all the people who have used Firesheep in public to look at peoples' accounts and then not told anyone about it, I notified the users and then told the public about what happened. You're saying that's bad?
- uptown 16y ago"I deliberately did not look at anything in their account while I was in it, so privacy was not actually compromised." From your blog: "I opened up his Amazon homepage, identified something he had recently looked at"
- uptown 16y agoOkay, let's connect some dots about you. Your name is Gary LosHuertos You look like this: http://yfrog.com/0irajuj http://yfrog.com/0irajuj Gender: Male Astrological Sign: Scorpio Industry: Consulting Occupation: Software Engineer Location: New York : NY : United States You have a blog hosted on BlogSpot from which this article came. You send tweets from @gloshuertos where you promoted this story. Your twitter account lists a latitude/longitude address of 27.109827,-82.308136 which is in Venice, Florida. One of your oldest tweets mentions that you're on your way to Gainsville, Florida. https://twitter.com/#!/gloshuertos/status/1267758656 https://twitter.com/#!/gloshuertos/status/1267758656 Only one Gary LosHuertos comes up on LinkedIn, but this person used to work in Gainsville Florida, so it's reasonable to assume this person may be you. http://www.linkedin.com/pub/gary-loshuertos/11/68/aa0 http://www.linkedin.com/pub/gary-loshuertos/11/68/aa0 The interesting thing about that LinkedIn profile is that it lists your current employer as Amazon.com. From your blog post, you mentioned the following: "This was somewhat puzzling. Did they receive the first message? I logged into their accounts, and surely enough, they had. One of them was even on Amazon.com, which I had warned about in my first message. I targeted him first: I opened up his Amazon homepage, identified something he had recently looked at, and then sent him a "no, seriously" message on Facebook from his account including the fun fact about his music choices." So what you're telling us is that you used a user account of a customer of your current employer to login as that person, spy on their purchases, then logged to their Facebook account and send them messages about his customer information? You're entering into a world of hurt if Amazon catches wind of this.
- mcknz 16y agoI don't agree with killing the messenger here. His activity is in a decidedly gray area, but I think the results and discussion are valuable.
- jhancock 16y agoThis is valuable discussion but not to the HN audience as we already get it. There are some tough laws that can be applied to his behavior. I don't know what the odds are of getting caught into a criminal prosecution, but you don't want to spend the next 10 years of your life dealing with the fallout of a blog post.
- ergo98 16y agoIf that public wifi is secured with a password -- albeit a public password -- does that protect individual sessions? Meaning you go to a cafe and the blackboard tells you that today's WPA2 password is "greenbeans". Knowing this does it provide the ability to sniff or abuse other users sessions on this WAP? Honestly don't know this and can't find a clear answer about it.
- jrnkntl 16y agoafaik (and from my own experience) that won't work. "As long as the universally supported WPA encryption protocol is used, each individual user receives their own private “session key” that absolutely prevents eavesdropping between users, even through they are all using the same WiFi password." from: http://steve.grc.com/2010/10/28/instant-hotspot-protection-from-firesheep/ http://steve.grc.com/2010/10/28/instant-hotspot-protection-f...
- deleted 16y ago[deleted]
- docgnome 16y agoYeah, we tested it on our WPA encrypted wireless and didn't get anything. It was seen when I logged into facebook but my coworker wasn't able to login as me. At least not with Firesheep.
- icode 16y agoI have wondered about the same question. Strange, I upvoted your question but it still only has one point.
- jrockway 16y agoSecuring the connection layer doesn't matter. With a $10 Wifi card I can create an infrastructure access point called "Starbucks Wifi" or whatever I want that's encrypted with anything (WPA2, WEP, open... doesn't matter). Then when you connect to that, I get all your packets and can steal your session. Now, sure, this attacks costs me $10 for the wifi card and it's not as fast as connecting to Starbucks' wifi and opening a Firefox tab... but you will still get a lot of data. Link-level encryption is not the same as session encryption. For your link to be secure, you need link-level encryption. For your session to be secure, you need session-level encryption. It's that simple. Facebook is a session, not a link, so Facebook needs SSL. There is simply no other workaround. (And oh yeah, you need to authenticate who you are talking to. The access point asks you for a password to prove that you are allowed to talk to it. But you don't ask it for a password to prove that it is allowed to talk to you. Connecting to an access point is like giving your credit card information to the call that starts like, "Is this jrockway? There's a problem with your credit card...". They know who you are, but you have no idea whether they are actually your bank.)
- AngeloAnolin 16y agoDo users care. Quite a thought that actually scared a bit out of me, because unless these users would actually care, only would there be protocols that would prevent this from happening. And when would users care? When their personal identities have been stolen, and private information (credit cards, social insurance numbers, personal messages) have been compromised. Do we really have to go that point where the risk is imminent before taking action? Having identified the vulnerabilities of WEP encryption on wireless networks, shouldn't it be that device manufacturers of wireless routers take away WEP encryption as an option but instead focus on a more secure method of connection? Of course this may have some downside to it, but unless your ordinary Joe and Jane realize the upsides of having secure connection to the web, they may see this as a discomfort.
- tnorthcutt 16y agoThe solution you link to in your post involves using a not-free VPN service. Is there a guide somewhere to setting up a free solution to this problem?
- Zev 16y agoHonestly? The word "douche" springs to mind. Regardless of the legality of it and how grey it may or may not be. I'm sure you thought you were doing something good. But, short of not using Facebook in a coffee shop, what do you expect people to do? Set up their own VPN? I bet that of the people you scared off, they'll all be back on in another day or two. Maybe at the same coffee shop. This is a problem that needs to be solved by on the website's end, not the user's end.
- gloshuertos 16y agoYeah, it does need to be solved by the website. That doesn't change that users are vulnerable and don't know about it.
- Zev 16y agoAgain: What do you expect people to do about this? Stop using Facebook while sipping on a latte?
- gloshuertos 16y agoYes.
- alanh 16y agoOff-topic: I submitted a Tell HN post inspired by this submission: http://news.ycombinator.com/item?id=1848420 http://news.ycombinator.com/item?id=1848420
- WingForward 16y agoA few days into it and I've decided Eric Butler made a mistake in releasing Firesheep. Security is about battling a combination of Time + Talents/Tools + Determination + Opportunity. Firesheep greatly increases the Tools someone has to hack an account. Eric has made browsing much less secure. The intended result is to bring the security issue to people's awareness, which he has done. But the result should have been to increase security. That will only happen if the the change in required Tools is balanced by a decrease in Opportunity (free wifi becoming simple password wifi at a minimum). I doubt that will happen. Releasing Firesheep was a mistake.
- rmoriz 16y agoSomeone should write a blog post about dsniff and how to get dozens of login/passwords for not only pop3, imap, messenger logins at starbucks/airport wifi. We all know that 90% of the users tend to have one passwort for everything. That password usually works for any SSL secured service, too ;-)