3 ms·
I posted my thoughts on FireShepherd to my blog here: http://codebutler.com/firesheep-a-week-later-idiot-shepherds http://codebutler.com/firesheep-a-week-later-
by EricButler 16y ago
I posted my thoughts on FireShepherd to my blog here:
http://codebutler.com/firesheep-a-week-later-idiot-shepherds http://codebutler.com/firesheep-a-week-later-idiot-shepherds
- trotsky 16y agoFrom your blog: "Sending out lots of random data, especially over a wireless network, can disturb everyone else on the network and result in their connections becoming slow and/or unreliable. In addition, FireShepherd by default sends all this data out over the Internet to www.facebook.com, placing unnecessary load on their servers." Your position is laughable at best - you're saying "but think of the users" (you're lagging their connections) and "think of the facebook" (you're wasting their resources) when your own software treats both parties far worse at least in the short term. Suggesting that an HTTP GET set twice a second to a server that will return a 404 will somehow have a measurable effect on the performance of a public network like a starbucks hotspot is beyond ridiculous. Since a days worth of that traffic would be dwarfed by a single user playing a single 5 second low quality youtube clip - the evidence suggests you either lack a fundamental understanding of practical networking or you're simply trying to trick people into disliking a tool (that attacks your tool). As far as your concern about facebook's resources, it seems highly disingenuous in light of the fact that your tool automatically makes a series of two or more http requests (that generate real, dynamic responses) to any site (including facebook) you include a handler for any time it sees a new session on the wire. Without any consent, including hijacked session cookies, even if the firesheep user never once clicks to hijack it. You have every right to release whatever wannabe click2pwn tools you want. You even have a fair point about session infrastructure, though you made it with all the subtlety of a wrecking ball. You just look like an idiot, though, when you try cry about someone else's tool claiming injury to the very users and sites your own tool victimizes. You should grow a much thicker skin if you want to play big boy security researcher.