bk99.de entertain the web since 1997

Firesheep makes unencrypted sessions visible

Summary

Eric Butler releases a Firefox extension that captures session cookies on open Wi-Fi networks and thus demonstrates the consequences of incomplete HTTPS use. Security problems get priority as soon as exploiting them becomes cheap and easy to grasp. Partial encryption does not protect secrets if the subsequent session remains unprotected.

Ideas

  • At the time many services encrypted the login but sent later session cookies in the clear.
  • A captured cookie could take over an existing session without a password.
  • Firesheep made a well-known protocol flaw immediately visible to non-specialists.

Recommendations

  • Enforce HTTPS for the entire session and set cookies to Secure and HttpOnly.
  • On other people's networks, do not use services that still allow unencrypted HTTP.

References

Read the original post

Search the Web Archive