Firesheep makes unencrypted sessions visible
Summary
Eric Butler releases a Firefox extension that captures session cookies on open Wi-Fi networks and thus demonstrates the consequences of incomplete HTTPS use. Security problems get priority as soon as exploiting them becomes cheap and easy to grasp. Partial encryption does not protect secrets if the subsequent session remains unprotected.
Ideas
- At the time many services encrypted the login but sent later session cookies in the clear.
- A captured cookie could take over an existing session without a password.
- Firesheep made a well-known protocol flaw immediately visible to non-specialists.
Recommendations
- Enforce HTTPS for the entire session and set cookies to Secure and HttpOnly.
- On other people's networks, do not use services that still allow unencrypted HTTP.
References
Links to the original source and the Web Archive open in a new tab.