Live data from Hacker News

Firesheep usage leads to Idiocy

jonty.co.uk

1–10 of 89 posts

Re: Firesheep usage leads to Idiocy

#3
This sounds like an interesting idea, but is it legal to run? Sure it might be a good thing to educate people about the dangers of accessing the internet over open wireless, but what if you accidentally run it on the account of someone who is willing to sue? Do they have a legal basis to sue you?

Just because they are doing something stupid, doesn't give you the right to mess with their accounts.

Re: Firesheep usage leads to Idiocy

#4
In the last few days a tool has been released

That seems to imply it's a single tool, and once this is "stopped" you don't need to worry any more. Surely it should mention instead that a recently released tool is widely publicised? Firesheep didn't make this possible, it has been for a long time, it just made it more accessible.

Re: Firesheep usage leads to Idiocy

#5

In the last few days a tool has been released That seems to imply it's a single tool, and once this is "stopped" you don't need to worry any more. Surely it should mention instead that a recently released tool is widely publicised ? Firesheep didn't make this possible, it has been for a long time, it just made it more accessible.

I thought the rest of the paragraph covered that, but I'm happy to edit it if you can suggest a rephrasing?

It's just supposed to be a quick introduction stating that the chances of being exploited are significantly higher now that the entry barrier is practically non-existent.

Re: Firesheep usage leads to Idiocy

#6
post #3

This sounds like an interesting idea, but is it legal to run? Sure it might be a good thing to educate people about the dangers of accessing the internet over open wireless, but what if you accidentally run it on the account of someone who is willing to sue? Do they have a legal basis to sue you? Just because they are doing something stupid, doesn't give you the right to mess with their accounts.

Unless they're running a honey-pot machine... how do they tell? You're coming from the same IP, with the same session. At best they can fingerprint your browser, which is far from proof and easy to change. Or nab things from Flash, maybe - but people likely to use this exploit to educate are probably more likely to run Flash blockers.

Re: Firesheep usage leads to Idiocy

#7

I wonder how this jives with security expert Bruce Scheiner's stance: http://www.schneier.com/blog/archives/2008/01/my_open_wirele...

Doesn't seem to line up much... his stance is about running his own open wireless access point, and how much FUD there is around it, not SSL on websites.

edit: ah, now I see what you were getting at. Though things have changed now that it's easier, and there's nothing inherently dangerous with open wifi - SSH to your server, and you're plenty secure.

Re: Firesheep usage leads to Idiocy

#8
post #6
post #3

This sounds like an interesting idea, but is it legal to run? Sure it might be a good thing to educate people about the dangers of accessing the internet over open wireless, but what if you accidentally run it on the account of someone who is willing to sue? Do they have a legal basis to sue you? Just because they are doing something stupid, doesn't give you the right to mess with their accounts.

Unless they're running a honey-pot machine... how do they tell? You're coming from the same IP, with the same session. At best they can fingerprint your browser, which is far from proof and easy to change. Or nab things from Flash, maybe - but people likely to use this exploit to educate are probably more likely to run Flash blockers.

While it may be unlikely for you to get caught in my mind that still doesn't make it a good idea to run Idiocy. In essence I consider it to be a form of cyber terrorism.

Terrorists use illegal or unsavory acts to gain attention and draw media coverage of their cause. Essentially idiocy is just cyber terrorism. It says "Look! I can take over your account. Now that you are scared let me show you what I want you to do."

I'm sure that if this takes off it will get media coverage, and may even cause people and websites to change their habits and protocols, but why should terrorism be used to accomplish a change to secure web protocols?

Then again I have never been a believer in "the end justifies the means" so even assuming that the end result of forcing people to use HTTPS is good, I don't think cyber terrorism is a good way to accomplish it.

Re: Firesheep usage leads to Idiocy

#9
post #8
post #6

Earlier quoted context omitted.

Unless they're running a honey-pot machine... how do they tell? You're coming from the same IP, with the same session. At best they can fingerprint your browser, which is far from proof and easy to change. Or nab things from Flash, maybe - but people likely to use this exploit to educate are probably more likely to run Flash blockers.

While it may be unlikely for you to get caught in my mind that still doesn't make it a good idea to run Idiocy. In essence I consider it to be a form of cyber terrorism. Terrorists use illegal or unsavory acts to gain attention and draw media coverage of their cause. Essentially idiocy is just cyber terrorism. It says "Look! I can take over your account. Now that you are scared let me show you what I want you to do."…

Didn't mean to imply I disagreed with your stance, just pointing out the relative security (unless someone else knows something) of running it.

It probably is illegal, yes, and I won't personally run it, nor recommend anyone else does (as much as I've toyed with the idea of doing just such a thing by hand, at times). One could consider this civil disobedience, however, as it's not inherently harmful nor capable of spreading like a virus, and is for a good cause. At worst it annoys and makes people more paranoid online (as they should be), at best it causes change.

Re: Firesheep usage leads to Idiocy

#10

In the last few days a tool has been released That seems to imply it's a single tool, and once this is "stopped" you don't need to worry any more. Surely it should mention instead that a recently released tool is widely publicised ? Firesheep didn't make this possible, it has been for a long time, it just made it more accessible.

I thought the rest of the paragraph covered that, but I'm happy to edit it if you can suggest a rephrasing? It's just supposed to be a quick introduction stating that the chances of being exploited are significantly higher now that the entry barrier is practically non-existent.

I... how did I miss that. I just went back and it's right there in the next sentence, my apologies. wtf.
Post reply on HN