Live data from Hacker News

Firesheep usage leads to Idiocy

jonty.co.uk

81–89 of 89 posts

Re: Firesheep usage leads to Idiocy

#81
Has anyone gotten this thing to even work? Seems to rely on http://code.google.com/p/pypcap/ and when I attempt install from source the install.py turns out to be horribly useless.

Without installing that pypcap thing and just using libpcap, I get this error:

  Traceback (most recent call last):
  File "idiocy.py", line 128, in 
    main()
  File "idiocy.py", line 20, in main
    cap = pcap.pcap(device)
  AttributeError: 'module' object has no attribute 'pcap'

Re: Firesheep usage leads to Idiocy

#82
Ok, dumb question time: Outside of things like banks, does anyone actually run a 100% SSL web server?

I thought the point of Firesheep was more "don't use unsecured networks" than "don't use websites that aren't 10% SSL." If it's the former, then this only does any good if the "victims" are the people providing the service. How many people do you think are going to notice this tweet immediately, realize where they were when it happened, and complain to the wifi provider (whose response, of course, will be "use at your own risk").

It might do some good for people running insecure networks at home, but the people that understand what happened and how to fix it would already be running secure networks at home.

Re: Firesheep usage leads to Idiocy

#83

Earlier quoted context omitted.

If half of their friends also have their fly open, shouting it might be a better option.

I'm missing the logic here. If few people make a mistake, they should be informed privately, but if many people make a mistake, they should be shamed publicly? No. And to be honest, I'm getting slightly tired of the community's tendency to stretch metaphors way beyond their applicability. Mine was mostly meant to add a touch of humor. Pants, flies, and underwear aside, auto-hijacking the Twitter accounts of everyone…

Metaphors are less effort to bike-shed than the underlying concept. Witness the undying car analogy, or the "C is a hammer" nonsense from a couple of days ago.

Yes, it's boring; yes, it's intellectually lazy and useless. No, it's not going away.

Re: Firesheep usage leads to Idiocy

#84
post #54

Earlier quoted context omitted.

Your alternative to SSL would allow MITM attacks. Thus it would be useless.

I don't see another compromise that wouldn't require the signature infrastructure. MITM attacks are much less common than sniffing attacks as we can see here.

MITM over wifi isn't much harder than this attack, you've just got to convince people to associate with your AP rather than the default. Ettercap has been able to do that sort of thing for years; all that's needed is a swanky front-end.

Re: Firesheep usage leads to Idiocy

#85
post #54

Earlier quoted context omitted.

Your alternative to SSL would allow MITM attacks. Thus it would be useless.

I don't see another compromise that wouldn't require the signature infrastructure. MITM attacks are much less common than sniffing attacks as we can see here.

Use the DNSSEC signature infrastructure.

Generate your own self signed SSL certificate, then stick a hash of that cert in the DNS for your DNSSEC protected domain.

Of course, people need to start using DNSSEC, and browsers need to be updated to work with this system, but it beats paying a CA.

Re: Firesheep usage leads to Idiocy

#86
post #23
post #16

Earlier quoted context omitted.

From the code: status = 'I browsed twitter insecurely on a public network and all I got was this lousy tweet. http://jonty.co.uk/idiocy-what'

Unfortunately, the link it includes doesn't contain the part mentioning this capability is nothing new, merely that there's a new tool for it: http://jonty.co.uk/idiocy-what If the creator is browsing through these: include that part , or people will associate the danger with the new tool, and nothing else.

Good point! If you have any other comments I'd love to hear them.

Let me know if you think I should make any other edits: http://jonty.co.uk/idiocy-what

Re: Firesheep usage leads to Idiocy

#87
post #23
post #16

Earlier quoted context omitted.

From the code: status = 'I browsed twitter insecurely on a public network and all I got was this lousy tweet. http://jonty.co.uk/idiocy-what'

Unfortunately, the link it includes doesn't contain the part mentioning this capability is nothing new, merely that there's a new tool for it: http://jonty.co.uk/idiocy-what If the creator is browsing through these: include that part , or people will associate the danger with the new tool, and nothing else.

[deleted]

Re: Firesheep usage leads to Idiocy

#88
post #23

Earlier quoted context omitted.

Unfortunately, the link it includes doesn't contain the part mentioning this capability is nothing new, merely that there's a new tool for it: http://jonty.co.uk/idiocy-what If the creator is browsing through these: include that part , or people will associate the danger with the new tool, and nothing else.

Good point! If you have any other comments I'd love to hear them. Let me know if you think I should make any other edits: http://jonty.co.uk/idiocy-what

I think I'd swap the first and second paragraphs. That way, it makes more sense after "What happened?!", and reassures people ASAP so they won't lose interest / be confused before they find out what happened.

Re: Firesheep usage leads to Idiocy

#89
post #16

Earlier quoted context omitted.

From the code: status = 'I browsed twitter insecurely on a public network and all I got was this lousy tweet. http://jonty.co.uk/idiocy-what'

Barely in use so far: https://twitter.com/search?q=I+browsed+twitter+insecurely+on...

http://twecan.com/#!/insecurely%20on%20a%20public%20network
Post reply on HN