Live data from Hacker News

Firesheep, Week+ later

news.ycombinator.com

1–10 of 22 posts

Firesheep, Week+ later

#1
Nearly 500k firesheep downloads in 1 week. Microsoft, Facebook, others, have still not deployed SSL, granted this might be a complicated deployment.

But they didn't warn users either, how can this be justified? a warning is simple enough.

Re: Firesheep, Week+ later

#3
post #2

maybe because it's not a new threat and it's not their responsibility?

I think OP was suggesting that it's the responsibility of those companies to warn their users, etc. Not that it was the firesheep dev's responsibility.

Re: Firesheep, Week+ later

#4
post #3
post #2

maybe because it's not a new threat and it's not their responsibility?

I think OP was suggesting that it's the responsibility of those companies to warn their users, etc. Not that it was the firesheep dev's responsibility.

exactly, it's MITM attack people have been able to do for at least a decade

Re: Firesheep, Week+ later

#6
post #4
post #3

Earlier quoted context omitted.

I think OP was suggesting that it's the responsibility of those companies to warn their users, etc. Not that it was the firesheep dev's responsibility.

exactly, it's MITM attack people have been able to do for at least a decade

That doesn't really make it less of a security threat. Sites still don't know how to secure it. On my own site we do the same, and have no other answer but end-to-end encryption which we then charge for.

Re: Firesheep, Week+ later

#7
At least one site, GitHub, has certainly deployed changes as a result (and also pointed out that the author of Firesheep gave absolutely zero warning to the sites it targeted, which unnecessarily left a great many users vulnerable on sites like GitHub that would have otherwise been able to close the hole before Firesheep made it public information).

Re: Firesheep, Week+ later

#8
Why would they want to bring attention to something negative? What motivation do they have to make an announcement prior to fixing it unless the issue gets mainstream attention?

Re: Firesheep, Week+ later

#10
post #2

maybe because it's not a new threat and it's not their responsibility?

I disagree, on a certain level it is new. Few security flaws (i actually cant recall any) made a change from a fairly technical and obscure possibility, into a browser plugin.

as the download numbers show, the tool is now accessible in a manner that makes an exploit trivial and require no technical knowledge. I am of the opinion that providers like facebook etc... would do their users a service, by explaining to them the risk of accessing their networks via open wireless networks for instance. Perhaps it is not their responsibility but it might be beneficial for them to help the public understand privacy concerns.

Post reply on HN