Live data from Hacker News

How to screw with those firesheep snoops - FireShepherd

blogs.forbes.com

11–12 of 12 posts

Re: How to screw with those firesheep snoops - FireShepherd

#11
post #8

This a naive question, but what would prevent Google from buying one of the trusted CAs (or fast tracking their own service into most browsers) and knocking the bottom out of the cert market with a free and easy SSL solution? It doesn't make much business sense, but it fits in with some of Google's more philanthropic initiatives for a healthier net.

As I understand it, certificates are not the only problem. SSL requires significantly more overhead on the server as well, which is why it is commonly used just for logins.

There was a good discussion about it on stack overflow: http://stackoverflow.com/questions/548029/how-much-overhead-...

The bottom line is that with keep-alive connections, the overhead should be less of a problem, since the only expensive part is the initial RSA key generation.

Re: How to screw with those firesheep snoops - FireShepherd

#12
post #9
post #3

Earlier quoted context omitted.

Plus it probably can be fixed easely by FireSheep with an update. If FireShepard were to flood the network with fake personalities and their cookies instead, it might help hiding real accounts.

yeah, and if each fake personality lead to a rick roll or worse...

Wouldn't be subtle enough.
Post reply on HN