Live data from Hacker News

Facebook Fails at https

musiform.tumblr.com

1–10 of 32 posts

Re: Facebook Fails at https

#2
Even before FireSheep, that was known for anybody who cared to try it. The test (enter FB address with https, try to get the next page) doesn't need FireSheep at all to be demonstrated. And FireSheep doesn't do anything new except packaging the existing technology to make it extremely easy for everybody to experiment. But until FireSheep, if I'd tried to explain the problem to anybody, the best I'd get would be "meh." The worst: "you paranoid." Nice to see the change in the attitude.

Re: Facebook Fails at https

#3
post #2

Even before FireSheep, that was known for anybody who cared to try it. The test (enter FB address with https, try to get the next page) doesn't need FireSheep at all to be demonstrated. And FireSheep doesn't do anything new except packaging the existing technology to make it extremely easy for everybody to experiment. But until FireSheep, if I'd tried to explain the problem to anybody, the best I'd get would be "meh.…

This. I was trying to explain to my co-workers that this issue has existed for as long as the web has existed and they didn't really understand what I was talking about.

Not until they saw a demonstration video did they believe that it was as bad as I was telling them it was. It is hilarious as a security guy watching "new" exploits come out and watching them go into serious mode since this is a new exploit and it is a bad one and it is going to cause doom and whatnot.

If you can't trust the connection you are on, then time to not use said connection or VPN somewhere. Plenty of places to find hosted VPN services.

Re: Facebook Fails at https

#5
post #3
post #2

Even before FireSheep, that was known for anybody who cared to try it. The test (enter FB address with https, try to get the next page) doesn't need FireSheep at all to be demonstrated. And FireSheep doesn't do anything new except packaging the existing technology to make it extremely easy for everybody to experiment. But until FireSheep, if I'd tried to explain the problem to anybody, the best I'd get would be "meh.…

This. I was trying to explain to my co-workers that this issue has existed for as long as the web has existed and they didn't really understand what I was talking about. Not until they saw a demonstration video did they believe that it was as bad as I was telling them it was. It is hilarious as a security guy watching "new" exploits come out and watching them go into serious mode since this is a new exploit and it is…

> Plenty of places to find hosted VPN services

Care to recommend one? I've had a few unsatisfactory experiences (terrible bandwidth, unreliable servers, etc.) and would love a good recommendation.

Re: Facebook Fails at https

#6
Any Facebook employee reading this? That'd be a great thing to fix, and the PR of a positive privacy story about Facebook would probably be welcome.

I'd also love if they enabled encryption for FB chat, even if you used an external client like iChat or Pidgin.

Re: Facebook Fails at https

#7
Whats the point? Sensitive Information like the login page is secured by https (which is a great thing) but why encript the data you don't need to have encripted?

It's (for me) pretty simple. they force the users to use http because the amount of cpu time which is spent for http user is lower than the time for https...

just my two cents

Re: Facebook Fails at https

#8
post #7

Whats the point? Sensitive Information like the login page is secured by https (which is a great thing) but why encript the data you don't need to have encripted? It's (for me) pretty simple. they force the users to use http because the amount of cpu time which is spent for http user is lower than the time for https... just my two cents

Reading about Firesheep you'd find out that the session cookie is passed in the clear and acquiring that allows you to steal someone's session. This is easy on WiFi. That's why it matters.

Re: Facebook Fails at https

#9
post #8
post #7

Whats the point? Sensitive Information like the login page is secured by https (which is a great thing) but why encript the data you don't need to have encripted? It's (for me) pretty simple. they force the users to use http because the amount of cpu time which is spent for http user is lower than the time for https... just my two cents

Reading about Firesheep you'd find out that the session cookie is passed in the clear and acquiring that allows you to steal someone's session. This is easy on WiFi. That's why it matters.

Eew... i'm sorry. i didn't realized this point... you're right sir! this behaviour isn't good...

Re: Facebook Fails at https

#10
Perhaps supporting ssl and/or tls across their infrastructure isn't a priority. Why is that a "fail", as you so succinctly put it?

In addition, I'd like to ask the entire world to stop using 'fail' as a noun. It's lazy and incorrect.

Post reply on HN