GitHub moves to SSL, but remains Firesheepable
news.netcraft.com
GitHub moves to SSL, but remains Firesheepable
1–10 of 15 posts
Re: GitHub moves to SSL, but remains Firesheepable
#2Re: GitHub moves to SSL, but remains Firesheepable
#3Re: GitHub moves to SSL, but remains Firesheepable
#4We fat fingered the config. The cookie is marked secure now but we found another issue where it's being sent back on redirected HTTP requests. It should be all plugged up in a bit.
Re: GitHub moves to SSL, but remains Firesheepable
#5We fat fingered the config. The cookie is marked secure now but we found another issue where it's being sent back on redirected HTTP requests. It should be all plugged up in a bit.
Okay. The session cookie is marked secure and is sent only in response to HTTPS requests. That should cover everything.
Re: GitHub moves to SSL, but remains Firesheepable
#6I wish other sites were able to follow suit.
Re: GitHub moves to SSL, but remains Firesheepable
#7Re: GitHub moves to SSL, but remains Firesheepable
#8It's nice to see GitHub jumping to show action in regards to FireSheep and SSL security, and being able to implement something quickly. I wish other sites were able to follow suit.
Also, their audience is much more likely to pay attention to things like FireSheep. I can just about guarantee that 9/10 Facebook users have never heard of FireSheep and wouldn't even notice if Facebook went 100% SSL tomorrow.
Edit: That said, I totally agree with your comment.
Re: GitHub moves to SSL, but remains Firesheepable
#9Re: GitHub moves to SSL, but remains Firesheepable
#10Maybe I shouldn't be so naive, but this whole firesheep release is very shocking to me. Facebook is very insecure, and it is incredibly scary that so many people trust Facebook's privacy and give Facebook so much personal information.