There is a Firesheep discussion around here someplace, but search is not working for me this morning, so I shall begin a new topic.
Firesheep has already taught 750,000 people how to hijack your unencrypted WiFi sessions with a single click.
So here's how to extinguish Firesheep with a technological defence that you can put together in just 60 seconds, even when you're on the road, and even if you're connecting over unencrypted WiFi to start with.
Once you're done, you can browse over unencrypted WiFi access points with no more risk than you'd browse at home.
I know that I posted a thread here that "alluded" to firesheep, but intentionally avoided the name, due to its controversial use.
That is the discussion that I was thinking of. Considering the publicity, including a couple of excellent podcasts by Steve Gibson, there was no need to "allude" to Firesheep. Making the public and businesses that provide free wifi aware of it turned out to be a good thing.
I don't believe the discussion of FireSheep is anywhere in the virus/spyware forum... I know that I posted a thread here that "alluded" to firesheep, but intentionally avoided the name, due to its controversial use. [Perhaps there might be a thread about it elsewhere in the Dell forums??]
Quoting from the video: "it's easy if you are a UNIX-head and you happen to have an SSH server running at home..." I wonder how many of us that describes?? The video's information flew-by way-too-quickly, and went in AND OUT of my head just as fast :emotion-4: Perhaps if I played it several times --- slowly, and pausing --- I might be able to make more sense of it.
But on first impression, it almost seems as if the user would have to keep their home network on/running while they were away (e.g., at the airport)... and I have yet to fathom how he/she will able able to "reach" his/her home network from such distance.
But at the time I posted, we had no way to predict what might have happened... which is why I felt the need to notify the public (i.e., this forum) about the existence of a vulnerability, without my "broadcasting" how they could go about exploiting it.
---------------------
You didn't comment about the rest.... is the approach suggested in the video viable for most (average? advanced?) users?
"I doubt that the average user would have a clue." Thank you for being candid. I don't consider myself an "average user", and I freely admit having no idea what was being discussed there.
"I use a VPN and think that most would find that a simpler way to go". I was going to ask about that alternative next. Is there a free (and easy to setup/use) VPN program that you can recommend here? [I had "tinkered" with one a while back... it was free, but at the "price" of it being adware].
I had "tinkered" with one a while back... it was free, but at the "price" of it being adware
That is probably the one I use. The adware appears only on IE (so far), so I use FF with No-Script. I can deal with the adware better than I can deal with the ramifications if someone hacks into one of my accounts. However, because of that adware, I won't recommend that particular VPN here, even if it is "the lesser of two evils".
the problem (at least, as I understand it) is that using a non-secure [non-encrypted (non-WPA, non-WEP)] WiFi connection can allow (via FireSheep) secure [https://] information over non-secure [http://] sites... because once you establish a secure connection, the cookie information [required for security] is transmitted repeatedly... regardless of whether the continuing transmissions are secure or non-secure. I don't see how surfing within a sandox can bypass this. [Just a reasoned speculation on my part, I can't assert this with any certainty.]
Bugbatter
4 Apprentice
•
20487 Posts
243
0
Posted November 15th, 2010 05:00