Re: HTTP is just fine

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> you don't understand what firesheep does - it does not require access to 
> computer under attack, it requires access to network on which the system 
> under attack is
> 
> and that is not exactly that hard to arrange if you're on a WiFi in a 
> hotel/coffee house/event or on a network in school/library...
> 
> it's not 1970's any more, there is no such thing as a "trusted network"*

Sorry but that is more bullshit!

"However, using Wi-Fi Protected Access (WPA or WPA2) encryption offers
individual user isolation, preventing the attacker from using Firesheep
from decrypting cookies sent over the network even if the Firesheep
user has logged into the network using the same password.[11] An
attacker would be able to manually retrieve and decrypt another user's
data on a WPA-PSK connection, if the key is known and the attacker was
present at the time of the handshake, or if they send a spoofed
de-authenticate packet to the router, causing the user to
re-authenticate and allow the attacker to capture the handshake. This
attack would not work on WPA-Enterprise networks as there is no single
password (the 'Pre Shared Key' in PSK)."

AND

on top of that any site that is set up half correctly would not be
vulnerable anyway!!

http is not for logins, no-one said it was, what is being argued with is
whether the world is truly more secure with or without http. I
would state that the world is less correct with only https and no http
and also state that some servers are more secure without https.

-- 

KISSIS - Keep It Simple So It's Securable
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.