Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> you don't understand what firesheep does - it does not require access to > computer under attack, it requires access to network on which the system > under attack is > > and that is not exactly that hard to arrange if you're on a WiFi in a > hotel/coffee house/event or on a network in school/library... > > it's not 1970's any more, there is no such thing as a "trusted network"* Sorry but that is more bullshit! "However, using Wi-Fi Protected Access (WPA or WPA2) encryption offers individual user isolation, preventing the attacker from using Firesheep from decrypting cookies sent over the network even if the Firesheep user has logged into the network using the same password.[11] An attacker would be able to manually retrieve and decrypt another user's data on a WPA-PSK connection, if the key is known and the attacker was present at the time of the handshake, or if they send a spoofed de-authenticate packet to the router, causing the user to re-authenticate and allow the attacker to capture the handshake. This attack would not work on WPA-Enterprise networks as there is no single password (the 'Pre Shared Key' in PSK)." AND on top of that any site that is set up half correctly would not be vulnerable anyway!! http is not for logins, no-one said it was, what is being argued with is whether the world is truly more secure with or without http. I would state that the world is less correct with only https and no http and also state that some servers are more secure without https. -- KISSIS - Keep It Simple So It's Securable