Perimeter
Guest Blog // Selected Security Content Provided By Sophos
What's This?
10/26/2010
02:35 PM
Dark Reading
Dark Reading
Security Insights
Connect Directly
RSS
E-Mail
50%
50%

Cookies, Social Media And FireSheep

We've been seeing a lot of interest in FireSheep, the FireFox add-on that lets you spy on websites. How bad is it really?

We've been seeing a lot of interest in FireSheep, the FireFox add-on that lets you spy on websites. How bad is it really?To back the train up, let me explain what the add-in actually does for the benefit of the not-so-technical reader. When you go to a coffee shop or anywhere that has public WiFi, you share that connection with every other person using it. So the traffic all goes out over the same IP address. If a patron logs into most websites, then he or she will get a session ID and a cookie. If one can spy on the contents of that cookie, then the "hacker" can use that ID and the additional info to send traffic as that patron. Yes, usernames and passwords are encrypted on login with https and/or SSL, but then most sites switch back to plain, old unencrypted HTTP. This is generally seen as a VERY BAD THING if you are a privacy advocate.

Now none of this is new, different, or original. There have been sniffing techniques as long as there have been cookies. However, a well-meaning researcher by the name of Eric Butler has changed the game by making this technique extremely simple and accessible to the average person. Now I get what his aim was: He tried to show how insecure websites are. We security folks have been banging the drum on this for ages. I'm hoping sites like Facebook and Twitter will take notice. But will they?

Putting aside the security hat for a moment, let's look at these sites. Social networking sites have a business plan. That plan is to connect people and get them to share ideas, content, photos, etc., as freely as possible. Security and privacy simply are not at the top of the business plan. They now have to skate the line of trying to satisfy security experts and privacy advocates, while still holding to their business plan of allowing the sharing of information. Now does that mean personally identifiable info (PII) should be on display? Not really, but you willingly provide that information when you sign up for these sites (unless you give false information). These sites have a responsibility to protect your PII, but you have the choice of whether to provide it in the first place. Now that said (security hat goes back on), social networks most certainly DO have an obligation to ensure the person logged into the account really is that person and not someone masquerading as him or her. And, yes, they do need to start securing the whole session and not just the logging in portion of the session.

On a side note, someone asked us at Sophos if we think Firefox should start vetting add-ins to prevent them from ever being downloaded. Should they? Probably. Can they? That's a question I can't answer. Being an open community means there is such great range of innovation and tools to help, but at the same time that means any bad guy can easily get in and spoil things.

Beth Jones is a Senior Threat Researcher in SophosLabs North America. She manages the day-to-day research and analysis activities of incoming suspicious malware threats and potentially unwanted applications that arrive in the Lab via Sophos customers, partners, and prospects.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-4988
Published: 2014-07-09
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

CVE-2014-0207
Published: 2014-07-09
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVE-2014-0537
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-0539
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-3309
Published: 2014-07-09
The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.