Feeds

Browser add-on updated to slaughter Firesheep

HTTPS Everywhere: the missing protection

Choosing a cloud hosting partner with confidence

The Electronic Frontier Foundation has updated its popular web browser security tool to guard against attacks waged by the Firesheep script-kiddie snoop kit.

HTTPS Everywhere 0.9.0 has been updated to force websites such as Facebook and Twitter to activate a secure flag in cookies used to authenticate users on those websites, said EFF Senior Staff Technologist Peter Eckersley. By forcing the sites to send the authentication cookies only when a connection is protected by secure sockets layer encryption, man-in-the-middle attacks like the ones launched by cookie-jacking Firesheep are thwarted.

“By forcing cookies to Secure, HTTPS Everywhere adds protection against Firesheep that site operators should have but failed to provide,” said Chris Palmer, an EFF technology director who also worked on the project.

Although the web has been vulnerable to such attacks for more than a decade, many webmasters still don't follow best practices when granting users access to restricted parts of a site. A case in point, the latest version of HTTPS Everywhere breaks parts of Facebook that can only send authentication cookies over unprotected HTTP channels. That means that using the updated tool with Facebook chat and certain apps isn't possible – at least until changes are made to parts of social networking site.

The update also works with several widely used cloud-based services, including Amazon storage service s3.amazonaws.com and twimg.com, reducing the problems when one of those sites is used by Twitter, Facebook or another website. It has also been updated to work with more websites, including Bit.ly, Cisco, Dropbox, Evernote and GitHub.

HTTPS Everywhere is a Firefox plugin that, like NoScript, is a must-have for security-minded users of the open-source browser. It was released in June by the EFF and members of the Tor Project. It has been downloaded more than 500,000 times.

The code behind the add-on is based in part on the Strict Transport Security response header that's under consideration by the Internet Engineering Task Force as a way for websites and browsers to exchange data only when an encrypted connection is being used. Eventually, the technology will probably be widely available. For now, it's available for only a small smattering of websites and browsers. ®

Beginner's guide to SSL certificates

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
US government fines Intel's Wind River over crypto exports
New emphasis on encryption as a weapon?
To Russia With Love: Snowden's pole-dancer girlfriend is living with him in Moscow
While the NSA is tapping your PC, he's tapping ... nevermind
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Put down that shotgun: Wi-Fi's the way to beat Zombies
CreepyDOL sensors can pick walkers from humans with MAC snack attack
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.