An Around-the-World Travel Blog for Independent Travellers

Why Travellers Should Be Aware of Firesheep

Firesheep is a new security exploit (“hacking”) tool that allows wanna-be hackers with very little expertise to gain access to the accounts of their victims on a range of websites, including facebook, flickr, and twitter, when using an unsecured wifi network.

It’s particularly bad news for travellers, who tend to use unsecured wifi networks from their laptops, netbooks and smartphones — in cafes, guesthouses, etc — much more than the broader public.

Although the technique that Firesheep uses is not new, it was previously moderately difficult to perform. The release of Firesheep means that someone with almost no technical knowledge can gain access to other peoples accounts when using the same unsecured wifi network.

You will potentially be at risk if:

  • You’re using an unsecured wifi network — one that isn’t protected by a password.
  • The accessing facebook, twitter or google via HTTP, rather than HTTPS (secure HTTP)

Luckily Firesheep does not allow the hacker to get hold of your password.

firesheep.jpg

How to Protect Yourself

Here are a few things that you can do to prevent being hacked by Firesheep

  • Use a secure wifi network wherever possible.
  • If you are using Firefox, the EFF’s HTTP Everywhere extension will force your browser to use HTTPS when accessing the affected sites. Unfortunately, it seems that Safari, IE and Chrome’s extension architecture prevents a similar plugin being written for any of them, so for the moment, it’s only available for Firefox.

    Even if you don’t use Firefox normally, it would be a good idea to use Firefox with the HTTP Everywhere extension whenever you’re accessing the internet via unsecured wifi. At least until the exploit is fixed.

  • If you have to use an unsecured wifi network, always log out of any websites that you’ve logged into during the session, even though you’re using your own computer. This will invalidate any website cookies which the hacker could use to pretend he is you.

More information:

Firesheep

How to protect against Firesheep attacks

 

Related Posts Plugin for WordPress, Blogger...

  • http://www.123indiavacations.com India Vacations

    Thanks for the share of this tool