Herding Firesheep In NYC — Do Users Care?

An anonymous reader writes "Following the Firesheep uproar, I spent some time telling people who don't read Slashdot about the vulnerability that open WiFi networks create in what seemed like the most effective way possible: by sidejacking their accounts and sending them messages about how it happened. The results were surprising — would users really rather leave their accounts open to intruders rather than stay off Facebook at Starbucks? The link recounts the experience, and also lists some rough numbers of how many accounts could be compromised at a popular NY Starbucks location."
Herding Firesheep In NYC — Do Users Care?

  • by pthisis ( 27352 ) on Friday October 29, 2010 @07:40PM (#34069566) Homepage Journal

    It Takes a Thief got the owner's permission before staging the break-ins. If you got someone's permission before attempting to sidejack their account, you'd probably be in the clear. Without it, you're breaking the law.

  • by theshowmecanuck ( 703852 ) on Saturday October 30, 2010 @12:38AM (#34070936) Journal

    Post a toner cartridge and the whole country shuts down.

    Post a toner cartridge full of [] PETN [] and the whole country shuts down.

  • by MichaelSmith ( 789609 ) on Saturday October 30, 2010 @12:45AM (#34070950) Homepage Journal

    Even if thats all made up, this guy has posted more than one item to this blog.

  • by the_womble ( 580291 ) on Saturday October 30, 2010 @02:45AM (#34071262) Homepage Journal

    But they didn't have to be the one spending 20h+ trying to rescue what was left after 50+ different virus and adware fighting over the control of the computer. It's the same with getting their account hacked, it not their problem (they think), it's mine.

    It would be there problem if you did not make it yours.

    Its amazing how willing people are to volunteer free support for Windows. If they are not paying you tell them to ask MS for help.

  • by George_Ou ( 849225 ) on Saturday October 30, 2010 @05:01AM (#34071580)
    Forced SSL doesn't even work for Google, Twitter, and Facebook and probably most other sites even if they support SSL. That's because the javascript on those pages will opt to transmit authentication cookies in the clear. []

