Herding Firesheep in a NYC Starbucks: Do Users Care?
technologysufficientlyadvanced.blogspot.com
technologysufficientlyadvanced.blogspot.com
You describe your targets as lacking judgment. Maybe you should consider your own.
The folks I recognized on my way out were people with large profile pictures of their faces. In general, this wasn't the case. I'd have had to do a lot more rifling through accounts to be able to identify someone face-to-face, and would have risked someone having a bad reaction.
So, unlike all the people who have used Firesheep in public to look at peoples' accounts and then not told anyone about it, I notified the users and then told the public about what happened. You're saying that's bad?
From your blog: "I opened up his Amazon homepage, identified something he had recently looked at"
Let's look at the Florida statute:
815.06 - Offenses against computer users. -
(1)Whoever willfully, knowingly, and without authorization:
(a)Accesses or causes to be accessed any computer, computer system, or computer network;... commits an offense against computer users.
(2)(a)Except as provided in paragraphs (b) and (c), whoever violates subsection (1) commits a felony of the third degree, punishable as provided in s. 775.082, s. 775.083, or s. 775.084.
So you committed a felony punishable by up to five years in prison, informed the victims, and documented your crime in explicit detail on your blog. That's a tad more dangerous than using unsecured cookies.
The reverse obviously is also true, and arguably applies in this situation. (I'm not arguing that it does, but but the OP is).
Ethics are subject to opinion, one man's gray area is another mans A-Ok, and another's "big fat red zone".
Also I don't live in Florida.
I also never said that I thought I was protected from prosecution, so I don't know why you're so eager to prove that I am.
156.10 Computer trespass.
A person is guilty of computer trespass when he knowingly uses or causes to be used a computer or computer service without authorization and:
1. he does so with an intent to commit or attempt to commit or further the commission of any felony; or
2. he thereby knowingly gains access to computer material.
Computer trespass is a class E felony.
You also wrote '[I] then sent him a "no, seriously" message on Facebook from his account including the fun fact about his music choices.'
Viewing a person's music choices and sending them a message about them is a total violation of privacy. Or do you just attribute that to being another exception?
Just because it's easy doesn't mean it's ethical.
You notice that some folks in your town aren't locking the doors of their houses when they leave. So you go to each of those houses (when they're not there), walk in the front door, and tack a note to the first wall you encounter, telling them that they really ought to lock their doors.
The next day you go back and check their locks. For those that are still unlock, you go into their bedroom and mess up their sheets (being careful not to look around too much lest you notice some "marital aids", since you're not that kind of guy), so they can see that someone's really coming into their house.
It's pretty clear that you've violated any number of laws, morals, and societal values in the physical world. Why, in the virtual world, do you think that in doing so you're a white knight?
If someone breaks into your Facebook account, bad things can happen, but none that (directly) involve physical harm. If someone enters your home, they could easily cause you physical harm (and in many jurisdictions you'd be well within your rights to shoot them).
Your analogy is flawed because a person's home is not analogous to their Facebook account. Their car might be -- and I don't think opening an unlocked car door and leaving a note on the dash is wrong.
It's like when people equated Amazon's revoking of 1984 to breaking into a customer's house and taking the book off the shelf. It's fearmongering, and isn't an accurate analogy.
Are you serious? If someone did that to me I would feel terribly violated! Even if I forgot / just thought I lived in a neighborhood with human decency, that is wrong on so many levels.
Trespassing by accessing someone else's property, home, car, or virtual, is wrong. Harm is harm, physical or not, and you can cause plenty of harm by accessing someone's facebook account, embarrassing them to friends or co-workers for starters.
These are your opinions, your values. You've got no business with (a) deciding the value of a person's virtual identity and data; nor (b) weighing that against your value for the education about greater security.
You might be right -- FOR YOUR PERSONAL VALUES. But it's simply none of your business how another person would judge this in the balance. Your beneficiaries/victims have every right to decide for themselves that the security afforded by the current systems are sufficient for the risks. And the fact that their decision makes it easier for you to teach them a lesson does not give you the right to do so.
I would agree that there are some ethical problems with his actions, but this is far from being ethically analogous to the whole break-in scenario.
We can go back and forth on the white hat/black hat issues, but I think we need more people who are willing to raise awareness on this.
The animosity should be reserved for those who use Firesheep/Wireshark for completely malicious purposes.
As Henry David Thoreau said, If I knew for a certainty that a man was coming to my house with the conscious design of doing me good, I should run for my life.
You also seem to be describing the US Congress.
Maybe send the first message, but don't be obnoxious on purpose. I dunno.
(edit) What I mean here, is that to know that someone's door is unlocked, you have to check each house. To pick a lock, you need some rudimentary skill. Firesheep (and the underlying vulnerability) is wide open and requires 0 skill to operate.
For a non-tech person it's a pretty big jump from surfing Facebook at Starbucks to setting up a VPN.
Edit: waiting for the Starbug - small devices you stick to the bottom of a desk in starbucks that stream user data to your hacker home.
Your name is Gary LosHuertos
You look like this: http://yfrog.com/0irajuj
Gender: Male
Astrological Sign: Scorpio
Industry: Consulting
Occupation: Software Engineer
Location: New York : NY : United States
You have a blog hosted on BlogSpot from which this article came.
You send tweets from @gloshuertos where you promoted this story.
Your twitter account lists a latitude/longitude address of 27.109827,-82.308136 which is in Venice, Florida. One of your oldest tweets mentions that you're on your way to Gainsville, Florida.
https://twitter.com/#!/gloshuertos/status/1267758656
Only one Gary LosHuertos comes up on LinkedIn, but this person used to work in Gainsville Florida, so it's reasonable to assume this person may be you.
http://www.linkedin.com/pub/gary-loshuertos/11/68/aa0
The interesting thing about that LinkedIn profile is that it lists your current employer as Amazon.com. From your blog post, you mentioned the following:
"This was somewhat puzzling. Did they receive the first message? I logged into their accounts, and surely enough, they had. One of them was even on Amazon.com, which I had warned about in my first message. I targeted him first: I opened up his Amazon homepage, identified something he had recently looked at, and then sent him a "no, seriously" message on Facebook from his account including the fun fact about his music choices."
So what you're telling us is that you used a user account of a customer of your current employer to login as that person, spy on their purchases, then logged to their Facebook account and send them messages about his customer information?
You're entering into a world of hurt if Amazon catches wind of this.
Most people already know that if someone gets a hold of their account, and they already have access to it, to change the password. For this particular situation, they don't know about the whole SSL thing. It took me nearly 20 minutes to explain what a session was to my very non-technical girlfriend 2 days ago. Most people are very unsure of following directions from an untrusted source on the internet, even if they are very trusting of strangers on the internet. Most users are aware of Phishing scams as a general strategy. There is a good possibility they changed their passwords, since that is what they already know, but that particular solution doesn't work all that well for this scenario.
You're saying I shouldn't bash my employer on a public blog and then submit it to another public website?
OMG
Really you didn't dig deep enough. Googling my name pulls up an email with my current employer in it. I don't work for Amazon anymore.
Two wrongs do not make a right, but when you can implement a technical measure to protect your users from rogue ex-employees, you should do it. A legal contract does not prevent data loss, it merely allows you to punish the person who stole the data. SSL prevents the data loss in the first place.
I think most users have already accepted that information previously considered private is now available to most of the world. The step from anonominity to the information posted above is a hell of a lot more scary than from the information posted above to someone knowing your current location.
I know that the point of the article was that the author was able to log into random users accounts, but the scary part was supposed to be that the author knew exactly who and where they are. But when they give away information like the above on a regular basis, I honestly think users could care less.
"You're in Toronto, your IP is 99.12.34.56, your ISP is Rogers, you're using Windows XP! Thieves can steal your info! Download our antivirus now!"
I think your average internet user would feel this was primarily Facebook's (and other sites) problem to fix first. A distant second might be that there was a problem with their browser. It would barely register that they should change their behaviour or pay for a service they've not heard of before.
1. During the HTTPS part of the communication,
the server sends a long list of random strings.
2. The client stores all these strings in localStorage.
3. On every request, the client sends one of the strings
from the list, the server validates that it is in fact
a valid string for that session, and both remove that
string from their lists.
4. When the list runs out, you have to go back to SSL to
exchange a new list of strings.
Is there a flaw I'm overlooking (beyond the reliance on localStorage) that keeps people from using this?If not, is there a technical term for this technique so I can Google it?
(Just like the SAS codes that are used by STRATCOM to authenticate nuclear launches! ;)
The only way I can think of involves being really clever about timing and being physically between the other wireless client and the AP: create enough interference to prevent their transmission from getting through to the AP right after you read the transmission, then quickly forge a request using the same one-time key.
Of course, if someone has access to the packets upstream from the AP, you're always hosed if you're not using encryption. This certainly isn't meant as a replacement for AES. :)
Yes. You can attack ARP or DNS to take control of their connections.
For ARP-based attacks you'd presumably announce yourself as the owner of the default gateway's IP address, routing all data through your system.
Hijacking DHCP springs to mind; respond with an address on a completely different subnet, and your system as default gateway. Again, jackpot.
You could also install a rogue wireless access point with the same SSID, which would let you route all traffic through your system. You just need people's devices to pick yours over the real one, which would presumably require yours to have a stronger signal.
All of the above let you install a transparent proxy which gives you complete control over the target's browser's security context.
Interestingly, the rogue access point would even work with WPA(2)-PSK encrypted wifi, if you knew the key.
1. During the HTTPS part of the communication, the server generates a single
random key and sends it to the client.
2. The client stores this string in local storage.
3. For every request, the client generates a HMAC over the request parameters
(including a monotonic sequence number) using the key.
Both of these schemes are still susceptible to a MITM, who can just insert a bit of javascript in any page received over HTTP, that reveals the temporary secret in local storage to anyone listening.Smaller sites will suffer from the fact that SSL requires an IP address per server. Name based virtual hosting is out of the question (at least as long as Windows XP is still around). Combine this with the IP address pool quickly getting smaller and smaller and you'll see that for smaller sites, it might be impossible to get the needed amount of addresses for a reasonable price.
For large sites, there's the problem of the various CDNs which are not always under the control of the site and might not be prepared for SSL.
Remember: All assets of an encrypted page must also be encrypted, otherwise the browsers display a nasty warning (even though unencrypted assets, when served from a different domain would not be a problem what's session hijacking is concerned).
"just use SSL" might just not be possible in some cases.
https://secure.wikimedia.org/wikipedia/en/wiki/Server_Name_I...
Unforunately, support is not sufficiently widespread at this time.
Your read-only session might still be high-jacked, but that's relatively low impact, (since someone could simply sniff what you're reading anyway).
I love trains, coe's quest and minecraft. Looks like a perfect fit
I'm sure you thought you were doing something good. But, short of not using Facebook in a coffee shop, what do you expect people to do? Set up their own VPN? I bet that of the people you scared off, they'll all be back on in another day or two. Maybe at the same coffee shop.
This is a problem that needs to be solved by on the website's end, not the user's end.
I feel mostly the same way about Facebook, those so inclined could do more damage un-friending everyone, at which point I could thank them for cleaning out old contents and organically readd those who I still speak to.
People see starving children on CNN and they think "Oh, how awful!" Then they turn off the TV, eat dinner, and go on with their lives.
Further, the media as a whole runs so many scare articles to increase views, I think the public is jaded. How is the common man supposed to tell the difference between articles about the threat of bedbugs and the very real threat of this sort of identify theft?
That's not incomprehensible. They have trust. And they don't consider what they're doing particularly private.
Why suddenly jump on FB, Twitter etc with self-righteous anger when many of these same geeks were using insecure email until less than a year ago?
I've had a quick look and not seen anything but it's entirely possible I've missed something.
One example of the attack http://techcrunch.com/2009/01/20/latest-facebook-scam-phishe...
In those cases the fraudsters have stolen the account completely and locked the original user out, but I guess it's that kind of attack + the information leakage aspect that could be a concern..
This difference -- from random anonymous stranger whose only invested in software, to physical infrastructure with paid staff -- is also one reason bank phishing attacks happen via websites and not actual storefronts made to look like real banks.
If the only threat to Twitter and Facebook users was ISP-gnomes, the websites could put off fixing the issue for another decade.
Security is about battling a combination of Time + Talents/Tools + Determination + Opportunity.
Firesheep greatly increases the Tools someone has to hack an account. Eric has made browsing much less secure.
The intended result is to bring the security issue to people's awareness, which he has done. But the result should have been to increase security. That will only happen if the the change in required Tools is balanced by a decrease in Opportunity (free wifi becoming simple password wifi at a minimum).
I doubt that will happen. Releasing Firesheep was a mistake.
Disgusting. Sowing fear is not education.
You are not a hero. You have not done anybody a favor. You did this for the same perennial excuse of "spreading awareness" trotted out by any number of noxious social irritants and did so not by the means most efficient or effective, but the means readily available and most likely to satisfy your urge to feel superior to your fellow man.
You may actually care about the problem and take it seriously in other circumstances, but that is not reflected here. There is no security problem for which "exploit the problem to harass strangers in coffee shops" is the solution.
You should probably replace "harass" with "inform" in your comment. It would be more accurate, and less emotive.
Suppose you leave it be for the day. You've got more important things to do than blindly react to mysterious messages, haven't you? So day slips into night and before long it's morning again. You find another note:"Really wasn't kidding about the bars thing. I won't send another message after this -- it's up to you to take your security seriously." Same as before, nothing obviously missing, all windows and doors closed and locked. You have no idea who this is or why they are doing this. You have no idea if you can trust them.
How do you react?
That sounds exactly like a distinction to me. A fireman would break into a house to save a child. A burglar would break into a house to steal valuables. One intends harm, the other doesn't.
> did so not by the means most efficient or effective, but the means readily available and most likely to satisfy your urge to feel superior to your fellow man.
There's no such thing as true altruism. Why he did it isn't relevant. People feel good about doing good deeds. Sure, they say "I want to help people," but they really mean something more along the lines of "I want to feel good about myself."
Further, why would it be necessary for him to choose the most effective or efficient means? He owes these people nothing.
> There is no security problem for which "exploit the problem to harass strangers in coffee shops" is the solution.
Maybe not the best or even a good solution, but it's certainly still one. ;)
...but then...
Why he did it isn't relevant.
I am at least as uncertain as to what your position is as you are. Also...
He owes these people nothing.
Nothing, of course, except the common courtesy of not violating their privacy. Yes, even in New York.
2) Install Tunnelier on your laptop, flip to the Services tab and enable SOCKS at 127.0.0.1 and port 1337. Login in to your home computer.
3) Change Chrome target to chrome.exe --proxy-server=socks5://127.0.0.1:1337
Mostly used for obtrusive proxies though it will make you as secure as you are at your home network..
I did this to my home router and had it all working in about 30 minutes. Most of that time was trying to figure out how to get putty to open a tunnel (and registering/configuring a No-IP dynamic dns account).
Having identified the vulnerabilities of WEP encryption on wireless networks, shouldn't it be that device manufacturers of wireless routers take away WEP encryption as an option but instead focus on a more secure method of connection? Of course this may have some downside to it, but unless your ordinary Joe and Jane realize the upsides of having secure connection to the web, they may see this as a discomfort.
Of course there's still a bigger problem with arp spoofing and other attacks, which in the long term will need to be solved. Maybe with something like DNSSEC DKI.
will see who wins in the court :http://www.wired.com/threatlevel/2010/06/packet-sniffing-law...
see also : http://blogs.forbes.com/kashmirhill/2010/10/28/firesheep-use...
(1) A person is guilty of an offence if—
(a) he causes a computer to perform any function with intent to secure access to
any program or data held in any computer, or to enable any such access to be
secured;
(b) the access he intends to secure, or to enable to be secured, is unauthorised;
and
(c) he knows at the time when he causes the computer to perform the function that
that is the case.
(2) The intent a person has to have to commit an offence under this section need
not be directed at—
(a) any particular program or data;
(b) a program or data of any particular kind; or
(c) a program or data held in any particular computer.
I think passive sniffing may also be illegal in the UK according to RIPA [1] as it is unauthorised interception of public telecommunications.[1]: http://www.legislation.gov.uk/ukpga/2000/23/part/I/chapter/I...
So he's basically just blogged about committing a crime. I wonder what would happen if one if his "victims" read this and then contacted the police. I bet Facebook has enough information logged about which accounts were accessing Facebook from that IP at the time, and which of them received his messages.
Github doesn't have logs of who downloaded Firesheep and used it to sniff somebodys traffic without their permission.
This behavior extends beyond Internet usage. I (and probably most of you reading this) hand my credit/debit cards over to waiters several times per month knowing full well they could jot down enough information while out of my sight to make illegal charges on that card (if not do far worse via more elaborate identity theft schemes). Risky? Yes, but the extreme convenience outweighs the potential pain due to the low chance of actually being one of the people that gets exploited in this way, and thus it is with open hotspots and most Internet sites.
I use a credit card because it's safer and offers me options - someone snarfing the number would be a nuisance, because I'd need a new card, but that's it.
Let's please not forget (Sight.. I know - everyone already has) that charge-cards were pushed onto the market as a safe, convenient alternative to using cash - not a walking liability - don't let the issuers turn them into one on us.
As to the analogy - it's quite different. I'm very security conscious, and I generally don't do certain types of activity on uncontrolled or unknown networks (banking - home or somewhere else safe - but facebook at starbucks, okay)
IT's not just a problem with open hotspots, it's with any network you are on, anywhere - an open hotspot is just the easiest place for someone to try this on. An employee at an ISP could snarf data from millions of users easily...
Seems like the ones who read the message must have made a quick cost-benefit analysis in their head of viewing facebook insecurely right now versus not accessing facebook at all - and viewing it right this minute no matter how insecure still won!
dan·ger·ous
[deyn-jer-uhs, deynj-ruhs]
–adjective
1. full of danger or risk; causing danger; perilous; risky; hazardous; unsafe.
2. able or likely to cause physical injury
Who's out of touch here? We're all making such a huge deal about this with very little reason. The websites that truly need SSL (banking, purchasing, etc.) use it. People have real dangers to worry about; why should they care if someone can pretend to be them on a couple social websites that they just joined in the last year or two?We all know that 90% of the users tend to have one passwort for everything. That password usually works for any SSL secured service, too ;-)
Meaning you go to a cafe and the blackboard tells you that today's WPA2 password is "greenbeans". Knowing this does it provide the ability to sniff or abuse other users sessions on this WAP?
Honestly don't know this and can't find a clear answer about it.
"As long as the universally supported WPA encryption protocol is used,
each individual user receives their own private “session key” that absolutely
prevents eavesdropping between users, even through they are all using the
same WiFi password."
from: http://steve.grc.com/2010/10/28/instant-hotspot-protection-f...Now, sure, this attacks costs me $10 for the wifi card and it's not as fast as connecting to Starbucks' wifi and opening a Firefox tab... but you will still get a lot of data.
Link-level encryption is not the same as session encryption. For your link to be secure, you need link-level encryption. For your session to be secure, you need session-level encryption. It's that simple. Facebook is a session, not a link, so Facebook needs SSL.
There is simply no other workaround.
(And oh yeah, you need to authenticate who you are talking to. The access point asks you for a password to prove that you are allowed to talk to it. But you don't ask it for a password to prove that it is allowed to talk to you. Connecting to an access point is like giving your credit card information to the call that starts like, "Is this jrockway? There's a problem with your credit card...". They know who you are, but you have no idea whether they are actually your bank.)
Please HN: Stop getting outraged by stuff that doesn't really matter. You're turning into Reddit, and just like them, you will have forgotten all about this by next week, and be on to the next topic you need to be outraged about. It's depressing. Angelgate? No one cares any more. No one should have cared in the first place.
Seriously. This summer has been depressing to watch HN go down the pan.