The code injected to steal passwords in Tunisia
blog.jgc.org
blog.jgc.org
The only real protection here is to go full SSL and not forget to set the SSL only flag on session cookies. Even then, you only have to wait till Tunisia buys a forged certificate for Facebook.
When it's your your password on the line (and possibly your ass in jail) data security is more than aggregate statistics.
I don't use FB, but someone on Slashdot was saying it likes to reply with every link going to http anyway. Based on my experience with Twitter and other sites, this sounds very plausible.
(and after that, all the government needs to do is require an ssl signing authority to be used by all tunisian banks, and it's back in!)
By very easy I mean it requires almost no talent.
Long time back (even)I wrote a script to grab password and username using DOM and JavaScript.
But this doesn't should not be true for "remember me" cookies. Those just need some identifier.
At any rate, you still need "talent": to know where the person is, when they're going for coffee, ability to access their machine without bystanders asking questions, etc.
If you have access to a Windows machine, visit http://bit.ly/eWYRbA in IE then check your personal cert store for Agence Nationale de Certification Electronique
Isn't this rather huge news? Why did they do this sort of downgrading hackery when they could do a more elegant (and slightly more transparent) man in the middle?
B) Probably a lot of users prefer Mozilla, though it may defer to the system store on Windows anyway, I'm not sure.
C) For the same reasons it's a pain for FB to use https everywhere, it's a pain for Tunisia to set up SSL interception on their outbound connections. There are certainly off-the-shelf boxes which can do it though.
This attack only worked because the attacker could subvert the same-domain origin policy, by posting usernames and passwords to a page at the facebook.com domain (but which was routed to an attacker's host at a lower level.) The security failure happened at a lower layer than where Javascript security would be responsible.
Gmail always opens with SSL for me. Didn't Google make this the default after Chinagate?
sorry if i'm being ignorant