More danger lurking for WebUsers
-
RealBlackStuff
- Admin
- Posts: 17512
- Joined: Mon Sep 18, 2006 5:17 am
- Location: Mt. Cobb, PA USA
- Contact:
More danger lurking for WebUsers
Firesheep has made it possible for any moron to raid your Web use, but there are ways you can stop it.
Here are a few of them.
Here are a few of them.
Lovely day for a Guinness! (The Real Black Stuff)
Check out The Boardroom for Parts, Mods and Other Services.
Check out The Boardroom for Parts, Mods and Other Services.
Re: More danger lurking for WebUsers
Sadly, not on this forum, since it doesn't support SSL.
Is there anything that can be done about that?
Is there anything that can be done about that?
Need help with Linux or FreeBSD? Catch me on IRC: I'm ThinkRob on FreeNode and EFnet.
Code: Select all
Current laptop: X1 Carbon 3
Current workstation: none-
Woodenspoon
- Freshman Member
- Posts: 69
- Joined: Sat Oct 30, 2010 1:07 am
- Location: San Jose, Calif. USA
Re: More danger lurking for WebUsers
yea exactly, this site like many more, can no longer be used on open or wep wifi:(
Re: More danger lurking for WebUsers
It's been discussed amongst the staff and the consensus is that SSL is a dog and it would slow down the site. In addition to this most other forums do not run SSL for that very reason. Also, if a member gets a forum password lifted and it is discovered that someone else is using it, just ask an Admin to reset it, end of story. It's not the end of the world. Oh, and Chicken Little, the sky is not falling. (Insert any other cute but obnoxious saying here) 
Re: More danger lurking for WebUsers
I'm not sure that the consensus reached was correct.Harryc wrote:It's been discussed amongst the staff and the consensus is that SSL is a dog and it would slow down the site. In addition to this most other forums do not run SSL for that very reason.
According to one of Google's engineers:
I think that's pretty clear.In January this year (2010), Gmail switched to using HTTPS for everything by default. Previously it had been introduced as an option, but now all of our users use HTTPS to secure their email between their browsers and Google, all the time. In order to do this we had to deploy no additional machines and no special hardware. On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead. Many people believe that SSL takes a lot of CPU time and we hope the above numbers (public for the first time) will help to dispel that.
If you stop reading now you only need to remember one thing: SSL/TLS is not computationally expensive any more.
Need help with Linux or FreeBSD? Catch me on IRC: I'm ThinkRob on FreeNode and EFnet.
Code: Select all
Current laptop: X1 Carbon 3
Current workstation: noneRe: More danger lurking for WebUsers
The site owner says no SSL, and he pays the bills. I think that's pretty clear as well.ThinkRob wrote: I think that's pretty clear.
Re: More danger lurking for WebUsers
Fair enough.Harryc wrote: The site owner says no SSL, and he pays the bills. I think that's pretty clear as well.
It's no problem for me, as I *never* re-use passwords, and since everything we post is public there's probably not much harm even if the traffic were to be intercepted.
Need help with Linux or FreeBSD? Catch me on IRC: I'm ThinkRob on FreeNode and EFnet.
Code: Select all
Current laptop: X1 Carbon 3
Current workstation: none-
ajkula66
- SuperUserGeorge

- Posts: 15739
- Joined: Sun Feb 25, 2007 11:28 am
- Location: Brodheadsville, Pennsylvania
Re: More danger lurking for WebUsers
Woodenspoon wrote:
Don't know about the "open" but it can most certainly be used with WEP. Doing it right now.yea exactly, this site like many more, can no longer be used on open or wep wifi:(
...Knowledge is a deadly friend when no one sets the rules...(King Crimson)
Cheers,
George (your grouchy retired FlexView farmer)
AARP club members:A31p, T43pSF
Abused daily: T61p
PMs requesting personal tech support will be ignored.
Cheers,
George (your grouchy retired FlexView farmer)
AARP club members:A31p, T43pSF
Abused daily: T61p
PMs requesting personal tech support will be ignored.
-
mediasponge
- Junior Member

- Posts: 286
- Joined: Mon Oct 22, 2007 5:57 pm
- Location: Milpitas, CA
Re: More danger lurking for WebUsers
Firesheep is a problem on OPEN WiFi sites, like Starbucks. As long as you are using some flavor of WEP/WPA/WPA2/ etc. you are probably pretty safe at home. You can also set your router not to broadcast the SSID. That means all your home wireless devices need to have the SSID and security info entered manually, but that is minimal effort. Most systems outside your house won't even see your WAP because the SSID broadcast is silent. This could turn into a market killer for public WiFi, though.
OTOH, some coffee shops are starting to buck the trend of having unlimited WiFi, because people will sit there for hours nursing one cup of coffee just to use the WiFi. They are either turning it off, or setting limits on it. There's a particular coffee shop in Palo Alto I used to go to that was impossible to get a table in because of all the parked laptops.
OTOH, some coffee shops are starting to buck the trend of having unlimited WiFi, because people will sit there for hours nursing one cup of coffee just to use the WiFi. They are either turning it off, or setting limits on it. There's a particular coffee shop in Palo Alto I used to go to that was impossible to get a table in because of all the parked laptops.
A31p: 2653-N5U, 1.7GHz, 1.5GB, 320GB (upgr), CDRW/DVD, Win XP-Pro SP3
X41: 2528-5FU, 1.5 Ghz, 2GB, 40GB, Win XP-Pro SP3
X41: 2528-5FU, 1.5 Ghz, 2GB, 40GB, Win XP-Pro SP3
Re: More danger lurking for WebUsers
Two things:mediasponge wrote:As long as you are using some flavor of WEP/WPA/WPA2/ etc. you are probably pretty safe at home. You can also set your router not to broadcast the SSID. That means all your home wireless devices need to have the SSID and security info entered manually, but that is minimal effort. Most systems outside your house won't even see your WAP because the SSID broadcast is silent.
1) WEP is so fundamentally weak that it's trivial to break. It's right up there with wet cardboard wrapped around your AP in terms of how much protection it affords your network. WPA2+AES is the only real way to do wireless security.
2) "Hidden" SSIDs are not a security measure. It's easy to find so-called "hidden" networks, and every piece of stumbling/wardriving software that I've ever come across will do so automatically. There's no reason to do this, as it causes problems with a number of devices yet provides no protection whatsoever.
Need help with Linux or FreeBSD? Catch me on IRC: I'm ThinkRob on FreeNode and EFnet.
Code: Select all
Current laptop: X1 Carbon 3
Current workstation: none-
- Similar Topics
- Replies
- Views
- Last post
-
-
FREE: A box of R61e/i parts - and more
by wujstefan » Fri Jan 20, 2017 5:01 pm » in Marketplace - Forum Members only - 7 Replies
- 689 Views
-
Last post by wujstefan
Fri Feb 17, 2017 7:30 am
-
-
-
Thank you guys! I wanna get to know you more!
by Whitieiii » Sun Jan 22, 2017 6:52 am » in Off-Topic Stuff - 2 Replies
- 566 Views
-
Last post by TPFanatic
Sun Jan 22, 2017 11:51 pm
-
-
-
Undervolting CPU in Windows 8 / 10 ? RMclock doesn't work any more.
by zoltan87 » Fri Feb 17, 2017 10:26 am » in ThinkPad T6x Series - 6 Replies
- 2489 Views
-
Last post by lab
Sat Mar 18, 2017 11:55 am
-
-
- 6 Replies
- 1332 Views
-
Last post by kfzhu1229
Mon Mar 06, 2017 6:08 pm
Who is online
Users browsing this forum: No registered users and 1 guest




