ohryan.ca

A Web Developer in Winnipeg

  • privacy
  • Facebook Security Still Lacking

    March 10, 2011
    in Websites

    In October I blogged about a Firesheep, a Firefox plugin that highlights the inherent vulnerabilities in the way that Facebook and other websites handle sessions. TL;DR – Install the extension and with a click of a button you can capture un-encrypted Facebook sessions of any user using a WiFi network you’re connected to (read the full post for all the details). For research purposes, when a friend of mine was at Pearson a few months ago he fired up Firesheep and instantly had access to several dozen Facebook accounts.

    This is a bad, very bad.

    To combat this security hole, Facebook enabled secure HTTP connections in January. Enabling this feature renders Firesheep useless.

    Unfortunately, Facebook’s implementation has one serious flaw. When you use (almost) any Facebook app you’re required to switch back to un-encrypted HTTP mode! You’re presented with this dialog:

    The wording used in the dialog may make you think the setting is temporary while you’re using the app. I don’t know if it’s designed that way or if it’s just poorly worded. But in fact clicking “continue” will permanently disable your HTTPS preference!

    Sad.

    I suspect there’s probably a technical reason for this requirement, something about the way that apps include data from external domains. I haven’t looked into it. Facebook really needs to address this.

    My suggestion would be to disable some sort of alert when navigate away from the app, which a one click solution for re-enabling HTTPS.


  • Canadian Tech Roundup 15: That flash just froze my Chrome!

    March 9, 2011
    in Canadian Tech News

    [podcast]http://dl.dropbox.com/u/480185/podcasts/CTREP15.mp3[/podcast]

    Show notes are now available on the new CanadianTechRoundup.com!

    iTunes Link

    RSS


  • Canadian Tech Roundup 14: The one where we talk about iPad2

    March 2, 2011
    in Canadian Tech News, Podcasts
    • iPad 2 is out!
    • RIM may have missed window of opportunity
    • Facebook Quietly Launches ‘Deal’ in Canada
    • Facebook Photo Seizure
    • A tonne of new content on Netflix
    • Tony Clement defends his criticism of the CRTC UBB decision
    • Courts back TV broadcasters
    • Digital Transition is August 31, 2011!

    iTunes Link

    RSS

    [podcast]http://dl.dropbox.com/u/480185/podcasts/CTREP14.mp3[/podcast]


←Previous Page Next Page→

Hi.

Hello, my name is Ryan! I’m a web developer in Winnipeg, Canada. I’ve been documenting my random thoughts and occasional bits of interesting code here since 2005. Twitter. Github. Instagram. Mastodon.

Recent Posts

  • Buy Canadian VegansApril 30, 2025
  • What is a “Note”?April 28, 2025
  • PortlandDecember 20, 2024
  • Thom Bargen, TuxedoDecember 10, 2024
  • VA CaféDecember 4, 2024
  • The Forks x Fools & HorsesNovember 27, 2024

Designed with WordPress