musiform

  1. Search
  2. About
  3. Subscribe
  4. Archive
  5. Random

musiform

rambling musings from a dislocated intellect, perceiving itself as a lazy hacker, musician, philosopher, sociologist and at all times a lover of all things addictive. ~i shall rule the world with a rimshot and a protein shake!~

Newer
Older
  • Facebook FAIL

    I’m sitting at a coffee shop in Mission district in San Francisco and experimenting with Firesheep. I knew about the “cookie fail” for quite some time now, but never took the time to exploit it (unless we’re talking about my roommates) and luckily someone did the job for me.

    now, the Firesheep exploit itself if a huge fail on behalf of many a social networks, but Facebook takes their fail to a whole new level:

    the obvious thing to offer your users (at least on demand) is https. and you can do that most of the time at the majority of the pages. now go and try this at Facebook. seriously, go and try. it works! now go click on any link. it doesn’t matter which one. just click.

    it’s magic! you’re no longer using a secure protocol. not only does Facebook not default to https, even when you demand it, The Social Network decides you’re better off browsing their way.

    FAIL.

    m

    Tagged: facebook social fail firefly exploit grayhat

    Posted on October 25, 2010 with 2 notes

    1. l1fescape liked this
    2. yowadup liked this
    3. musiform posted this
  • staff

Field Notes Theme. Designed by Manasto Jones. Powered by Tumblr.