<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://www.osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/24003/Firesheep_Countermeasure_Tool_BlackSheep</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2013, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Wed, 22 May 2013 12:36:58 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Comment by satan666</title>
			<link>http://www.osnews.com/thread?449086</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449086</guid>
			<description>Then they will create anther extension called PinkSheep that will detect BlackSheep and will circumvent it.<br />
What we really need is a wolf.</description>
			<pubDate>Mon, 08 Nov 2010 17:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (satan666)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by satan666</title>
			<link>http://www.osnews.com/thread?449096</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449096</guid>
			<description>A wolf in sheepâs clothing, or the kind that dresses up in womenâs clothing?</description>
			<pubDate>Mon, 08 Nov 2010 17:36:00 GMT</pubDate>
			<author>donotreply@osnews.com (Kroc)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>A slow acting alarm as countermeasure?</title>
			<link>http://www.osnews.com/thread?449097</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449097</guid>
			<description>It only sends the fake stuff every 5 minutes so could be countered by adding a window to firesheep.  <br />
<br />
It also doesn't stop a hijacked session, so you get hijacked and see later that firesheep is running somewhere - now you have to logout in the interim and hope nothing bad happened.<br />
<br />
If they aren't using IP verification, I can use a VPN tunnel for the transmissions and blacksheep would not see them.</description>
			<pubDate>Mon, 08 Nov 2010 17:40:00 GMT</pubDate>
			<author>donotreply@osnews.com (tomz)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Yeah, cuz that makes you safe...</title>
			<link>http://www.osnews.com/thread?449110</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449110</guid>
			<description>What moron thinks that because they have a plugin in their browser that detects someone else using a plugin in their browser, that somehow they're no longer leaking sensitive data over a public network.<br />
<br />
Treating the symptom doesn't fix the problem... but I suppose it allows people to sleep at night in ignorance.</description>
			<pubDate>Mon, 08 Nov 2010 18:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: You mean...</title>
			<link>http://www.osnews.com/thread?449115</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449115</guid>
			<description>The internet is not all on my hard drive? You know the one on my desk?<br />
<br />
Yeah, that big black and tan box that has my automatic pullout cup holder!<br />
<br />
Where did my refrigerator magnet get to that holds my backup 8&quot; floppy disk to my steel fire proof filing cabinet?</description>
			<pubDate>Mon, 08 Nov 2010 19:19:00 GMT</pubDate>
			<author>donotreply@osnews.com (gfolkert)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Required SSL</title>
			<link>http://www.osnews.com/thread?449121</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449121</guid>
			<description>In today's world, I think any site that handles any personal information (other than name, and timezone) should require at least simple SSL encryption.<br />
 <br />
 Sites using phpbb, Wordpress, etc since they ususally only store name, IP, and timezone info can be exempt.<br />
 <br />
 These site should be forced IMO. (at least parts of the site once you are logged in) <br />
 Shopping sites (Amazon.com), WebMail (Hotmail, Google), Banks/Financial, social sites (Facebook).<br />
<br />
Unfortunately even using Facebook Pro Secure is iffy, sometimes it still uses normal http.<br />
<a href="http://userscripts.org/scripts/show/49079Edited" rel="nofollow">http://userscripts.org/scripts/show/49079Edited</a> 2010-11-08 20:13 UTC</description>
			<pubDate>Mon, 08 Nov 2010 20:11:00 GMT</pubDate>
			<author>donotreply@osnews.com (robojerk)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: You mean...</title>
			<link>http://www.osnews.com/thread?449123</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449123</guid>
			<description>You can download the Internet here: <a href="http://thepiratebay.org/torrent/5923737/Geocities_-_The_Torrent" rel="nofollow">http://thepiratebay.org/torrent/5923737/Geocities_-_The_Torrent</a> It's just 640 GB!</description>
			<pubDate>Mon, 08 Nov 2010 20:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (Kroc)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Required SSL</title>
			<link>http://www.osnews.com/thread?449124</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449124</guid>
			<description>The reason so few use SSL on their sites is the brain-dead stupid business model of SSL certs. Tying identity to encryption is a misdirection. Encryption should not require identity. SSL certs are expensive and simply don't prove anything useful.<br />
<br />
Developers are not the problem. It's the CAs and the browser vendors. Producing scary errors on self-signed certs protects absolutely bloody nobody and locks password protection to the SSL racket.</description>
			<pubDate>Mon, 08 Nov 2010 20:57:00 GMT</pubDate>
			<author>donotreply@osnews.com (Kroc)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: You mean...</title>
			<link>http://www.osnews.com/thread?449142</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449142</guid>
			<description>Heh, reminds me of this, click to see how OSNews would look if it had been hosted on geocities:<br />
<br />
<a href="http://wonder-tonic.com/geocitiesizer/content.php?theme=2&amp;music=6&amp;url=www.osnews.com" rel="nofollow">http://wonder-tonic.com/geocitiesizer/content.php?theme=2&amp;music...</a></description>
			<pubDate>Mon, 08 Nov 2010 22:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (Valhalla)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Required SSL</title>
			<link>http://www.osnews.com/thread?449145</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449145</guid>
			<description><div class="cquote">Developers are not the problem. It's the CAs and the browser vendors. Producing scary errors on self-signed certs protects absolutely bloody nobody and locks password protection to the SSL racket. </div><br />
 <br />
 I'll agree that the entire concept of SSL certificate/encryption, with CA's and high prices, is indeed a broken system and a scam to some extent - but the &quot;scary errors&quot; browsers display have a valid purpose.<br />
 <br />
 Given how SSL works, and how users expect it to behave, if you can't verify the certificate you're using belongs to the site you are surfing, you can't know that the encryption keys you're sharing with them haven't been tampered with by a middleman. On a public wifi network, this can be a real threat...<br />
 <br />
 In any case - if I encounter a site with an &quot;untrusted&quot; certificate, and I don't figure it matters for that particular site (read: I'm not revealing personal information to the site), then I'll just accept it anyway.<br />
 <br />
 These days, you can get a free Class 1 cert (unrevokable, single domain)... or a cheap Class 2 verification wildcard cert for like $25/year ($50 for two years) from StartCom:<br />
 <br />
 <a href="http://www.startssl.com/" rel="nofollow">http://www.startssl.com/</a><br />
 <br />
 All major browsers accept these... so it's hard to complain about it much.Edited 2010-11-08 22:46 UTC</description>
			<pubDate>Mon, 08 Nov 2010 22:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Required SSL</title>
			<link>http://www.osnews.com/thread?449150</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?449150</guid>
			<description><div class="cquote">In today's world, I think any site that handles any personal information (other than name, and timezone) should require at least simple SSL encryption.<br />
 <br />
 Sites using phpbb, Wordpress, etc since they ususally only store name, IP, and timezone info can be exempt.<br />
 <br />
 These site should be forced IMO. (at least parts of the site once you are logged in) <br />
 Shopping sites (Amazon.com), WebMail (Hotmail, Google), Banks/Financial, social sites (Facebook). </div><br />
<br />
One of the reasons I've heard cited is that encrypting all communication with SSL incurs higher server load (and client for that matter - those poor cell phones have to encrypt/decrypt every request to the server).<br />
<br />
Another thing it also limits is the ability to easily load balance cache-able resources - for example, a trick that many sites use is to farm their image or .js hosting out to other load balanced servers on different domains - which would require a connection to a different server, which creates a complicated security situation. I already see this often while using gmail https - my browser is constantly warning me that there are &quot;some unsecured elements on the page&quot;...<br />
<br />
There are some companies that take this stuff seriously... Google for example even gives you a way to search on a public network without anyone else sniffing your search terms (except Google of course... but hey, they already know everything about you):<br />
<br />
<a href="https://encrypted.google.com/" rel="nofollow">https://encrypted.google.com/</a></description>
			<pubDate>Mon, 08 Nov 2010 23:11:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
