How to protect against Firesheep attacks

Experts suggest defensive measures to ward off Firefox add-on's hijacking of Facebook, Twitter sessions

By Gregg Keizer, Computerworld |  Security, Facebook, Firefox 2 comments

Security experts today suggested ways Firefox users can protect themselves against Firesheep, the new browser add-on that lets amateurs hijack users' access to Facebook, Twitter and other popular services.

Firesheep adds a sidebar to Mozilla's Firefox browser that shows when anyone on an open network -- such as a coffee shop's Wi-Fi network -- visits an insecure site.

A simple double-click gives a hacker instant access to logged-on sites ranging from Twitter and Facebook to bit.ly and Flickr.

Since researcher Eric Butler released Firesheep on Sunday, the add-on has been downloaded nearly 220,000 times.

"I was in a Peet's Coffee today, and someone was using Firesheep," said Andrew Storms, director of security operations at San Francisco-based nCircle Security. "There were only 10 people in there, and one was using it!"

But users aren't defenseless, Storms and several other experts maintained.

One way they can protect themselves against rogue Firesheep users, experts said on Tuesday, is to avoid public Wi-Fi networks that aren't encrypted and available only with a password.

However, Ian Gallagher, a senior security engineer with Security Innovation, argued that tosses out the baby with the bathwater. Gallagher is one of the two researchers who debuted Firesheep last weekend at a San Diego conference.

"While open Wi-Fi is the prime proving ground for Firesheep, it's not the problem," Gallagher said in a blog post earlier on Tuesday. "This isn't a vulnerability in Wi-Fi, it's the lack of security from the sites you're using."

Free, open Wi-Fi is not only taken for granted by many, but it's not the problem. There are plenty of low-risk activities one can do on the Internet at a public hotspot, including reading news or looking up the address of a nearby eatery.

So if Wi-Fi stays, what's a user to do?

The best defense, said Chet Wisniewski, a senior security adviser at antivirus vendor Sophos, is to use a VPN (virtual private network) when connecting to public Wi-Fi networks at an airport or coffee shop, for example.

While many business workers use a VPN to connect to their office network while they're on the road, consumers typically lack that secure "tunnel" to the Internet.

"But there are some VPN services that you can subscribe to for $5 to $10 month that will prevent someone running Firesheep from 'sidejacking' your sessions," Wisniewski said.

A VPN encrypts all traffic between a computer -- a laptop at the airport gate, for instance -- and the Internet in general, including the sites vulnerable to Firesheep hijacking. "It's as good a solution as there is," Wisniewski said, "and no different, really, than using encrypted Wi-Fi."

One provider, Strong VPN , prices its service starting at $7 per month or $55 per year.

Gallagher, however, warned that a VPN isn't a total solution. "That's just pushing the problem to that VPN or SSH endpoint," he said. "Your traffic will then leave that server just as it would when it was leaving your laptop, so anyone running Firesheep or other tools could access your data in the same way."

"A blind suggestion of 'use a VPN' doesn't really solve the problem and may just provide a false sense of security," he said.

Strong VPN disagreed. "Our servers are in a secure datacenter, so no one's going to be able to 'sniff' the traffic coming in or going out," a company spokesman countered. "All the traffic from, for example, your laptop in San Francisco, is encrypted when it goes to one of our U.S. servers."

Storms echoed Strong VPN's assertion. "I can see [Gallagher's point], that a VPN doesn't solve the root problem, which is on the service end," he said. "But although it's true that the traffic would be clear text when it leaves the VPN server for the site, it's very unlikely that someone would snoop that traffic."

Sean Sullivan, a security advisor with F-Secure, recommended Comodo's TrustConnect as "a VPN in all but name only." Comodo, a rival of F-Secure, sells the service for $7 per month or $50 annually.


Originally published on Computerworld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

White Paper

Secure Mobile Applications

This white paper provides a detailed description of Good Technology's Security and Architecture. It provides an overview of the changing landscape of mobile technologies within the enterprise and enumerates the key mobile device challenges faced by enterprise and government organizations.

White Paper

BYOD Policy Considerations

As companies embrace the usage of individual liable mobile devices to access corporate applications and data, Good Technology is often asked for guidance on creating individual liable usage policies. This document provides guidance on the questions to ask when establishing these policies.

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

See more White Papers | Webcasts

Ask a question

Ask a Question