Correct, but at the time of this release many websites (including GMail and Facebook I believe) did not and were vulnerable to Firesheep. The title of this post should be updated to reflect the 2010 posting.
I still remember being in the local uni's lab over wifi and firesheep had ~80 entries for facebook/gmail/etc. Click a profile and hijack their session.
9 comments
[ 2.5 ms ] story [ 31.0 ms ] threadFacebook uses HTTPS for everything now, right?
I still remember being in the local uni's lab over wifi and firesheep had ~80 entries for facebook/gmail/etc. Click a profile and hijack their session.
It was brilliantly simple, spread fast, and forced the major players to adopt HTTPS rather quickly.