9 comments

[ 2.5 ms ] story [ 31.0 ms ] thread
This is from 2010.

Facebook uses HTTPS for everything now, right?

Yup. I was confused as to why Firesheep was resurfacing today.
(comment deleted)
Correct, but at the time of this release many websites (including GMail and Facebook I believe) did not and were vulnerable to Firesheep. The title of this post should be updated to reflect the 2010 posting.
I believe so.

I still remember being in the local uni's lab over wifi and firesheep had ~80 entries for facebook/gmail/etc. Click a profile and hijack their session.

Are we just here for the memories?
Astonishing to think about the lack of encryption in big services like Facebook 5 years ago.
We should be thankful for Firesheep.

It was brilliantly simple, spread fast, and forced the major players to adopt HTTPS rather quickly.

For the first time I've noticed the "past" option under the title (between flag and web).