EFF Tool Offers New Protection Against ‘Firesheep’

The Electronic Frontier Foundation (EFF) has launched a new version of HTTPS Everywhere, a security tool that offers enhanced protection for Firefox browser users against “Firesheep” and other exploits of webpage security flaws.

HTTPS secures web browsing by encrypting both requests from your browser to websites and the resulting pages that are displayed. Without HTTPS, your online reading habits and activities are vulnerable to eavesdropping, and your accounts are vulnerable to hijacking.

Unfortunately, while many sites on the web offer some limited support for HTTPS, it is often difficult to use. Websites may default to using the unencrypted, and therefore vulnerable, HTTP protocol or may fill HTTPS pages with insecure HTTP references. EFF’s HTTPS Everywhere tool uses carefully crafted rules to switch sites from HTTP to HTTPS.

This new version of HTTPS Everywhere responds to growing concerns about website vulnerability in the wake of Firesheep, an attack tool that could enable an eavesdropper on a network to take over another user’s web accounts — on social networking sites or webmail systems, for example — if the browser’s connection to the web application either does not use cryptography or does not use it thoroughly enough. Firesheep, which was released in October as a demonstration of a vulnerability that computer security experts have known about for years, sparked a flurry of media attention.

“These new enhancements make HTTPS Everywhere much more effective in thwarting an attack from Firesheep or a similar tool,” said EFF Senior Staff Technologist Peter Eckersley. “It will go a long way towards protecting your Facebook, Twitter, or Hotmail accounts from Firesheep hacks. And, like previous releases, it shields your Google searches from eavesdroppers and safeguards your payments made through PayPal.”

Other sites targeted by Firesheep that now receive protection from HTTPS Everywhere include Bit.ly, Cisco, Dropbox, Evernote, and GitHub. In addition to the HTTPS Everywhere update, EFF also released a guide to help website operators implement HTTPS properly.

“Firesheep works because many websites fail to use HTTPS,” said EFF Technology Director Chris Palmer. “Our hope is to make it easier for web applications to do the right thing by their users and keep us all safer from identity theft, security threats, viruses, and other bad things that can happen through insecure HTTP. Taking a little bit of care to protect your users is a reasonable thing for web application providers to do and is a good thing for users to demand.”

The first beta of HTTPS Everywhere was released last June. Since then, the tool has been downloaded more than half a million times.

To download HTTPS Everywhere for Firefox:
https://www.eff.org/https-everywhere

For more on implementing HTTPS in websites:
https://www.eff.org/pages/how-deploy-https-correctly

This article was originally published by the Electronic Frontier Foundation.

Related Posts

Should Truecrypt be audited? Truecrypt is a cross-platform, free disk encryption software for Windows and Unix-like operating systems. It is generally considered a good disk encry...
Galician government launches a promotion campaign on open source The government of Galicia, one of Spain's autonomous regions, wants to boost the use of free and open source software by its public administrations an...
Knock: A Linux kernel patch for NAT-compatible, stealthy port knocking A Linux kernel patch that "implements a new NAT-compatible, TCP option for stealthy port knocking with a few new twists for improved security" has bee...
Project Chess spied on you long before Microsoft acquired Skype Long before Edward Snowden told us about a govt privacy-abusing spy operation called PRISM or Prism, Skype had its own collaborative project with the ...
Cases Against Thousands of Alleged BitTorrent Pirates Dismissed Last year, Larry Flynt Publications filed lawsuits against several thousand “John Does” the company accused of illegally sharing its movie “This Ain’t...
One more reason to not use Skype for Linux Even though Skype for Linux is unlike most applications available on any Linux installation, that is, it is a proprietary application, it has long bee...

We Recommend These Vendors and Free Offers

ContainerizeThis 2016 is a free, 2-day conference for all things containers and big data. Featured, will be presentations and free, hands-on workshops. Learn more at ContainerizeThis.com

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).

Want to become an expert ethical hacker and penetration tester? Request your free video training course of Online Penetration Testing and Ethical Hacking

Whether you're new to Linux or are a Linux guru, you can learn a lot more about the Linux kernel by requesting your free ebook of Linux Kernel In A Nutshell.


One Comment

  1. Pingback: Tweets that mention EFF Tool Offers New Protection Against ‘Firesheep’ -- Topsy.com

Leave a Comment

Your email address will not be published. Required fields are marked *

*