Skip to content

Comment on Firesheep, a day laterparent

Comments

It's all been discussed by WHATWG/W3C and the conclusion was that cookies have too large momentum, Digest is not secure enough, and everyone should be using HTTPS.

http://www.w3.org/html/wg/tracker/issues/13?changelog

http://lists.whatwg.org/htdig.cgi/whatwg-whatwg.org/2008-Nov...

Digest is vulnerable to MITM attacks. It's only secure against passive sniffing, but if you can sniff, you usually can also modify response, spoof DNS/ARP/base station. If everyone switched to Digest, it would be only a matter of time when someone writes Digest-stripping Firesheep2.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.