{"id":83,"date":"2011-03-07T01:45:31","date_gmt":"2011-03-06T15:45:31","guid":{"rendered":"http:\/\/www.ajwesley.com\/flipangle\/?p=83"},"modified":"2011-03-07T01:58:03","modified_gmt":"2011-03-06T15:58:03","slug":"fb-security-yawn-firesheep-hmmm-sounds-interesting-and-the-opt-in-option-for-https-on-facebook-yawn","status":"publish","type":"post","link":"https:\/\/www.flipangle.org\/?p=83","title":{"rendered":"FB security *yawn* &#8211; Firesheep *hmmm sounds interesting*  &#8211; and the opt in option for https on Facebook *yawn*"},"content":{"rendered":"<p>Me doing a security type post, here&#8217;s a first&#8230;Some of you will repost this, others won&#8217;t. No scaremongering here. Realistically, not enabling https access may not affect you at all, but if you use an unencrypted wi-fi access for FB, then you definitely should be. (Does anyone still have a non WPA2 encrypted home wi-fi network? I so so hope not!)<\/p>\n<p>I am not going to get technical. Lets just say that gmail implemented it as default a few months back. I remember <a href=\"http:\/\/cpbotha.net\/2009\/11\/01\/your-gmail-account-can-be-hacked-over-insecure-wifi\/#more-678\" target=\"_blank\">Charl B pointing out<\/a> this issue with regards to gmail nearly 16 months ago and the opt in solution . Then they made it default a few months later.\u00a0 Most gmail users probably never even noticed the change. It made no difference to the performance.<\/p>\n<p>On facebook its still opt in however, not default, a year later!<\/p>\n<p>https is the encrypted protocol that banks use for communication when you do your banking. You know, &#8220;the lock&#8221; at the bottom of your browser?<br \/>\nFiresheep is an add-on that runs in firefox that allows someone on the same unencrypted wi-fi network as you to basically log in as you to sites that don&#8217;t use https for the whole session. Before this, &#8220;sidejacking&#8221; was a bit more difficult.<\/p>\n<p>Aston Kutcher, while at TED (TED is awesomeness!) must have used unencrypted wi-fi without https on his twitter and got <a title=\"firesheep-ed\" href=\"http:\/\/www.digitalsociety.org\/2011\/03\/ashton-kutcher-meets-firesheep-twitter-hacked\/\" target=\"_blank\">firesheeped. <\/a><br \/>\nmore background here:<br \/>\n<a href=\"http:\/\/www.digitalsociety.org\/2011\/02\/someone-in-dc-cares-about-online-security\/\" target=\"_blank\">Someone in DC cares about online security<\/a><\/p>\n<p>It makes sense to turn it on. If it gives you hassles, turn it off. If you use unencrypted wifi bear with it!<\/p>\n<p>in FB goto<br \/>\nAccount&gt;account settings&gt;Account security and click Secure browsing (https)<br \/>\nSimple!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Me doing a security type post, here&#8217;s a first&#8230;Some of you will repost this, others won&#8217;t. No scaremongering here. Realistically, not enabling https access may not affect you at all, but if you use an unencrypted wi-fi access for FB, then you definitely should be. (Does anyone still have a non WPA2 encrypted home wi-fi &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.flipangle.org\/?p=83\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;FB security *yawn* &#8211; Firesheep *hmmm sounds interesting*  &#8211; and the opt in option for https on Facebook *yawn*&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-83","post","type-post","status-publish","format-standard","hentry","category-solutions"],"_links":{"self":[{"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/posts\/83","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=83"}],"version-history":[{"count":4,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/posts\/83\/revisions"}],"predecessor-version":[{"id":85,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=\/wp\/v2\/posts\/83\/revisions\/85"}],"wp:attachment":[{"href":"https:\/\/www.flipangle.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=83"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=83"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.flipangle.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=83"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}