jducoeur: (Default)
[personal profile] jducoeur
Nope -- not the burnt coffee, nor even their business practices. This time, it's those public hotspots that I'm talking about. You know, the ones that let you wirelessly log into your mail on your laptop from any Starbucks or Panera? Well, this article (rather technical, but you can get the gist) demonstrates the danger of those things. Suffice it to say, if you log normally into your Gmail account via a public hotspot, it is getting *quite* easy for a hacker to steal your credentials and impersonate you on all of the Google services.

Basically, if you're using any personal services through a public hotspot, you need to pay closer attention than normal. It's reasonable to assume that any URL that starts with "http:" may be snooped -- and that means, if you log into a personal site that way, they may be able to steal your passwords and your data. If the URL starts with "https:", it's much more likely to be fully secure against snooping, and you can often simply substitute the one for the other. (I just proved that I can hack my Google Toolbar to default to "https:".)

When browsing publically, it's a good idea to watch out. The Web is never 100% secure, but it's much, much easier for someone to grab your identity through these public hotspots than under normal circumstances...

(no subject)

Date: 2007-08-16 04:48 pm (UTC)
From: [identity profile] metahacker.livejournal.com
For Firefox users, one specific fix is to install the Better GMail plug-in. It has an option to force https use when connecting to gmail, which is good if you're like me and forget to go in via that route.

It has a bunch of other useful features, too.

(no subject)

Date: 2007-08-16 10:13 pm (UTC)
ext_44932: (tech)
From: [identity profile] baavgai.livejournal.com
The few times I've been around hotspots with the right toys, I've been amazed by the open traffic. With just laptops and PDAs, nothing special, you can often watch your neighbors bits fly by.

And Windows the default with that shared folder? Do people really know they share such things?

Thanks for the https suggestion. Making that a default makes a whole lot of sense.

(no subject)

Date: 2007-08-17 01:15 pm (UTC)
From: [identity profile] shava23.livejournal.com
of course, you could use http://tor.eff.org/ and then all your traffic is encrypted from your computer out until the last hop to its destination, but it's SLOWer and it won't let you, say, play WOW or log into SL from a coffeeshop, or use Skype reliably.

There are security vulnerabilities to using multimedia plug-ins with Tor, but that's only if you're trying to be anonymous (hide the "caller ID" of your IP origin from anyone along the path). But if you're just using it to make sure that first hop is encrypted, you don't need to worry about that.

Shava
Development Director
The Tor Project

Profile

jducoeur: (Default)
jducoeur

June 2025

S M T W T F S
12 34567
891011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags