Twitter is vulnerable to Firesheep even when you connect via HTTPS

https://news.ycombinator.com/item?id=1846757
by PawelDecowski • 16 years ago
9 1 16 years ago

For a session to be secure all requests that carry the cookie need to be over HTTPS.

When going to https://twitter.com/ I noticed that (among dozens of others) it requests URL http://twitter.com/scribe?[...] (note HTTP, not HTTPS) which includes the session cookie.

Hence, it's sent plain-text, even if you go to https://twitter.com/

Related Stories

Loading related stories...

Source preview

news.ycombinator.com