Skip to main content
  1. Home
  2. Computing
  3. Social Media
  4. Legacy Archives

Firesheep exposes gaping Wi-Fi security holes

Add as a preferred source on Google

best-firefox-add-onsIn case you weren’t already weary of Internet security plagues, here’s a new one for you. Firesheep, a downloadable extension for Firefox, can now make it more than possible for someone to take over your Wi-Fi session. It makes it really easy.

Once installed, a person can hijack your Wi-Fi session, including the ability to access Twitter, Facebook, WordPress, and Amazon accounts, among others.

Recommended Videos

Who’s responsible for this? Software developer Eric Butler says he created the app in order to show the masses how easy it is for their accounts to be highjacked over a Wi-Fi connection.  And if you were already aware of this, he is simply confirming it for you.

On his blog, Butler explains the simplicity of Firesheep. “It’s extremely common for websites to protect your password by encrypting the initial login, but surprisingly uncommon for websites to encrypt everything else. This leaves the cookie (and the user) vulnerable.” Butler has made the add-on openly available and very simple to download and use – so anyone with a Wi-Fi connection and a strong sense of curiosity can easily try it out.

Wi-Fi security isn’t a new issue. Concern about accessing secure information over a public connection has been loudly voiced, but the effortlessness and availability of Firesheep makes it easy to use by anyone, even those with little to no technical knowledge.

Butler insists his motives are pure, that website security needs to acknowledge these holes and fix them before more people like him won’t exploit them.

Molly McHugh
Former Social Media/Web Editor
Before coming to Digital Trends, Molly worked as a freelance writer, occasional photographer, and general technical lackey…
AI models from Anthropic and OpenAI were caught breaking the rules again
A new report states AI agents from both companies took unauthorized actions during safety tests, from hacking a website to tricking real people online.
Claude website open on laptop

OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.

Now, the UK's AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.

Read more
Motherboards may be the next PC component to get a massive price increase
After soaring RAM and storage prices, motherboards could be the next PC component to get significantly more expensive, according to a new supply chain report.
Gigabyte X870E AORUS INFINITY NEXT motherboard on display

Building a PC from scratch has already become a lot more expensive, thanks to skyrocketing RAM and storage prices driven by rising AI data center demand. Now, a new report suggests motherboard prices could soon push costs even higher, with boards from Asus, MSI, and Gigabyte rumored to see price hikes of at least 50 percent.

Your next PC upgrade could get a lot pricier

Read more
Deepfake bosses are crashing video calls, and researchers are trying to expose them
Seeing your boss on video no longer proves they are real
Researchers at Fraunhofer SIT are fighting against deepfake meeting video calls

Entering into a meeting with your boss and several familiar coworkers inside a video conference is the next area vulnerable to cybercrimes, and it's all because of deepfake technology. Researchers at the Fraunhofer Institute for Secure Information Technology SIT are working on a real-time warning system designed to identify attempted fraud during corporate video conferences.

The report states that criminals are increasingly targeting video meetings for identity theft and financial scams, taking advantage of the trust people place in familiar faces and voices. The intention is to flag suspicious activity while the meeting is still taking place. This gives an employee a chance to stop before following an expensive instruction from an AI-generated executive.

Read more