One of the joys of the Internet age is the ubiquity of Wi-Fi hotspots. More and more businesses are offering Wi-Fi access. It’s often free, as well as being free of any password requirements or encryption. While that’s convenient, it’s also dangerous.
Security experts have long warned that connecting to a non-encrypted hotspot leaves you vulnerable to attack — a warning that most Wi-Fi users gleefully ignore as they sign in to check their Facebook walls, scan e-mail messages or browse Twitter.
It’s even more dangerous if you’re not making secure connections to the Web sites themselves. Sites that use a secure, encrypted connection have https in their Web address — rather than just http — and show a lock icon in most browsers.
You could take some comfort in the fact that it requires some skill to launch one of these attacks. Most people are honest, and even more people are clueless as to the hackery necessary to access someone else’s data.
Firesheep changes all that. It’s a Firefox extension that makes it ridiculously easy to log into certain sites as another user — in as little as three clicks after installing the extension.
How does Firesheep work? It “sniffs” the traffic that moves across a network, looking for unencrypted Web connections to any of 26 sites. When it finds one, it displays the user name and the site.
When you’re connected to a site, you’re sharing information with the site, which assigns you a number known as a session ID. That number is passed over the network and can be grabbed by Firesheep if the connection isn’t encrypted. When you double-click on a connection in Firesheep’s list, it uses the session ID number it’s grabbed to sign you in as that person.
This technique is not new. Hackers have used tools called packet sniffers for…