Länk - CERT varnar för http över öppet WiFi

published Sep 10, 2007 12:28   by admin ( last modified Sep 10, 2007 12:28 )
Som jag skrivit om tidigare, använd https hela tiden eller VPN.

US CERT warned that Google, eBay, MySpace, Yahoo, and Microsoft were vulnerable, but that list is nowhere near exhaustive. Just about any banking website, online social network or other electronic forum that transmits certain types of security cookies is also susceptible. The vulnerability stems from websites' use of authentication cookies, which work much the way an ink-based hand stamp does at your favorite night club. Like the stamp, the cookie acts as assurance to sensitive web servers that the user has already been vetted by security and is authorized to tread beyond the velvet rope.


Läs mer: A US CERT reminder: The net is an insecure place | The Register