Firesheep Exposes Flaw In Facebook Log-In Security

A new extension to Firefox called Firesheep reveals a potential security flaw in Facebook's log-in process.

A new extension to Firefox called Firesheep reveals a potential security flaw in Facebook’s log-in process.

A Codebutler blog post explains how Firesheep works. Basically, the plug-in lets attackers capture and spoof a cookie so they can log-in to Facebook as another user. The vulnerability was already there but Firesheep makes it as easy as opening the application and then double-clicking on someone’s name to log-in as them.

According to Facebook its log-in process uses SSL technology, whether you go via https://www.facebook.com

AW+

WORK SMARTER - LEARN, GROW AND BE INSPIRED.

Subscribe today!

To Read the Full Story Become an Adweek+ Subscriber

View Subscription Options

Already a member? Sign in