webOS Nation Forums >  webOS apps and software >  webOS Synergy and synchronization > Firesheep protection
Firesheep protection

  Reply
 
LinkBack Thread Tools Display Modes
Old 02/18/2011, 08:42 PM   #21 (permalink)
Member
 
Join Date: Mar 2002
Location: NY
Posts: 191
Likes Received: 0
Thanks: 9
Thanked 0 Times in 0 Posts
Default

bump - can we force contacts/calendar to sync using https? Or are ALL google connections SSL if you select "always use https" for gmail?

Last edited by sck18; 02/26/2011 at 07:00 AM. Reason: typo
sck18 is offline   Reply With Quote
Old 02/26/2011, 01:19 AM   #22 (permalink)
Member
 
Mr._Happy's Avatar
 
Join Date: Feb 2010
Posts: 101
Likes Received: 1
Thanks: 23
Thanked 27 Times in 15 Posts
Default

If you use gMail there is an "always use https" setting.

Facebook has it now too - although using it screws some of the gaming apps up at this point.
__________________
Trēo 650 -> Trēo 700P -> Trēo 755P -> Prē
Mr._Happy is offline   Reply With Quote
Old 06/06/2011, 05:41 PM   #23 (permalink)
Member
 
Join Date: Jun 2011
Posts: 29
Likes Received: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Was anyone able to figure out if the Contacts use HTTPS when updating from Facebook, Twitter, LinkedIn, etc?
tomlamb is offline   Reply With Quote
Old 06/06/2011, 09:24 PM   #24 (permalink)
Member
 
Join Date: Apr 2011
Posts: 41
Likes Received: 2
Thanks: 7
Thanked 21 Times in 5 Posts
Unhappy

Quote:
Originally Posted by lordbah View Post
Are Calendar and Contacts automatically making unsecured connections periodically? If so, can't we patch them to use HTTPS?
I don't think so, at least not all of them. I've made a test, by making my Pre connect to my computer via WiFi, then creating a new Google calendar event and a new Google contact. I found out that I can view the new calendar event and contact easily (i.e. they are in plaintext form, not encrypted).
rcmarvin is offline   Reply With Quote
Old 06/07/2011, 10:22 AM   #25 (permalink)
Member
 
Join Date: Jun 2011
Posts: 29
Likes Received: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Default

I am surprised that I could not find anything to verify that the Facebook app and contact interface are done through HTTPS or Http. With the AT&T phones normally set to automatically connect to their Hotspots (Starbucks) I would think there would be enough concern to at least have HP/Palm give a statement about it.

Update: According to a support supervisor, the default (LinkedIn, Facebook, Twitter) is to use http so that was not what I wanted to hear. If this is true, this would be a problem for those who automatically connect to AT&T hotspots as your info could get caught by Firesheep or FaceNiff. The supervisor said he would forward this as a feature request.

Last edited by tomlamb; 06/07/2011 at 12:34 PM.
tomlamb is offline   Reply With Quote
Old 06/07/2011, 12:37 PM   #26 (permalink)
Member
 
Unclevanya's Avatar
 
Join Date: Aug 2010
Location: Charlotte, NC
Posts: 1,483
Likes Received: 27
Thanks: 322
Thanked 203 Times in 168 Posts
Default

Does anyone know if the LinkedIn contact sync and application use https?

Last edited by Unclevanya; 06/07/2011 at 12:48 PM.
Unclevanya is offline   Reply With Quote
Old 06/07/2011, 12:43 PM   #27 (permalink)
Member
 
Join Date: Jun 2011
Posts: 29
Likes Received: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Default

The reply I got from one supervisor is that Facebook, LinkedIn, and Twitter by default connect via http. That is just one support session (started with a regular support guy and escalated to a supervisor) so you should take it with a grain of salt.
tomlamb is offline   Reply With Quote
Old 06/07/2011, 01:16 PM   #28 (permalink)
Member
 
Unclevanya's Avatar
 
Join Date: Aug 2010
Location: Charlotte, NC
Posts: 1,483
Likes Received: 27
Thanks: 322
Thanked 203 Times in 168 Posts
Default

Quote:
Originally Posted by tomlamb View Post
The reply I got from one supervisor is that Facebook, LinkedIn, and Twitter by default connect via http. That is just one support session (started with a regular support guy and escalated to a supervisor) so you should take it with a grain of salt.
The answer they gave isn't really detailed enough - we need to know if the app and synergy both do this or if only one or the other do this. We also need to know if this can be changed easily or if OS patches are required.
Unclevanya is offline   Reply With Quote
Old 06/07/2011, 01:46 PM   #29 (permalink)
Member
 
Orion Antares's Avatar
 
Join Date: Jun 2010
Location: Alaska
Posts: 1,617
Likes Received: 105
Thanks: 67
Thanked 304 Times in 227 Posts
Default

Quote:
Originally Posted by Unclevanya View Post
Does anyone know if the LinkedIn contact sync and application use https?
Last I checked a couple days ago LinkedIn didn't yet support full session SSL but it's in their plans to do so. When they do though it will be off by default so you'll still need to turn it on in your account settings.
__________________
Sign up for SugerSync Get and Give 500MB of extra space
Sign up for DropBox Get and Give 250MB of extra space
Sign up for Memopal Get and Give 500MB of extra space


GoAruna is a cloud service with a webOS app maintained by the company and referral bonuses
Orion Antares is offline   Reply With Quote
Old 06/07/2011, 02:48 PM   #30 (permalink)
Member
 
Join Date: Jun 2011
Posts: 29
Likes Received: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by Unclevanya View Post
The answer they gave isn't really detailed enough - we need to know if the app and synergy both do this or if only one or the other do this. We also need to know if this can be changed easily or if OS patches are required.

I agree completely. As I am a new to WebOS (only 1 day) I am not sure where to send this, but for now I guess I will just keep the Wifi off.
tomlamb is offline   Reply With Quote
Old 06/07/2011, 03:21 PM   #31 (permalink)
Member
 
Unclevanya's Avatar
 
Join Date: Aug 2010
Location: Charlotte, NC
Posts: 1,483
Likes Received: 27
Thanks: 322
Thanked 203 Times in 168 Posts
Default

Quote:
Originally Posted by tomlamb View Post
I agree completely. As I am a new to WebOS (only 1 day) I am not sure where to send this, but for now I guess I will just keep the Wifi off.
Probably a good solution for the most part.

There are some SSL based proxies that would limit exposure on the local wireless network. These do not provide full ssl protection since they only provide the ssl tunnel to the gateway and from then on it's unencrypted again - but this does prevent people on the same lan stealing your info from the web browser - however it does not help for non-browser based connections.

Potentially a VPN could help - but in the same way as before it would be limited to protection at the local network layer - once it reached the gateway it would be decrypted and vulnerable but presumably this would be a smaller risk.

I haven't really tried either of these solutions with webOS - guess it's time to start looking into this.
Unclevanya is offline   Reply With Quote
Reply

 

Tags
firesheep, security, sync

Thread Tools
Display Modes



 


Content Relevant URLs by vBSEO 3.6.0