Idiocy auto-hacks Twitter accounts on public Wi-Fi, warns the owners about Firesheep
The geek community has been buzzing about Firesheep, a Firefox add-on that grabs Facebook and Twitter login cookies from any public Wi-Fi network, and uses them to log into others' accounts. Not everyone at the local coffee shop will have heard about Firesheep, though ... and that's where Idiocy comes in. Idiocy is a bit of code you can run that will use Firesheep to automatically break into any Twitter account that sends an insecure login cookie over your wireless network.
Once it's grabbed someone's login credentials, Idiocy will post a tweet from their account, warning them that they've been compromised and linking to a page about Firesheep and how to secure your account against it. It sounds malicious, but Idiocy is more like a public service than anything else. Sure, the tech blogs and Twitter buzz about Firesheep should be enough to convince people to use HTTPS when they log into social networking sites, but some people just don't get the picture until it affects them personally.
The moral of the story is that, unless you want someone maliciously using Firesheep on you, or using Idiocy on you for your own good, you should consider taking five minutes for some quick security fixes.
Once it's grabbed someone's login credentials, Idiocy will post a tweet from their account, warning them that they've been compromised and linking to a page about Firesheep and how to secure your account against it. It sounds malicious, but Idiocy is more like a public service than anything else. Sure, the tech blogs and Twitter buzz about Firesheep should be enough to convince people to use HTTPS when they log into social networking sites, but some people just don't get the picture until it affects them personally.
The moral of the story is that, unless you want someone maliciously using Firesheep on you, or using Idiocy on you for your own good, you should consider taking five minutes for some quick security fixes.













Comments
3
Subscribe to commentsMike ZachaczewskiOct 27th 2010 5:46PM
Lesson learned, do not log in to your Facebook or Twitter account over open unsecured Wi-Fi.
UserOct 28th 2010 12:31PM
I don't even log in on university computers because I do not trust the security of those machines. A bit paranoid I guess, but do not want my stuff compromised.
JamesOct 29th 2010 2:48PM
Just to clarify, idiocy doesn't use firesheep (though it exploits the same security vulnerability).
In fact, right now idiocy only works on linux, and firesheep works on windows and mac, but not on linux.