Allow TLS/SSL encrypted use of LiveJournal (not just logins)

Oct 28, 2010 09:52


Title
Allow TLS/SSL encrypted use of LiveJournal (not just logins)

Short, concise description of the idea
Now that cookie-capturing attacks (e.g. Firesheep) have become easy to use, it would be good to be able to use LiveJournal through an encrypted connection.

Full description of the ideaIt's been possible to log in through an encrypted connection ( Read more... )

security, § no status

Leave a comment

Comments 7

koulagirl666 November 10 2010, 12:53:01 UTC
I just want to say this is a well-thought out and wonderfully detailed suggestion.

Reply


pauamma November 10 2010, 13:53:32 UTC
Yep, definitely needed.

Reply


(The comment has been removed)

pne November 10 2010, 16:17:23 UTC
Insecure content would be a huge problem in general, not just for ads. Consider images posted by users in their entries. Or, worse yet: userpics are hosted through the (external) Limelight CDN, which might not support SSL (or might charge much more for SSL delivery).

Good point - hadn't thought of those.

Reply


azurelunatic November 10 2010, 21:48:16 UTC
Another benefit: less wear and tear on the people expected to deal with incidents of account compromisation.

Reply


imc November 11 2010, 17:16:24 UTC
Good point well made.

I seriously doubt this will get done in the near future. :-(  If it is, it's likely to be only on site pages (for reasons including those mentioned above).

You can mitigate the effect of cookie-stealing by setting the "Bind cookie to IP address" option when logging in, which admittedly doesn't work in all circumstances. But as far as I know there is still a years-old bug in ScrapBook which means that it doesn't think you are logged in if you selected this option, so it's useless for managing your pics or even for looking at others' friends-only pics. (Yay for security…)

I think the per-subdomain cookies only give away read access - so there's still a privacy issue but at least not one of malicious damage.

Reply


Leave a comment

Up