Archive for the ‘Security’ Category

Protection against (firesheep) session hijacking

Last month, a simple firefox extension called FireSheep caused a slight panic amongst web developers. FireSheep makes it dead simple to hijack a user session with just one click. Even a 10 year old could take over your Facebook session with a single mouse click.

Don’t worry: all shops on SolidShops.com are protected against session hijacking. We wanted to put this blog post out there only to inform web developers and end users about the problem of session hijacking.

Let me explain in short what the problem is and why any other web application out there should also protect its users from session hijacking.

Read the rest of this entry »