• About
  • Contact
  • Visitor Map
  • Privacy Policy
  • Tutorials
    • Geotagging Tutorial
Average Traveller | Travel Blog within easy driving distance of the beaten path
  • About
  • Contact
  • How To
  • Museums
  • Hong Kong
  • United Kingdom
  • Italy
  • Visitor Map
  • Privacy
  • RSS Feed
  • Twitter
  • Facebook

Travel Security: Facebook Login and Sessions

– January 31, 2011Posted in: How To, Security

Travel Security for Facebook Login and Sessions

Have you ever had your Facebook account hacked? Do you know anyone who has? Much has been made lately of Facebook supporting full HTTPS access. There are many different people out there who will tell you that it’s a good thing and show you how to enable it, but not many who explain how it will help prevent your account from being hacked – especially while travelling.

If you’ve found your way here you are likely that type that enjoys travelling and using the Internet. Many people who use the Internet while travelling use it to access Facebook in order to stick to to their family and friends back at home. To take this story a little further, I suggest that many of these travelling Facebook users will access Facebook on unencrypted wireless connections at a hotel, hostel, airport, cafe, or other location. I have no scientific evidence to back this up, but it holds true among my circle of friends so hopefully this post will at least be useful to both of them.

Logging into and using any web applications not protected by encryption is much more risky than most people know. In my other life as an Information Security Consultant I get to show people how easy it is to hijack web application accounts over unencrypted wireless networks such as those commonly used by travellers.

If you didn’t already know, HTTPS secures your Facebook session by encrypting all the traffic that travels between your browser and Facebook’s servers. The S stands for secure. It’s been around for ages and is the the same technology that you’ve been taught to look for while banking online.

HTTPS support isn’t entirely new to Facebook, either, as it has been possible to simply change the HTTP in the URL to HTTS before login for quite some time. The difference is that until now that HTTPS session only protected your Facebook login credentials (user name and password) and the rest of your session would run in unencrypted plain-text after login.

Why wouldn’t Facebook encrypt everything? The primary argument against it is that encryption requires computer processing power on their servers. On a one-off basis the difference is barely noticeable, but when you are one of the biggest websites on the Internet every little bit adds up quickly.

So what caused Facebook to bring about the change? Firesheep. Firesheep is a Firefox extension that easily allows people to monitor unencrypted traffic on a network to look for Facebook cookies and then use those cookies to hijack those accounts. Cookies are how your browser proves to Facebook that the click you are sending them is associated with the login process you completed earlier. It’s a web trick to prevent you from having to send your username and password every time you click on a web page.

Because Facebook didn’t encrypt sessions, anyone on the same network as you or who is within radio range of your unencrypted wireless traffic could capture one of these cookies. The cookie could then be replayed by the bad guy and Facebook would happyily think that the bad guy using your cookie is, in fact, you. This kind of attack was possible before Firesheep, but it required knowledge of computer networking and a moderate amount of geekery. Firesheep just brought this capability to anyone who can use a browser and handed it them with point and click simplicity.

If you use are a heavy user of cafe or hotel wireless, I strongly suggest that you enable this function. Facebook hasn’t rolled this out to everyone yet, but I know I will enable it once it is available to me. If Facebook has planned things out properly and bumped up their encryption horsepower you shouldn’t really notice a difference in performance. Of course, just using this setting alone does not guarantee that the bad guys won’t hack your Facebook, but it means that only the more sophisticated bad guys can do it. And trust me, there are loads of unsophisticated bad guys out there.

If you want to learn how to increase your protection against the smart bad guys, as well as how to protect your email and other web apps, check back for a future post about Virtual Private Networks.

To see if you can enable HTTPS on Facebook:

  1. Login to Facebook 
  2. Click on ‘Account’ at the top right hand of your Facebook page
  3. Click on ‘Account Settings’ in the drop-down box
  4. There should be an option to enable HTTPS there. I would include a screen cap, but it’s not available to me yet.
If you enjoyed this post, please consider leaving a comment or subscribing to the RSS feed to have future articles delivered to your feed reader. Thanks!

Related posts:

Rick Mercer on Airport Security
How To Geotag Photos with EasyGPS - Part 2
UK Value Added Tax (VAT) Refunds for Visitors
  • Keep this:
  • Email
  • Print
Tags: Facebook, HTTPS, Login

No Comments

Start the ball rolling by posting a comment on this article!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

*

*

* 9+1=?

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Notify me of followup comments via e-mail. You can also subscribe without commenting.

  • Please Share!
    Tweet
  • Get email Notifications


     

  • Be a Little Social
    Follow Me on Pinterest

    Follow Me on Facebook

    Follow Me on Twitter

    Follow Me on Flickr

  • Related Links
    • How To
      • San Diego Zoo Tips and Tricks
      • Taking the MTR Train to Hong Kong Disneyland
      • Tutorial: How to Take Better Indoor Pictures Without a Flash
      • Top Tips for Visiting Legoland California
      • How to Create a Trip Map Using EasyGPS and GPSVisualizer.com
    • Security
      • Travel Internet Safety Using Virtual Private Networks (VPN)
      • Rick Mercer on Airport Security
      • Travel Security: Don't Trust Your Hotel Door Lock
  • Do You Know How To
    • Don't try to see the zoo in a day. The zoo has 9 different animal zones and covers 100 acres in Balboa Park. If you only have one day to spend there you won't be able to see everything, especially if you have kids in tow. To make sure that you don't leave disappointed, check out the San Diego Zoo website before you show up and come up with a list of must-see attractions. Once you know what you want to see check out the online Park Map [sandiegozoo.org] to come up with a rough plan of attack.
      San Diego Zoo Tips and Tricks
      25 April 2012 7:35 PM | 25 Comments
    • Whoever decided to put Hong Kong Disneyland and the new Hong Kong International Airport on the same island is brilliant. The result of this little nugget of transportation planning means that making the trip from downtown Hong Kong to the House of the Mouse could hardly be easier. The trip to Lantau Island takes a little over 30 minutes, which is about the same amount of time it would take to drive or take a cab and costs $24.50 hkd for adults and $12.50 hdk for concession (rates even lower if you use an Octopus card).
      Taking the MTR Train to Hong Kong Disneyland
      05 April 2012 10:26 AM | 11 Comments
    • The good news is that it is possible to take nice pictures without a flash. Once you get up a bit of a learning curve on some camera basics, and if you have a few dollars to spend on some relatively inexpensive camera gear, you'll be shooting with a plan instead of just hoping for the best!
      Tutorial: How to Take Better Indoor Pictures Without a Flash
      16 January 2012 9:36 AM | 3 Comments
    • While the park only really has 1 major thrill ride to satisfy big kids, there are plenty of small coasters, a target ride, a pirate themed splash zone, and many other well themed rides to keep kids from age 5 and up to the young teens entertained. And of course, adult fans of Lego (AFOL - there's actually an official club) and teenage fans of Lego will enjoy checking out the many Lego sculptures around the park. I would allow 2 full days to see everything.
      Top Tips for Visiting Legoland California
      04 January 2012 7:10 PM | 5 Comments
    • We used the GPS the whole weekend. When we got back I I exported all of the GPS track data using EasyGPS and was able to generate this map using GPSVisualizer.com to show a map all of the places that we went.
      How to Create a Trip Map Using EasyGPS and GPSVisualizer.com
      15 November 2011 4:37 PM | No Comments
    • On a recent trip we were staying at the Sheraton Seattle which has a very large interior window ledge covered with nice hotel blackout curtains. When it was lights-out time for the kids I snuck behind the curtain with my camera and gorilla-pod and tried to figure out the zoom effect.
      Travel Photo Thursday: Seattle View Zoom Effect (How To)
      28 September 2011 7:43 PM | 17 Comments
    • When I was in Hong Kong earlier this year I toyed with the idea of buying a 900/2100 band phone there but I couldn't find a reasonably contemporary Android phone for less than $300. Now that I've started doing research on prepaid SIM cards in London I've noticed that 3 UK has two nice looking 3G speed phones available for under £100 and they also offer 500mb of data on a £15 top up.
      Affordable Pay As You Go Smartphones in London
      24 June 2011 10:17 AM | No Comments
    • Having access to a VPN allows travellers to access all of their Internet services without fear of someone listening in on that free Wifi connection at the Cafe. Many people don't really understand how amazingly easy it is to eavesdrop and even hijack Internet connections on unecrypted Wifi, which is trypically what you'll be using at your hotel, hostel, and cafe.
      Travel Internet Safety Using Virtual Private Networks (VPN)
      13 March 2011 9:20 AM | 2 Comments
    • I've had a number of people ask me about travelling in Italy so I thought that I would list some of the things that might not be completely obvious. Some of this is repeated from my trip logs posts, but you can read it all in one place here.
      Advanced Travel Tips for Italy
      08 February 2011 10:04 PM | 7 Comments
    • After finding out that my trusty HTC Desire Z won't give me 3G speeds in Hong Kong I might try one of the 2G data providers first and see if I can live at 2G speeds again. If it's unbearable I might pick-up an unlocked Android that supports the 2100 band while I'm there.
      Hong Kong Prepaid GSM and Mobile Data Options
      06 February 2011 9:29 AM | 11 Comments
  • Recent Posts
    • Tomorrowland Toilets at Hong Kong Disneyland
    • Dario Cecchini’s Officina della Bistecca Steak Workshop
    • San Diego Zoo Tips and Tricks
    • Visiting the San Diego Zoo Safari Park
    • Causeway Bay Dessert Map 2012 (Hong Kong)
    • Toy Story Land at Hong Kong Disneyland
    • Taking the MTR Train to Hong Kong Disneyland
    • Hong Kong Museum of Coastal Defence
  • Popular Posts
    • Consent Letters: One Parent Travelling Abroad with Children
    • Dario Cecchini’s Officina della Bistecca Steak Workshop
    • San Diego Zoo Tips and Tricks
    • Visiting the San Diego Zoo Safari Park
    • Hong Kong Prepaid GSM and Mobile Data Options
    • Tomorrowland Toilets at Hong Kong Disneyland
    • Italy Prepaid SIM Cards Part III: Mobile Data
    • Hong Kong Food Blogs
  • Sponsored Links
  • Categories
    • British Columbia (20)
      • Prince George (2)
      • Tofino (1)
      • Vancouver (15)
      • Victoria (2)
      • Whistler (1)
    • California (8)
      • Los Angeles (3)
      • San Diego (5)
    • Flying (8)
    • Food (16)
    • Gadgets (8)
    • Hawaii (6)
    • Hong Kong (24)
    • How To (16)
    • Italy (30)
    • Kids (2)
    • Las Vegas (7)
    • Misc (2)
    • Museums (7)
    • New Zealand (1)
    • Photography (13)
    • Seattle (5)
    • Security (4)
    • Spain (2)
    • Theme Parks (12)
    • Travel Contests (3)
    • Travel TV (4)
    • Trip Log (12)
    • United Kingdom (22)
    • Weird (4)
    • Yukon (1)

About Arras WordPress Theme

Copyright Average Traveller | Travel Blog. All Rights Reserved.

loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.