Security Innovation today announced performance statistics for its NTRU encryption algorithm, providing further proof that adopting end-to-end encryption for web applications can be cost effective. This data comes on the heels of the release last week of Firesheep, a Firefox add-on that exposes the prevalence and simplicity of session hijacking vulnerabilities in websites. Firesheep was developed by Eric Butler, a freelance web application developer and Ian Gallagher, a Sr. Security Engineer at Security Innovation. The duo presented Firesheep to an eager audience at the ToorCon security conference, and demonstrated session hijacking flaws in both Facebook and Twitter.
“Session hijacking is particularly dangerous in an open wireless network setting, such as in a public coffee shop” says Gallagher of Security Innovation. “Cookies are frequently issued on Web sites and freely accessible in clear text view over the network, making these attacks easy to carry out. We created Firesheep so that organizations can find and eradicate security flaws and reduce user risk.” Firesheep makes it easy to demonstrate and understand the impact of session hijacking, an attack in which a victim’s web session is stolen and used to impersonate the victim on a web site. This is a serious attack, but one that can be prevented with end-to-end encryption using technology such as SSL.
“Organizations that offer Web sites have a responsibility to protect the private information and credentials of users who depend on their services” said Ed Adams, CEO of Security Innovation. “Security Innovation is committed to helping organizations improve security measures and pleased to support the research work of our employees, such as Mr. Gallagher, as well as Mr. Butler in this regard.”
0 comments:
Post a Comment