Showing posts with label wireless. Show all posts
Showing posts with label wireless. Show all posts

Tuesday, February 1, 2011

Enabling https on Facebook

Below is a screenshot of how to enable https on Facebook.

This will protect you from people trying to see what is being transmitted over the network, and also things like Firesheep, a free Firefox extension that allows people to log in as YOU.

Wednesday, January 26, 2011

A more secure Facebook connection

Nice! Facebook is now making secure connections to it possible.

From today's Facebook blog entry:
Starting today we'll provide you with the ability to experience Facebook entirely over HTTPS. You should consider enabling this option if you frequently use Facebook from public Internet access points found at coffee shops, airports, libraries or schools. The option will exist as part of our advanced security features, which you can find in the "Account Security" section of the Account Settings page.
This protects any information (including profile pages, contact information, location of you and your friends, etc) sent to/from your browser and Facebook's server from any eavesdroppers. So, if you are in a public area, such as an airport, library, coffee shop, where there are many people (possibly malicious), you'll definitely want to enable this. Because you have to log in to turn it on, you'll probably just want to go ahead and enable it.

I tried going to the "Account Security" section of my Account settings, but did not see the option available yet. Maybe tomorrow.

See my previous blog entry about using free public internet.

Monday, May 25, 2009

Using free public wireless internet

What do you do when you want to use the internet, but don't have your own connection? Most people will search for a wireless signal and try to get "free internet." Most coffee shops, airports, hotels, schools, etc., provide free WiFi. Everyone likes FREE stuff, but if you are sending any personal information, you may want to think twice because Mr. Stranger might be able to read it.

Imagine you are at a party, and you see two of your best friends. You have some wonderful personal news to tell them, and you get them together to share your news (in the middle of the crowd.) As you talk with your two friends, a nosy Mr. Stranger is curious about what's going on, walks by casually, listens intently, and overhears your conversation. Something similar could also happen when using free public wireless internet.

When you are using a wireless network, you are sending and receiving messages back and forth with the wireless router to which you are connected via radio waves. You're having a conversation with the router (although not a very personal one - the router is more like a middleman. It just relays the messages.) Any computers within distance (i.e. the radio waves can reach them) can also hear your conversation. Usually computers ignore messages that are not addressed to them. However, a malicious Mr. Stranger could use various tools on his computer to read those messages. (This is called packet sniffing, although packet sniffing is not always malicious.)


For example, in the picture above - all the computers could potentially see what messages others are sending to and receiving from the router (if the messages aren't encrypted.) Computer ABC can see the username and password Computer XYZ is using to log into the insecure web site toothbrush.com, as well as the email to Bob that you are sending. If you are just surfing the web, such as checking sports scores or the weather forecast, then you may not care if others can see what you're doing.

This is why it is important to make sure you are using encryption when sending confidential information over a wireless connection. Using encryption is like using your own invented language with your friends so that no one else can understand. People can still hear what you're saying, and who you are saying it to, but they won't understand what you're saying (unless they figure out your invented language.)

Turning on the gmail security setting suggested in the last post makes your computer and the gmail server use their own invented language.

Other web sites that require a password may or may not use encryption. Most will at least encrypt your password, but some possibly do not. If you use your own wireless network and have configured it so that you need a password to connect to your own router (e.g. using WEP or WPA,) then you are using encryption over your wireless connection - your computer and your wireless router are using their own language to talk.

More on what uses encryption (and how you can tell), and how to secure your own wireless network later.