Is Algeria Deleting Facebook Accounts?
belmolis writes "Algeria is reported to be shutting down ISPs and deleting Facebook accounts in an effort to prevent anti-government protests from escalating as they did in Egypt. Is it likely that they are deleting FB accounts? Unless Facebook is cooperating, this would either require hacking FB to obtain administrator privileges or cracking the password of each account they wish to delete."
I thought it was impossible to actually delete a Facebook account? Sure, you can deactivate it, but not delete as far as I can remember.
That cookie is renegotiated after each https login, and it is specific to one session. You can't clone it from another station.
Even if you do manage to intercept it, Man in The Middle attacks are notoriously hard to execute
Quick, someone tell these guys that hijacking FB sessions should be difficult.
Muslims inside Egypt and out condemned that attack. Fortunately, such attacks are few and far between. Look at the aftermath, when terrorists attacked a church around Christmas, thousands of Muslim Egyptians attended church services in Egyptian churches, in order to serve as human shields in case of another attack. They held candlelight vigils outside and put crosses on their facebook pages as well.
Let's look to the last 2 weeks. A photo has been spreading all over Twitter of Egyptian Christians making a human chain to protect Muslims from police attack as they were praying in Tahrir square on Friday. On Sunday, Egyptian Muslims returned the favor, protecting them while they had prayer services. This is a great moment for Muslim-Christian unity in Egypt.
This entire thread, with one notable exception, is entirely, horribly uninformed. As the only other worthwhile poster points out, the Firesheep plugin proves that once you have the FB cookie (which can be sniffed via MITM attack or over Wifi), you can hop onto a Facebook session from any computer. Maybe not a shortcoming with the idea of login cookies, but certainly a shortcoming in Facebook's handling of them. Second, about two weeks ago FB started officially supporting an HTTPS-Always preference. There's a checkbox in Account, under Security, that forces all connections (and I do mean all, even connections to other subdomains) to use SSL. No plugin needed. As much as I enjoy Facebook, and correctly monitor both security settings AND what data I allow it to access, I'm really happy that Firesheep showed how piss-poor their security was. It gave the final push to my campaign to secure the "public" wifi hotspots our company offers to it's guests.
Poor means hoping the toothache goes away.