Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Sidejack Prevention

Blog post from GitHub

Post Details
Company
Date Published
Author
Ryan Tomayko
Word Count
374
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

A Firefox plugin called Firesheep has highlighted vulnerabilities in network security by enabling easy capture and exploitation of users' HTTP session cookies over insecure connections, which can lead to unauthorized account access on various services. GitHub was initially vulnerable to this type of session hijacking but has implemented a secure solution involving a second, secure cookie that is only sent over SSL requests, providing an additional layer of protection by ensuring that sidejacked session cookies cannot be used to access sensitive information. This secure cookie is a checksum of the user’s ID and password hash combined with a secret salt value, verified against subsequent SSL requests to confirm authentication. While GitHub has strengthened its defenses, the broader problem of sidejacking persists across many sites, leading to recommendations for users to encrypt all connections, with tools like SheepSafe offering solutions for secure browsing.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.