Re: [Full-disclosure] The Cookie Tools v0.3 -- first public release

2007-12-10 Thread coderman
On Dec 10, 2007 5:45 AM, michele dallachiesa <[EMAIL PROTECTED]> wrote: > ... > why HTTPS is not the default in this type of services? see http://www.kb.cert.org/vuls/id/466433 the big web service providers don't care about your privacy or security. it costs too much, and your commodity eyeballs

Re: [Full-disclosure] The Cookie Tools v0.3 -- first public release

2007-12-10 Thread Jason
Andrew Farmer wrote: > On 10 Dec 07, at 05:45, michele dallachiesa wrote: >> why HTTPS is not the default in this type of services? this is a big >> silent hole. maybe, today is less silent :) > > The short version is "because hosting things with SSL is still hard". > > There's a few things whi

Re: [Full-disclosure] The Cookie Tools v0.3 -- first public release

2007-12-10 Thread Andrew Farmer
On 10 Dec 07, at 05:45, michele dallachiesa wrote: > why HTTPS is not the default in this type of services? this is a big > silent hole. maybe, today is less silent :) The short version is "because hosting things with SSL is still hard". There's a few things which are significantly holding back t

[Full-disclosure] The Cookie Tools v0.3 -- first public release

2007-12-10 Thread michele dallachiesa
hi, I would like to announce you the first public release of The Cookie Tools project! included tools: ** cookiesniffer ** cookiesniffer is a simple and powerful cookie sniffer that recognizes (through heuristics) and reconstructs (through libnids) new and existing HTTP connections, parsing any v