![]() |
#1 |
friendly lurker
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 896
Karma: 2436026
Join Date: Apr 2007
Location: US
Device: Kindle, nook, Apple and Kobo
|
Kindle cookies?
I was reading about Firesheep (http://www.pcworld.com/businesscente..._spx_h_cbintro) and it got me wondering how safe it is to connect a Kindle to Amazon over a public Wifi connection.
Perhaps there are no cookies passed since every Kindle is known to Amazon (assuming they each have a unique identifier burned in at the factory), but if you use the browser to go to other sites could Firesheep work on a Kindle session? I lack technological sophistication. Maybe this question is nonsense. I was just wondering how comfortable to get on public Wifi services with a Kindle or iPad. |
![]() |
![]() |
![]() |
#2 |
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 154
Karma: 1310
Join Date: Dec 2009
Device: kindle DX Graphite
|
Kindle 3 using wifi... unsafe obviously... if you go through https, it should be safer
the kindle 3 HAS cookies stored... dont understand ur question about cookies passed |
![]() |
![]() |
Advert | |
|
![]() |
#3 | |
friendly lurker
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 896
Karma: 2436026
Join Date: Apr 2007
Location: US
Device: Kindle, nook, Apple and Kobo
|
Quote:
http://www.pcworld.com/businesscente...tml?tk=mod_rel It seems like the way Firesheep works is to snag a cookie from a site you access from a public access point--hopefully not your bank--and then the black hat uses it later to spoof your identity at the site that sent you the cookie. So I wondered if the Kindle receives cookies and stores them to authenticate you at later visits. I was thinking that maybe Amazon burned all but the IP address of the Kindle into the CPU or something (at the factory) so they didn't need to pass a cookie that could be used to access your actual account. Last edited by 6charlong; 11-11-2010 at 10:38 PM. |
|
![]() |
![]() |
![]() |
#4 |
Junior Member
![]() Posts: 4
Karma: 10
Join Date: Nov 2010
Device: Kindle 3 WiFi+3G
|
It's possible that the Kindle does not use cookies for access to the store, because it's not accessed through the web browser and may therefore use some other method of authentication which Firesheep does not intercept. However, even if it transmits another unique ID that Firesheep can't currently capture, it would be possible to intercept that on an unsecured network if it's transmitted in the clear/unencrypted. There's nothing particularly novel or special about Firesheep - packet sniffing isn't some new exploit, it's unavoidable with an unencrypted connection. It's just a packaged-up tool to use packet sniffing to specifically steal cookies.
Hopefully the Kindle encrypts all its ID/login-related communication with Amazon; if that's the case then none of this would be a concern. |
![]() |
![]() |
![]() |
#5 |
eBook Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 85,544
Karma: 93383099
Join Date: Nov 2006
Location: UK
Device: Kindle Oasis 2, iPad Pro 10.5", iPhone 6
|
|
![]() |
![]() |
Advert | |
|
![]() |
#6 | |
Junior Member
![]() Posts: 4
Karma: 10
Join Date: Nov 2010
Device: Kindle 3 WiFi+3G
|
Quote:
Of course, it could pass some other kind of authentication over HTTP rather than using cookies, I suppose. |
|
![]() |
![]() |
![]() |
#7 |
eBook Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 85,544
Karma: 93383099
Join Date: Nov 2006
Location: UK
Device: Kindle Oasis 2, iPad Pro 10.5", iPhone 6
|
Sorry, I should have elaborated. You are correct that the Kindle store is not accessed via the "standard" Kindle web browser interface, but I am 99.9% certain that it is being displayed as web pages, and displayed using exactly the same HTML display control that the "standalone" web browser uses.
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Transfer Kindle books from Kindle PC to Kindle 3 | ppearce | Amazon Kindle | 15 | 09-16-2010 05:11 PM |
Font hacks for the Kindle 2, Kindle International and Kindle DX | edge777 | Kindle Developer's Corner | 17 | 04-30-2010 04:11 PM |
$0.01 in Kindle Store: Interactive Sudoku for Kindle 2 and Kindle DX - Volume 1 | Xia | Deals and Resources (No Self-Promotion or Affiliate Links) | 2 | 11-07-2009 10:06 AM |
Firefox extension: View Cookies | Colin Dunstan | Lounge | 0 | 10-25-2004 08:10 PM |