logo

The Web Has Still Not Switched To SSL-only

ID: c7fc9f46-c01c-5ff5-b311-e174473b047c

STIX ID: report--c7fc9f46-c01c-5ff5-b311-e174473b047c

Feed Name: Zscaler Security Research Blog

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This 2010 analysis explains how the release of Firesheep highlighted risks from non-HTTPS web traffic and insecure cookie handling that enable session hijacking. It criticizes Facebook's mixed HTTP/HTTPS cookie usage and app incompatibilities, praises Google+ for HTTPS-only design, warns about mobile apps sending credentials in plaintext, and urges HTTPS-by-default (including securing cookies) for all authenticated web traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.