A one-tap-wonder app called FaceNiff, a wicked mobile cousin of Firesheep, could allow even a clueless noob with a rooted Android smartphone to hack Facebook, YouTube, and Twitter over Wi-Fi. Stealing cookies to potentially steal users’ credentials just got so easy and portable that loony stalkers are probably jumping for joy. Picture this mobile-type scenario, as a person with a rooted Android smartphone casually strolls by a Starbucks, he or she taps once on a new app, and whammo, hops on and takes over Facebook profiles.Like a wicked mobile cousin of Firesheep, FaceNiff could allow even a clueless noob to hack Facebook over Wi-FI networks. The hacking app requires root access on Android phones. FaceNiff allows users to sniff and intercept web sessions for Facebook, Twitter, YouTube, Amazon, and Nasza-Klasa (a Polish site). Unlike Firesheep, the FaceNiff app listens in on wireless networks encrypted with WPA and WPA2 (WEP too) so that with one tap and within seconds, users can hijack the account types supported.Not that you intend to try out FaceNiff, but you can’t hijack more than three profiles. However, FaceNiff app developer Bartosz Ponurkiewicz says more sites for hopping onto user accounts will soon be supported. He noted if you want to hijack more than three profiles with FaceNiff, there will be an option to pay and unlock the code.FaceNiff has been confirmed to work on rooted mobile phones: HTC Desire CM7, original Droid/Milestone CM7, SE Xperia X10, Samsung Galaxy S, Nexus 1 CM7, HTC HD2, LG Swift 2X, LG Optimus black (original ROM), LG Optimus 3D (original ROM), and Samsung Infuse. As a portable sniff and snoop, FaceNiff presents yet another possible assault on privacy and security. Imagine how happy this might make off-their-rocker-stalkers, cause it’s not just for public wireless networks. Depending how you manage your wireless network at home, someone could park outside or walk by your house and FaceNiff you.This one-tap-wonder app again underscores the importance of using HTTPS. If you have not done so, you can tweak your Facebook and Twitter settings to always enable HTTPS. Or use the EFF’s Firefox add-on HTTPS Everywhere or another addon of your choosing to force SSL. HTTPS is your friend. It is way past time to start applying major public pressure in order to force sites to use HTTPS. Or perhaps time to get serious about security and use a VPN; stay under 100MB and this one is free, or you might want to search for other free VPN services to protect your privacy. While we are on the subject of Androids and apps, Lookout Mobile Security reported finding 26 malware-laced applications in the official Android Market. The smartphone security firm said the infected apps are a “stripped down version of DroidDream” and were probably maliciously crafted by the same developers. The new malware is being called “Droid Dream Light” (DDLight). Malware in the tainted apps can be activated by an incoming call, meaning users do not actually have to launch the app to trigger it.Anyone who downloaded an app on Lookout’s list could have their personal information compromised. It is suspected that between 30,000 and 120,000 users were affected by DroidDreamLight.Like this? Here’s more posts:PBS hacked by LulzSec: Lulz Boat Sailed, PBS FailedIE Flaw Could Allow Hackers Access to your Facebook, Gmail, Twitter Accounts‘Secret Law’ of Patriot Act: Geolocation Tracking & Domestic Spying on Steroids?Thanks to ID thieves, your child may have more debt than youHaving private parts is not probable cause for TSA to grope or body scan youFBI: Surveillance “going dark” or obsessed with porn and doing a poor job?Ridiculous DHS list: You might be a domestic terrorist if…Former FBI Agent Turned ACLU Attorney: Feds Routinely Spy on CitizensPatching Windows is a major time sink for IT departmentsFollow me on Twitter @PrivacyFanatic Related content news Dow Jones watchlist of high-risk businesses, people found on unsecured database A Dow Jones watchlist of 2.4 million at-risk businesses, politicians, and individuals was left unprotected on public cloud server. By Ms. Smith Feb 28, 2019 4 mins Data Breach Hacking Security news Ransomware attacks hit Florida ISP, Australian cardiology group Ransomware attacks might be on the decline, but that doesn't mean we don't have new victims. A Florida ISP and an Australian cardiology group were hit recently. By Ms. Smith Feb 27, 2019 4 mins Ransomware Security news Bare-metal cloud servers vulnerable to Cloudborne flaw Researchers warn that firmware backdoors planted on bare-metal cloud servers could later be exploited to brick a different customer’s server, to steal their data, or for ransomware attacks. By Ms. Smith Feb 26, 2019 3 mins Cloud Computing Security news Meet the man-in-the-room attack: Hackers can invisibly eavesdrop on Bigscreen VR users Flaws in Bigscreen could allow 'invisible Peeping Tom' hackers to eavesdrop on Bigscreen VR users, to discreetly deliver malware payloads, to completely control victims' computers and even to start a worm infection spreading through VR By Ms. Smith Feb 21, 2019 4 mins Hacking Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe