FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Technical Support and Feedback (https://www.flyertalk.com/forum/technical-support-feedback-386/)
-   -   Log-in security [and using SSL / https] (https://www.flyertalk.com/forum/technical-support-feedback/1591204-log-security-using-ssl-https.html)

techie Jul 3, 2014 11:52 am

Log-in security [and using SSL / https]
 
Hi all,

I find it to be a bit of a shocker that not only is the log-in process not done over HTTPS -- schoolboy error, if I ever saw one -- but you do a simple MD5 of the password and send it along as part of the log-in procedure in clear text. The username is also in clear text.

<deleted>

Could you please sort it out ASAP? This should really not be happening in this day and age.

IBxAnders Jul 3, 2014 12:15 pm

We don't force SSL; you are welcome to use SSL by switching over to HTTPS, you can log in via SSL.

techie Jul 3, 2014 12:24 pm

Naturally, the question is: why isn't SSL enabled by default?

IBxAnders Jul 3, 2014 12:33 pm


Originally Posted by techie (Post 23138230)
Naturally, the question is: why isn't SSL enabled by default?

When we turn on for everyone we have some complaining about slowness and that alot of "posts" / "threads" are broken or "display browser error messages". Since this site is almost all user generated content - people post non-https images and etc and depending on their browser it may display a broken image or a warning pop-up, subsequently we start getting reports that site is broken.

techie Jul 3, 2014 2:05 pm

That's fair enough. However, this does not preclude you from presenting the log-in form over a secure connection and processing the form information over HTTPS, followed by redirection back to HTTP.

P.S. The main page looks really bad when HTTPS is enforced.

techie Jul 18, 2014 7:24 am

I would consider the following to be shameless, since it has been a couple of weeks: bump.


All times are GMT -6. The time now is 8:15 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.