Author
|
Topic: site not secure
|
|
|
|
Mathew James
Jedi Master Film Handler
Posts: 740
From: Hamilton, Ontario, Canada
Registered: Dec 2014
|
posted April 15, 2019 09:49 PM
Jim, 1. You are correct that this site is not using encryption. So...When you log into this site, your username and password is not encrypted currently under the site setup using the http: protocol, meaning if someone 'rogue' were using exploitation tools, they can see/capture data and decrypt it thus revealing your username or password, which they could then use to log into the site. Once in the site, they could look at your PM, change things in your profile, etc... On many many forums, for many many years, their was no SSL secure protocol one could use to encrypt the site data as it was transferred...we 'admins' dealt with the 'rogues' in the same way we do now...We kick them off once discovered. You can normally discover and ban IP addresses etc.. Trust me, these guys want banking info type sites, not film forums! On our end(as users), some rules can be followed to help alleviate any heart palpitations occurring from this revelation of fact... Such as, Do not send PERSONAL BANKING info using PM, or delete PM's as a practice so if someone were to log in, they wouldn't see anything. Really, we shouldn't have any super sensitive info online anyways!
Now, the next question may be, why do our admins not just secure the site? Well, I can tell you from my own experience as a forum admin, for many years i didn't because a) i didn't have any issue or reason to, and b)the ripoff cost to pay for an SSL is stupid and unnecessarily expensive. What i did rather is moved my forums to a host that includes this(SSL) at their expense automatically in the package, not mine. For example hostpapa is one that includes, so my forums are now https:// automatically now. I hope this helps explain a bit and gives some level of comfort. Cheers. [ April 16, 2019, 09:30 AM: Message edited by: Mathew James ]
-------------------- -- Cheers, Matt 📽
| IP: Logged
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|