Page 2 of 2 FirstFirst 12
Results 11 to 17 of 17

Thread: Security? Even for login, no https://ubuntuformums.org??

  1. #11
    Join Date
    Aug 2007
    Location
    Manchester, UK
    Beans
    10,285
    Distro
    Ubuntu

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by rajeev1204 View Post
    Are you telling me that my password is visible to admins here ?
    No, we cannot view any passwords

  2. #12
    Join Date
    Oct 2005
    Beans
    87
    Distro
    Kubuntu 13.04 Raring Ringtail

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by Joeb454 View Post
    No, we cannot view any passwords
    But the sysadmins of the servers that the forums live on could, if they so choose

  3. #13
    Join Date
    Mar 2007
    Location
    Portsmouth, UK
    Beans
    Hidden!
    Distro
    Ubuntu 11.10 Oneiric Ocelot

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by robsoles View Post
    Look: http://www.vbulletin.org/forum/showthread.php?t=135864

    If a valid SSL certificate is acquired and the web-server is configured to serve the site in HTTPS (on port 443) while HTTP is left on then that *should* allow users to choose to access the site in 'clear text' or with 'decent encryption' pretty much regardless of the script (or other sources) of the site.

    Valid SSL certificate is probably the real tumbler. expensive buggers - I for one would gladly tell my browser to accept an unsigned certificate from ubuntuforums.org but to the masses that 'unsigned/invalid' certificate message is a killer.
    Single-domain certs are quite cheap.

  4. #14
    Join Date
    Jan 2010
    Location
    opposing reality (VIC AU)
    Beans
    990
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by TheSqueak View Post
    But the sysadmins of the servers that the forums live on could, if they so choose
    Passwords are encrypted where they 'live'.
    NEED HELP? | [SOLVED] | MS hide
    A little nonsense now and then...
    .
    If this is a game thread and you are going to post I hope you have read the Original Post.

  5. #15
    Join Date
    Oct 2005
    Beans
    87
    Distro
    Kubuntu 13.04 Raring Ringtail

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by robsoles View Post
    Passwords are encrypted where they 'live'.
    That may be true, but if they're transmitted in the clear then anyone who has ever used snoop, or tcpdump, or any of a number of programs, can get them.

  6. #16
    Join Date
    Jan 2010
    Location
    opposing reality (VIC AU)
    Beans
    990
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Security? Even for login, no https://ubuntuformums.org??

    that is the concern the OP had for this thread.

    The administrators of UF have plenty on their plates, right now, without us starting some sort of rally about this.

    HTTPS shouldn't add to the issues the site is experiencing, the added "overheads" are slightly bigger for the client for instance (if I understood that lesson). But it would be something Canonical would have to be agreeable about and approaching them for more annual or bi-annual expenditure (pretty sure cert. authority is "rented") straight after the expenditure of these new servers, we are told will be implemented soon, probably wouldn't meet a warm reception.

    I think it would be very professional of ubuntuforums.org to get a certificate and redirect all http requests to https but it won't stop me logging in and posting here if they never can/do. Anyway, as stated earlier in thread, if people are concerned about coming up with a 'throwaway' password to transmit in clear-text then they could use a launchpad id.
    NEED HELP? | [SOLVED] | MS hide
    A little nonsense now and then...
    .
    If this is a game thread and you are going to post I hope you have read the Original Post.

  7. #17
    Join Date
    Mar 2006
    Location
    Kitakyushu Japan
    Beans
    9,361
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: Security? Even for login, no https://ubuntuformums.org??

    Quote Originally Posted by robsoles View Post
    that is the concern the OP had for this thread.

    The administrators of UF have plenty on their plates, right now, without us starting some sort of rally about this.
    That, and if you have a launchpad ID, you can already log into the forums over SSL. Being able to log into the forums over SSL was one of the specific reasons for writing the Launchpad mod for the forums.
    Last edited by dmizer; January 26th, 2011 at 02:55 PM.

Page 2 of 2 FirstFirst 12

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •