Bump. I want my RFD fix at school!
-
Oct 23rd, 2007 02:57 PM #1
Security "problem" with RFD
When logging into the RFD forums, it would be very nice to submit to an SSL page, so that my authentication credentials are not sent plaintext over the internet. I use open wireless at school, so it's trivial to sniff my RFD password when I log in.
Reply With Quote
LOG IN TO THANK
No one has yet thanked kloostec for this post.
-
Sponsored Links - Join the RedFlagDeals.com community and remove this ad.
-
Nov 3rd, 2007 07:41 PM #2
Reply With Quote
LOG IN TO THANK
No one has yet thanked kloostec for this post.
-
Nov 3rd, 2007 10:28 PM #3
Just make sure your RFD password isn't the same as other, important passwords (such as online banking).
Problem solved!_______________
Toronto Maple Leafs tickets for sale. PM me for details
Reply With Quote
LOG IN TO THANK
No one has yet thanked Shaner for this post.
-
Nov 3rd, 2007 11:07 PM #4
Does your school offer VPN?
Reply With Quote
LOG IN TO THANK
No one has yet thanked Firestorm ZERO for this post.
-
Nov 3rd, 2007 11:22 PM #5
Actually I believe that the password is hashed before it is sent, so in fact nobody gets your password.
Just make sure you have javascript enabled and you're good to go!
Reply With Quote
LOG IN TO THANK
No one has yet thanked Kaitlyn for this post.
-
Nov 3rd, 2007 11:41 PM #6_______________
The silent genocide in Pakistan
Reply With Quote
LOG IN TO THANK
No one has yet thanked Rehan for this post.
-
Nov 4th, 2007 07:13 AM #7
Reply With Quote
LOG IN TO THANK
No one has yet thanked Kaitlyn for this post.
-
Nov 4th, 2007 07:54 AM #8
If you're on your laptop at school (assuming this from the "open wireless" network you mention) why not just stay logged into the forums on your computer? The cookie it stores stays alive for a pretty long time, up to one year afaik, barring any major upgrades to the forum system. Plus, you have the added benefit of the hashed password being sent from your cookie instead of the plaintext one from the login form.
If you're using a public computer, I'd suggest using a copy of Firefox Portable from a USB drive or something. That way you can keep your cookie information intact and avoid the login issue altogether similar to using your own computer.
Reply With Quote
LOG IN TO THANK
No one has yet thanked cka for this post.
-
Nov 5th, 2007 10:14 PM #9
Opera password tool thingy for the win!
_______________Resident vehicle detailing enthusiast - PM for detailing related questions
RedFlagDeals Official Detailing Thread
Reply With Quote
LOG IN TO THANK
No one has yet thanked Asad_A203 for this post.
-
Nov 6th, 2007 05:31 AM #10
Reply With Quote
LOG IN TO THANK
No one has yet thanked Kaitlyn for this post.
-
Nov 6th, 2007 01:20 PM #11
It doesn't, he doesn't know what he's talking about.
Anyhow, RFD should do this. It's not like it costs anything, since they can simply create a self-signed certificate (we don't care about real certificate authorities, since the few people who will actually use this feature on RFD will already trust this place).
OpenSSL for the win.
Reply With Quote
LOG IN TO THANK
No one has yet thanked S_G for this post.
-
Nov 6th, 2007 01:45 PM #12
I think you'd be surprised. Not everyone on this forum even has a clue what a certificate means, and through personal experience I know people get scared off when they see these popups about an untrusted site and such.
The simplest solution would be to hash the password with JS before it's sent. 99% of people on this site surely have JS enabled and they could always enable it JUST to log in if really mattered THAT much to them
Reply With Quote
LOG IN TO THANK
No one has yet thanked Kaitlyn for this post.
-
Nov 6th, 2007 09:09 PM #13
Ryan/Derek should pay for the new script protection.. it would be awesome!
Reply With Quote
LOG IN TO THANK
No one has yet thanked aimfox for this post.
-
Nov 6th, 2007 09:12 PM #14
Reply With Quote
LOG IN TO THANK
No one has yet thanked Kaitlyn for this post.
-
Nov 7th, 2007 11:00 PM #15
SSL certs are cheap (relatively speaking), so if it's more than a few hours worth of work to get the JavaScript hashing code working (I've seen examples of that with vBulletin, LiveJournal and Typo3), maybe it's easier to get a cert and be done with it? Either solution would be satisfactory, though.
And yes, my RFD password is different than my important passwords, but that's beside the point, as the password is still getting sent over the Internet plaintext...
Reply With Quote
LOG IN TO THANK
No one has yet thanked kloostec for this post.
Search Forums


