Jump to content

Ssl Login Trial


irokin

Recommended Posts

Members dont see this ad

nice- I see the Courts in the USA are arguing over whether the Govt can demand your encryption key from you.

 

Very dangerous road to go down with serious security ramifications. Bad idea IMO. I can see what they're trying to do but I don't think they've considered (or care about) the side effects.

 

I've just heard about a smartphone app that pretends to be a wireless router and copys all the data as it goes through, so I think this is getting to be important.

 

Yep, if you're not in control of the hardware you're connected to and you're sending passwords in the clear (not encrypted) then there's every possibility your password will be sniffed. It's not a new technique but it sounds like it's being bought down to the level of consumers now.

 

I should point out though, if you're not in control of the hardware while your password should be safe over SSL an attacker could still hijack your Rollaclub session. I could encrypt the entire site but I don't think that's necessary at this stage. There's CPU and bandwidth issues that we would probably encounter.

 

 

Hopefully I can start a bit of a trend and get some more forums to consider it.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...