• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

HTTPS on the ContractorUK

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #21
    I believe that Admin is already looking at this aspect of the forum.
    "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
    - Voltaire/Benjamin Franklin/Anne Frank...

    Comment


      #22
      Originally posted by cojak View Post
      And even dumber if you don’t have a burner email account...
      Ah so that's why we, some people have sockies.
      Originally posted by Stevie Wonder Boy
      I can't see any way to do it can you please advise?

      I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

      Comment


        #23
        Originally posted by woohoo View Post
        that's the attitude. You don't want to make any effort to protect your members.
        It's a risk vs reward situation, if you are protecting PCI data and at risk of millions of pounds in fines the reward for activating HTTPS is high, if the only think to protect are email addresses and password, it makes greater sense to educate the denizens in good practise when it comes to password management as HTTPS in itself is not 100% secure
        Last edited by SimonMac; 27 November 2017, 08:32.
        Originally posted by Stevie Wonder Boy
        I can't see any way to do it can you please advise?

        I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

        Comment


          #24
          Originally posted by SimonMac View Post
          It's a risk vs reward situation, if you are protecting PCI data and at risk of millions of pounds in fines the reward for activating HTTPS is high, if the only think to protect are email addresses and password, it makes greater sense to educate the denizens in good practise when it comes to password management as HTTPS in itself is not 100% secure
          I don't see much in the way of education going on.

          Https is a lot more secure than Http. It just a basic thing you should do.

          It's not just about login/passwords, it's also about the topics you are reading and posting on being visible.

          Comment


            #25
            Originally posted by woohoo View Post
            I don't see much in the way of education going on.

            Https is a lot more secure than Http. It just a basic thing you should do.

            It's not just about login/passwords, it's also about the topics you are reading and posting on being visible.
            They are via Google.
            "You’re just a bad memory who doesn’t know when to go away" JR

            Comment


              #26
              Originally posted by SueEllen View Post
              They are via Google.
              If you are at a clients site. You decide to read or post something negative about the client. The client could be monitoring the network and will see the post in clear text. Just an example but you get my meaning.

              Comment


                #27
                Originally posted by SimonMac View Post
                It's a risk vs reward situation, if you are protecting PCI data and at risk of millions of pounds in fines the reward for activating HTTPS is high, if the only think to protect are email addresses and password, it makes greater sense to educate the denizens in good practise when it comes to password management as HTTPS in itself is not 100% secure
                Could be wrong, but my own experience with BBS software, phpBB, is that the passwords are encrypted by default. So even those with top tier admin rights can't see the passwords. I'm guessing the same applies here too.
                Public Service Posting by the BBC - Bloggs Bulls**t Corp.
                Officially CUK certified - Thick as f**k.

                Comment


                  #28
                  Originally posted by Fred Bloggs View Post
                  Could be wrong, but my own experience with BBS software, phpBB, is that the passwords are encrypted by default. So even those with top tier admin rights can't see the passwords. I'm guessing the same applies here too.
                  CUK, encrypts the password using md5, which is then sent in clear text across the interweb. It's trivial to decrypt the password.

                  Posts, urls etc are all visible in plain text.

                  Comment


                    #29
                    Originally posted by woohoo View Post
                    Posts, urls etc are all visible in plain text.
                    They are also in plain sight.
                    Best Forum Advisor 2014
                    Work in the public sector? You can read my FAQ here
                    Click here to get 15% off your first year's IPSE membership

                    Comment


                      #30
                      Originally posted by TheFaQQer View Post
                      They are also in plain sight.
                      If you mean someone can see your monitor whilst posting, yes. Plain sight.

                      However, if you mean it's just on google like Sue posted then the client example. If you are at a clients site, you post negative things or read dodgy stuff on CUK or any site without SSL, assume your client is looking over your shoulder.

                      I think I'm like a dog with a bone, it doesn't affect me, it's the people that don't understand this that it affects. So, I think Cojak said admin is looking at it and he will know more about his own site than I do.

                      Comment

                      Working...
                      X