Jump to content


Unsecure web pages


style="text-align: center;">  

Thread Locked

because no one has posted on it for the last 3956 days.

If you need to add something to this thread then

 

Please click the "Report " link

 

at the bottom of one of the posts.

 

If you want to post a new story then

Please

Start your own new thread

That way you will attract more attention to your story and get more visitors and more help 

 

Thanks

Recommended Posts

  • 9 months later...
Hi

 

Does anyone know who to report unsecure websites to

 

for example, a payday loan company collecting credit card details through an unsecure page?

 

thanks

You could contact the site administrator/webmaster. If it's not already at the bottom of the page you could email webmaster@.

 

You could try to manually hijack the page adding a 's' after "http". If this works you could download and install the "force https" extension for your browser.

 

Sites are not compelled to use https by default, but it would be better if they did. I'm not 100% comfortable using this forum because it doesn't use https but I have no choice.

"Ask not what your country can do for you, ask what you can do for Poundland"

Link to post
Share on other sites

I'm not 100% comfortable using this forum because it doesn't use https but I have no choice.

 

Why, this site doesn't take personal information or debit card details, it has no need to be encrypted.

Link to post
Share on other sites

Why, this site doesn't take personal information or debit card details, it has no need to be encrypted.

I disagree. Login is unencrypted here. Any 12yo can sniff my credentials over the network (and I use wireless most of the time). At least the login process should be over https. Activating https is not a big deal really and the overhead is minimal.

 

Don't forget that most people use the same password for most of their logins. Once you sniff one, you have them all.

 

I don't mind having a self-signed ssl certificate as I don't believe in signed certification.

"Ask not what your country can do for you, ask what you can do for Poundland"

Link to post
Share on other sites

Your password is encrypted, even the administrator cannot see your password.

 

As for your wireless, you should have a minimum of WEP protection set up, that's up to the user to do.

Link to post
Share on other sites

Password might be encrypted on your server but end to end transaction is in clear.

 

Wep or the more modern Wap only protect (poorly) the key transaction not the whole end to end credential transaction. And even if it did encrypt traffic, it would do so only within the boundaries of the Wlan.

"Ask not what your country can do for you, ask what you can do for Poundland"

Link to post
Share on other sites

  • Recently Browsing   0 Caggers

    • No registered users viewing this page.

  • Have we helped you ...?


×
×
  • Create New...