PDA

View Full Version : Logging in to this site



dave2010
20-04-2017, 20:00
Recently the latest versions of Firefox have been warning me of possible risks of logging in to this site. Is this specific to Firefox, or is that the only browser that actually detects a potential problem. The issue seems to relate to sending passwords over an insecure channel.

Is this something we have been living with for a while, or do I need to do something else in order to log in?

walpurgis
20-04-2017, 20:09
I've never had that. Looks like it is Firefox related.

struth
20-04-2017, 20:16
it might be the way its looking for an https instead of the more usual http. i use firefox mostly and have not had it ever.

Hudz
20-04-2017, 20:49
I also get this warning with Firefox so I just make sure that my AOS password is not used for any other sites, therefore very little risk if it is stolen.

dave2010
20-04-2017, 21:08
I've never had that. Looks like it is Firefox related.Here is the info file from Firefox - https://support.mozilla.org/en-US/kb/insecure-password-warning-firefox?as=u&utm_source=inproduct

Is it just that Firefox is taking more care of us all, and we're not actually any safer with other browsers, or is there some other technical reason and this is really Firefox specific?

struth
20-04-2017, 21:11
yeah thought it might be the https bit. We had this before. Beachwoods will maybe comment next time he is on.

dave2010
21-04-2017, 09:52
I guess many people can live with this, but people who will be particularly vulnerable will be those who use the same password for all sites, including sites particularly important to them, such as their bank account and credit card sites, and maybe other confidential sites.

Indeed it might be worth having some sites with slightly laxer security, so that we can tell that our browers are warning us correctly, otherwise if all the sites upgrade to HTTPS for password entry, then we won't know that the browsers are checking or not. :)

struth
21-04-2017, 09:59
if you have a robust password then you will have no problems i think

mikeyb
21-04-2017, 10:03
It's a definite risk to your bank balance 😁

Yomanze
21-04-2017, 13:04
if you have a robust password then you will have no problems i think
This is why Firefox is warning because password strength is irrelevant if not sent through an encrypted (HTTPS) page.

I use different passwords on forums for this reason and use huge passphrases for my sensitive logins. Consider that a password such as "ilikehifiandcheese" is far more secure than "R3!ww3?n" despite lack of special characters, uppercase and numbers due to the length.

dave2010
21-04-2017, 13:15
if you have a robust password then you will have no problems i thinkIt doesn't matter how "robust" your password is if a hacker can actually read it. There's a low probability here, as a hacker would have to intercept the data stream as the password was sent across and capture it, but there are people out there with equipment and determination to do just that. They don't even have to capture the password in a fraction of a second, but could grab a great chunk of data traffic, then analyse it later to gather passwords. They would probably use automatic tools for that. Also, while a single hacker might not be able to do very much, groups of hackers could work in collaboration.

Whether for non critical sites (I'm assuming AoS is one such - do I really care if anyone knows what CDs I like, whether I have any vinyl, what my cartridge preferences are etc.?) hackers could build up information which they would consider useful and use against me or us collectively I don't know.

struth
21-04-2017, 13:24
AOS was never set up to have https security as it didnt warrant it. Nick disabled SSL / HTTPS. Connections to The Art of Sound should always be via http://theartofsound.net. trying to use https should default you back to http. maybe thats why your getting the warning

dave2010
21-04-2017, 13:43
AOS was never set up to have https security as it didnt warrant it. Nick disabled SSL / HTTPS. Connections to The Art of Sound should always be via http://theartofsound.net. trying to use https should default you back to http. maybe thats why your getting the warningIt's possible to have ssl/https connections only for the login phase I think. Given that most of the traffic can be visible to anyone who wants to intercept it, the main concern must be if users are likely to use similar passwords for different sites.

dave2010
21-04-2017, 13:51
AOS was never set up to have https security as it didnt warrant it. Nick disabled SSL / HTTPS. Connections to The Art of Sound should always be via http://theartofsound.net. trying to use https should default you back to http. maybe thats why your [sic] getting the warningNope. Clicking on the little 'i' in the circle to the left of the URL window shows that it is the http:// variant of AoS (i.e. the only variant). It's a recent Firefox feature I think since version 51. There is a drop down menu with more options and info.

Beechwoods
21-04-2017, 19:56
AOS was never set up to have https security as it didnt warrant it. Nick disabled SSL / HTTPS. Connections to The Art of Sound should always be via http://theartofsound.net. trying to use https should default you back to http. maybe thats why your getting the warning

Grant is right. AOS is currently not configured to work over HTTPS / SSL. Out of the box, vBulletin was historically a bugger to get working over HTTPS. This is now less of an issue, but it still requires additional (expensive) certificates, and since we're not running ecommerce (an online shop) or carrying out banking or other stuff which requires encrypted connections between you and the site, it's not something we've pursued.

There is a movement towards forcing sites to use HTTPS when requiring passwords to log-on. I think this is fair enough for sites where the risk from someone 'hacking' your connection and intercepting your traffic (like with a shop, or bank), but for a forum like this? It's not something I'd worry about.

If the message bugs you and you still want to use Firefox, this link tells you how to disable the warning:

http://www.trishtech.com/2017/03/disable-insecure-login-field-warning-in-firefox/

If you do disable the warning, and even if you don't, I recommend using the HTTPS Everywhere (https://www.eff.org/https-everywhere) plugin from the EFF. This ensures that you always connect to Secure Sites via HTTPS if HTTPS is supported. If a site has enabled HTTPS it's because they think you need it, and in that case, you're better with it than not :)