Equipped To Survive Equipped To Survive® Presents
The Survival Forum
Where do you want to go on ETS?

Topic Options
#284695 - 06/03/17 03:57 PM Security issue with this website?
Bingley Offline
Veteran

Registered: 02/27/08
Posts: 1580
Firefox warns me about logging in to this forum, saying it's insecure. I get the "slash through the lock" icon, and when I click for more information, this is what I got --

https://support.mozilla.org/en-US/kb/insecure-password-warning-firefox

I don't know how to alert you guys without logging in, so here I am. Do we have a security issue on this forum?

Top
#284698 - 06/03/17 08:22 PM Re: Security issue with this website? [Re: Bingley]
chaosmagnet Offline
Sheriff
Carpal Tunnel

Registered: 12/03/09
Posts: 3842
Loc: USA
Thank you for bringing this up, Bingley.

The forum website is not secured with encryption, so a bad actor who had access to your network, the network the site is hosted on, or (less likely) any network between the two could capture the packets containing your username and password in plaintext, and steal your account.

I'll see what Blast and Doug would like to do about it.


In the meantime, here are two simple security tips that you should follow wherever you go.

1) Do not reuse passwords

One of the most common ways accounts are compromised is when one website has a security breach of some kind, and the users use the same password on other sites. The bad guys will take the credentials they stole and try them everywhere else.

Don't ever do this. Most particularly don't ever reuse a password on a website that has critical information on it, such as anything to do with your financial life. To be clear, that means that once you use a password anywhere, you don't ever use the same password again, anywhere.

2) Don't use insecure wireless networks

Don't use wireless networks that are unencrypted or have weak security to login anywhere. It's trivially easy to capture packets on these networks, and your login credentials can be easily stolen.


Neither of these security tips are perfect or foolproof, but they're easy ways to make it harder for the bad guys to do bad things to you.


chaosmagnet

Top
#284724 - 06/07/17 01:45 PM Re: Security issue with this website? [Re: chaosmagnet]
haertig Offline
Pooh-Bah

Registered: 03/13/05
Posts: 2322
Loc: Colorado
Firefox now complains about anything that is not HTTPS, with varying degrees of alarmism. Try going to something that actually IS https, but uses a self-signed certificate (free) rather than a paid certificate from some place like Verisign, and boy will Firefox complain. So will Chrome. You'd think the whole world was on fire!

Note: Most public websites don't use self-signed certificates, but many private ones do. I've got a couple HTTPS websites set up at home for my personal cloud service and backup service. They are perfectly secure with encryption and all, but I don't need to pay Verisign to prove to me that the personal websites that I own are indeed owned by me (I already know that!) But Firefox screams about it like a scalded ape. Chrome does too. But public websites are different. Those have many different users and those users rightfully might want to know that their target website is indeed where they thought they were going. Not a big deal for some place like Equipped To Survive (who would want to spoof this website, and why?) But something like a banks website is a whole different ballgame.

I'm sure Verisign, et.al., paid good money to Firefox to have it scream so loudly to coerce people to use Verisign's paid signing service.

Top
#284735 - 06/07/17 11:25 PM Re: Security issue with this website? [Re: Bingley]
chaosmagnet Offline
Sheriff
Carpal Tunnel

Registered: 12/03/09
Posts: 3842
Loc: USA
We are working on a plan. Please stay tuned.


chaosmagnet

Top



Moderator:  Alan_Romania, Blast, chaosmagnet, cliff 
December
Su M Tu W Th F Sa
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31
Who's Online
0 registered (), 725 Guests and 1 Spider online.
Key: Admin, Global Mod, Mod
Newest Members
Aaron_Guinn, israfaceVity, Explorer9, GallenR, Jeebo
5370 Registered Users
Newest Posts
Missing Hiker Found After 50 Days
by Ren
Yesterday at 02:24 PM
Leather Work Gloves
by KenK
11/24/24 06:43 PM
Satellite texting via iPhone, 911 via Pixel
by Ren
11/05/24 03:30 PM
Emergency Toilets for Obese People
by adam2
11/04/24 06:59 PM
Newest Images
Tiny knife / wrench
Handmade knives
2"x2" Glass Signal Mirror, Retroreflective Mesh
Trade School Tool Kit
My Pocket Kit
Glossary
Test

WARNING & DISCLAIMER: SELECT AND USE OUTDOORS AND SURVIVAL EQUIPMENT, SUPPLIES AND TECHNIQUES AT YOUR OWN RISK. Information posted on this forum is not reviewed for accuracy and may not be reliable, use at your own risk. Please review the full WARNING & DISCLAIMER about information on this site.