Log in

View Full Version : [REQUEST] Please enable SSL/HTTPs for this web site!!!



visaker
September 23rd, 2013, 04:48 PM
Is anyone following news about NSA spying here? I know it might not completely fix everything but still, just an extra layer of protection would be helpful.

Deadfreak
September 23rd, 2013, 05:03 PM
We do not host any payments on our site, so there is no need for SSL on our end. That's why we use payment processors such as PayPal, Click and Buy, and PaySafeCard, since they are the ones that provide you with that extra layer of security. HTTPs we could do later on.

visaker
September 23rd, 2013, 05:16 PM
I don't think you understand the concept of privacy, I suggest you research. This needs to be addressed asap.

Deadfreak
September 23rd, 2013, 06:49 PM
I think you do not understand what SSL is even for. SSL does not protect our server, and SSL does not protect your PC. It protects data that is being transmitted. As i said, we do not host any sensitive information. You aren't sending us your credit card/bank details, etc. All that info is going through the payment processor (their responsibility to protect you). We outsource the payments to PayPal, Click and Buy, PaySafeCard, so they are protecting you with SSL (if they use it) and we necessarily don't even need it.

visaker
September 23rd, 2013, 07:19 PM
Im very well aware of payment protection, this required by laws, but the login credentials(for this web site) sent in plain text, all users on this web site are traceable and can be hi-jacked. Very "intelligent people" might even be able to hi-jack accounts here without needing their passwords. While owner of this web site secured their money user accounts are available for spying, hi-jacking and etc. This is very legit concern and if you don't fully understand it please take it up to owner and colleagues.

It seem that implementing ssl for this web site doesn't require much effort, don't ignore it. I don't want my account to be spied on or hijacked!

Deadfreak
September 23rd, 2013, 07:39 PM
Spied on in what way? Hijacked in what way? Like i said, SSL does not protect YOU, it only protects DATA. You are better off securing your PC than worrying about a website's security. The only thing we have to worry about is exploits and any vulnerabilities (which we have taken care of, so you don't have to worry about it). As for your password, that's all secured on our server. Someone needs to find an exploit, or hack our server to even get it. The best bet is to rather hack you to get your password, which is the most common case of "hijacks" as you would say. I'm not bashing SSL in anyway, because it is great for sensitive information, but you seem to be misinformed. Simply because you see the lock on your browser, does not make you secure. Login credentials are not in plain text. They are encrypted in hash, just like any other site. Nothing is illegal on our page. If your ISP reads your data, are you scared?

P.S I would love if our site was globally activated with SSL since that way we wouldn't have to worry about any data leak if we ever asked for sensitive information. Otherwise, what i said above still stands true.

visaker
September 23rd, 2013, 08:07 PM
No, I'm not scared, its inconvenient, I can't use my smartphone to directly access this web site because even my gramma can see where I'd go on internet when I'm at her house. As soon as she knows my login, she can even google my posts here.

As far as security goes, login form of this forum transmits data in plain text, while it might be hashed, there is nothing that would stop to brute force my account and no ssl means less work for hijacker.

I don't want my gramma or anyone else trolling me for going to this web site. I understand that this is good for advertising but it doesn't mean users should be treated like crap. I'm more concerned about privacy than security, ssl is not bad thing and should not be hard to implement here.

ps im not going to explain ways to hijack accounts and spying, those are covered on google. please do your own research.

JohnnyWalker
September 23rd, 2013, 10:21 PM
You don't need data to brute force an account. Just a bit knowledge and not even SSL would save you there. Data AREN'T send in plaintext, get that into your mind.
Every data is hashed (which is obviously not plain) and if you granny could read that then you're fucked anyways. But I just doubt that.
Just another one who informed himself and some shitty pages and magazines.
Actually it's not impossible, but it's a lot of work to enable it (SSL) and telling every system to use it. ;)