Why no HTTPS?

Derstn

Member
Joined
Dec 12, 2016
Threads
1
Messages
28
Reaction score
9
Location
Chattanooga, TN
Vehicle(s)
'16 Civic EX
Why is this NOT using SSL in this day and age? There are user credentials being passed in plain text since the connection to the site is not encrypted.

Please tell me that the passwords are salted and only hashes are stored in the DB.
Sponsored

 

MickeyDubs

Senior Member
Joined
Jun 2, 2016
Threads
5
Messages
72
Reaction score
37
Location
New Jersey
Vehicle(s)
2017 Golf R
Why is this NOT using SSL in this day and age? There are user credentials being passed in plain text since the connection to the site is not encrypted.

Please tell me that the passwords are salted and only hashes are stored in the DB.
SSL certification costs money...

All you're sending is your password for this website. Unless you use the same password on car forums as your bank account / credit card accounts then the password alone doesn't mean anything...

And even then, someone needs to be monitoring your internet traffic- which, if that's the case, I doubt this forum is the most of your worries.
 

chokesmaster

Senior Member
Joined
Sep 3, 2016
Threads
7
Messages
169
Reaction score
91
Location
Sherbrooke Quebec, Canada
Vehicle(s)
Honda Civic LX Manual 2016
Country flag
SSL certification costs money...

All you're sending is your password for this website. Unless you use the same password on car forums as your bank account / credit card accounts then the password alone doesn't mean anything...

And even then, someone needs to be monitoring your internet traffic- which, if that's the case, I doubt this forum is the most of your worries.
Wildcard SSL certificates are 60$/year so it is not expensive at all considering the revenue this site can have. It's just a bit trickier to setup on a forum like this. But that should not keep the admin to enable SSL.
 
OP
OP
Derstn

Derstn

Member
Joined
Dec 12, 2016
Threads
1
Messages
28
Reaction score
9
Location
Chattanooga, TN
Vehicle(s)
'16 Civic EX
SSL certification costs money...

All you're sending is your password for this website. Unless you use the same password on car forums as your bank account / credit card accounts then the password alone doesn't mean anything...

And even then, someone needs to be monitoring your internet traffic- which, if that's the case, I doubt this forum is the most of your worries.
The cost for a single domain cert is next to nothing. Wildcards are expensive. The issue comes from passing credentials at all in plain text. It's a best practice to encrypt any authentication requests.

Really, it's not just about the password I use for this site, it's about the principle of encrypting authentication period. It's becoming an industry standard and should be implemented as soon as a web host is brought up.
 
OP
OP
Derstn

Derstn

Member
Joined
Dec 12, 2016
Threads
1
Messages
28
Reaction score
9
Location
Chattanooga, TN
Vehicle(s)
'16 Civic EX
Wildcard SSL certificates are 60$/year so it is not expensive at all considering the revenue this site can have. It's just a bit trickier to setup on a forum like this. But that should not keep the admin to enable SSL.
There aren't even subdomains. It's one domain cert, which can be had for 10 bucks a year. I'm sure the ads on every page have covered that this week alone.
 

Boz

Senior Member
Joined
Feb 3, 2016
Threads
3
Messages
515
Reaction score
179
Location
NW Ohio
Vehicle(s)
2016 Honda Civic EX Sedan - Modern Steel Metalic / Black
Country flag
Hmmm...

Now I have an excuse if I start posting really stupid things here. It wasn't me...somebody decided to hack an internet forum and steal my password!

Maybe I'm not even posting this message!? Or AM I!? Who knows!? ;) :)
Sponsored

 


 


Top