Open Side Menu Go to the Top
Register
Does this site really not use https, and uses plaintext passwords? Does this site really not use https, and uses plaintext passwords?

05-13-2012 , 12:51 PM
Everyone who says https is too resource intensive, thats not quite true. Yes, https is more resource intensive than http, and yes, 5 years ago, it was a huge overhead, but now days, https adds a minimum overhead.

There is no reason for https not to be turned on, and not implementing it is a HUGE security floor imo.
Does this site really not use https, and uses plaintext passwords? Quote
05-13-2012 , 03:19 PM
Quote:
Originally Posted by MrWooster
Everyone who says https is too resource intensive, thats not quite true. Yes, https is more resource intensive than http, and yes, 5 years ago, it was a huge overhead, but now days, https adds a minimum overhead.

There is no reason for https not to be turned on, and not implementing it is a HUGE security floor imo.
We already know they've been struggling with inadequate capacity (I think I read that somewhere). Dunno where the bottleneck is, however. If they're struggling with the front-end side of it facing the browsers, adding HTTPS may make the situation worse. On the other hand, if they're having backend DB issues, say, they may have gobs of capacity and won't notice the SSL overhead.

But if they hired a super-high-end security firm to come in and make sure everything was safe and secure, you'd kinda think "ENABLE HTTPS!!!" woulda been pretty high on said company's list of recommendations.
Does this site really not use https, and uses plaintext passwords? Quote
05-13-2012 , 11:04 PM
Cookie sniffing is a big deal. It's not enough just to do https logins, not at all.
Does this site really not use https, and uses plaintext passwords? Quote
05-13-2012 , 11:46 PM
Quote:
Originally Posted by Neil S
Cookie sniffing is a big deal. It's not enough just to do https logins, not at all.
Cookie sniffing is a big deal but it's a different problem than the problem of stealing passwords.

Implementing full https would be great but doing it just for logins would be better than what we have now and would be a very small increase in resource consumption.
Does this site really not use https, and uses plaintext passwords? Quote
05-13-2012 , 11:56 PM
Quote:
Originally Posted by pvn
Cookie sniffing is a big deal but it's a different problem than the problem of stealing passwords.

Implementing full https would be great but doing it just for logins would be better than what we have now and would be a very small increase in resource consumption.
Is the goal to stop password sniffing or to prevent account hijacks?
Does this site really not use https, and uses plaintext passwords? Quote
05-15-2012 , 03:30 PM
cookie sniffing sounds like a weird fetish.
Does this site really not use https, and uses plaintext passwords? Quote
05-15-2012 , 08:45 PM
Quote:
Originally Posted by Count Chocula
Wookie sniffing sounds like a weird fetish.
Fixed.
Does this site really not use https, and uses plaintext passwords? Quote
05-15-2012 , 09:48 PM
Quote:
Originally Posted by Gin 'n Tonic
Fixed.
wat

Nothing weird about that IMO.
Does this site really not use https, and uses plaintext passwords? Quote
05-15-2012 , 10:25 PM
I bent my wookiee.
Does this site really not use https, and uses plaintext passwords? Quote
05-17-2012 , 01:06 PM
Quote:
Originally Posted by pvn
Cookie sniffing is a big deal but it's a different problem than the problem of stealing passwords.

Implementing full https would be great but doing it just for logins would be better than what we have now and would be a very small increase in resource consumption.
Basically impossible/extremely difficult to blanket install https on a website like this that links to so much external content as it will throw up tons of security messages when someone posts an image on a different domain etc.

Doing it on the login/registration pages is a good idea and easy to do though.
Does this site really not use https, and uses plaintext passwords? Quote
05-17-2012 , 07:26 PM
Quote:
Originally Posted by Gullanian
Basically impossible/extremely difficult to blanket install https on a website like this that links to so much external content as it will throw up tons of security messages when someone posts an image on a different domain etc.

Doing it on the login/registration pages is a good idea and easy to do though.
Ehh, it's security theater.
Does this site really not use https, and uses plaintext passwords? Quote
10-22-2015 , 08:16 PM
You cannot be serious. How old is this vbulletin software as well? Someone could probably just google a vbulletin exploit and there's a good chance it will work.

Unreal, lol.
Does this site really not use https, and uses plaintext passwords? Quote
10-22-2015 , 08:40 PM
You tell 'em.
Does this site really not use https, and uses plaintext passwords? Quote
10-22-2015 , 09:49 PM
I have been assured that this is nothing to worry about. Also that the sever load for encryption requires more hamsters than 2+2 can afford.

Last edited by zikzak; 10-22-2015 at 09:49 PM. Reason: it's not like the site has ever been hacked or anything
Does this site really not use https, and uses plaintext passwords? Quote
10-27-2015 , 03:10 AM
I can explain it, it's not actually a porn
Does this site really not use https, and uses plaintext passwords? Quote
10-27-2015 , 04:37 AM
I heard the pas words have been encrypted using a banana and 2 large Chinese vases
Does this site really not use https, and uses plaintext passwords? Quote
11-03-2015 , 05:15 AM
April, 2012.
Does this site really not use https, and uses plaintext passwords? Quote
11-03-2015 , 06:29 AM
Here's your money back
Does this site really not use https, and uses plaintext passwords? Quote
11-04-2015 , 02:10 PM
why does OP think they use plaintext?

wireshark seems to think my password is 3abaf9cb25496efb9f918ba63135249c, which I assure you it isn't.
Does this site really not use https, and uses plaintext passwords? Quote
11-04-2015 , 02:43 PM
Quote:
Originally Posted by Roonil Wazlib
wireshark seems to think my password is 3abaf9cb25496efb9f918ba63135249c, which I assure you it isn't.
Really?

Mine is.
Does this site really not use https, and uses plaintext passwords? Quote
11-04-2015 , 02:57 PM
What a crazy coincidence!
Does this site really not use https, and uses plaintext passwords? Quote
11-04-2015 , 07:08 PM
Quote:
Originally Posted by Roonil Wazlib
why does OP think they use plaintext?

wireshark seems to think my password is 3abaf9cb25496efb9f918ba63135249c, which I assure you it isn't.
Obviously your password is :ºùË%InûŸ‘‹¦15$œ
Does this site really not use https, and uses plaintext passwords? Quote
11-04-2015 , 09:28 PM
Ssshhhhhhhh
Does this site really not use https, and uses plaintext passwords? Quote
11-05-2015 , 01:09 AM
Mine shows

7c6a180b36896a0a8c02787eeafb0e4c

hmmm
Does this site really not use https, and uses plaintext passwords? Quote
11-09-2015 , 04:15 AM
****ingfd trolle
Does this site really not use https, and uses plaintext passwords? Quote

      
m