Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Internet Gambling > Internet Gambling
FAQ Community Calendar Today's Posts Search

View Poll Results: SB unraised pot, 72s
4-1 3 14.29%
5-1 3 14.29%
6-1 2 9.52%
7-1 5 23.81%
8-1 8 38.10%
Voters: 21. You may not vote on this poll

Reply
 
Thread Tools Display Modes
  #11  
Old 10-27-2006, 08:29 PM
jfk jfk is offline
Senior Member
 
Join Date: Apr 2006
Posts: 1,313
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
I have just been informed that https://www.wsex.com should be available next week as an option for those who wish to use it.

Fred Balfour
GM
WSEX.com

[/ QUOTE ]

I don't mean to nitpick but wouldn't it be better/safer to have the https prefix as the default rather than an option? I am unaware of any downside for this choice.
Reply With Quote
  #12  
Old 10-28-2006, 10:01 AM
Todpullen Todpullen is offline
Senior Member
 
Join Date: Sep 2006
Location: England
Posts: 126
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
I have just been informed that https://www.wsex.com should be available next week as an option for those who wish to use it.

Fred Balfour
GM
WSEX.com

[/ QUOTE ]

Wonderful - thanks for this. I might even start spending some of my rakeback on sports betting if you ever get round to taking bets on English sports!
Reply With Quote
  #13  
Old 10-28-2006, 02:16 PM
Benjamin Benjamin is offline
Senior Member
 
Join Date: Aug 2004
Posts: 1,096
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
I have just been informed that https://www.wsex.com should be available next week as an option for those who wish to use it.


[/ QUOTE ]
Thank you Mr. Balfour. I will echo someone else's comment that you should really consider making that login frame secure for all users all the time.

Benjamin
Reply With Quote
  #14  
Old 10-30-2006, 07:04 AM
LoveDub LoveDub is offline
Senior Member
 
Join Date: Jun 2004
Location: Ook!
Posts: 196
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
I have just been informed that https://www.wsex.com should be available next week as an option for those who wish to use it.

Fred Balfour
GM
WSEX.com

[/ QUOTE ]

An aside: could you also increase the maximum size of the password? 8 characters maximum for a password is too short. This combined with the insecure login makes it ridiculously easy to hack your customer's accounts.
Reply With Quote
  #15  
Old 10-30-2006, 07:24 AM
LoveDub LoveDub is offline
Senior Member
 
Join Date: Jun 2004
Location: Ook!
Posts: 196
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
I have just been informed that https://www.wsex.com should be available next week as an option for those who wish to use it.

Fred Balfour
GM
WSEX.com

[/ QUOTE ]

Also, you might consider using a freely available md5 script to hash/encrypt the password in the browser before sending it to the server. It would be best to match the encryption algorithm that you use to store the passwords in the database (you do store encrypted passwords in your database, I hope...).

This will give reasonable security to those who do not go to the secure page.
Reply With Quote
  #16  
Old 10-30-2006, 11:24 AM
FCBLComish FCBLComish is offline
Senior Member
 
Join Date: Sep 2005
Location: Hi, everybody
Posts: 8,791
Default Re: What flimsy evidence of this not being secure

[ QUOTE ]
A question and a comment:

When I log in, I insert the "s" in front of the http. I assumed that afforded me a secure log in. Is this true or not?

[/ QUOTE ]

Usually, when I log in I use SIIHP.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:16 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.