Recommended Posts

I was going to say. There's dozens of certified signing authorities that do SSL cert pricing for reasonable money O.o

Comodo will sign a multi-domain cert through namecheap for $91..

http://www.namecheap.com/ssl-certificates/comodo.aspx

It's humorous that you don't understand that this isn't actually a huge problem, and can only be resolved by purchasing an expensive SSL certificate for 3 servers, or have a free one cry about it being self signed (creating an unnecessary browser alert for my site).

So...because I found humor in the length of time it took someone on a tech site to notice something such as this, automatically equates to my having no understanding. Ooook.

So...because I found humor in the length of time it took someone on a tech site to notice something such as this, automatically equates to my having no understanding. Ooook.

I think Neobond merely misinterpreted the first post, as not having SSL is something we've discussed in the past (as shown by the link in my previous post)

So...because I found humor in the length of time it took someone on a tech site to notice something such as this, automatically equates to my having no understanding. Ooook.

Ook? Ook. Ook! Ook! (sorry, can't resist.. :p )

On topic, how about setting up a donation page? Then annoy the hell out of your users, a'la Wikipedia?

Or at least have optional secure login using self-signed cert for those worried about sniffing but not too bothered with an extra browser warning?

Don't worry about it :)

My poke wasn't directed at Neowin (staff), it was towards the fact that for the most part the folks that use Neowin are technologically savvy individuals and someone was just coming across this now (Or so it was believed before Dave posted the old thread). When you quoted the length of time, it literally made me laugh. I just found it ironic.

I think Neobond merely misinterpreted the first post, as not having SSL is something we've discussed in the past (as shown by the link in my previous post)

I'm chalking it up to early money brain cloud (for those of you just waking up) and late night brain cloud (for those like me who are just about to come off a 12 hour overnight shift) ;)

Ook? Ook. Ook! Ook! (sorry, can't resist.. :p )

Lol :p

As for the issue, I don't really think it's that big of a deal.

My poke wasn't directed at Neowin (staff), it was towards the fact that for the most part the folks that use Neowin are technologically savvy individuals and someone was just coming across this now (Or so it was believed before Dave posted the old thread). When you quoted the length of time, it literally made me laugh. I just found it ironic.

I'm chalking it up to early money brain cloud (for those of you just waking up) and late night brain cloud (for those like me who are just about to come off a 12 hour overnight shift) ;)

I had just woke up (was on first coffee) :p

The way I see it, a lot of people use the same passwords for different sites.

I'm pretty sure people do it here.

It's all well in saying use a different password etc etc. but standard users won't do that.

So for a small fee of an SSL cert. I'm sure we could do a whip around and get the cash raised pretty easliy. I'll donate a few dollars no problem :-)

To me sites need to protect the user, just as much as the user needs to protect themselves.

Even if the info isn't that important, some of the stuff could be used for social engineering attacks.

There was a previous discussion about this here: http://www.neowin.ne...ds-https-login/

Not bad. It's ONLY been 7 years since that topic was started!!

Neowin is right on top of it. Certs ARE NOT that expensice now a days, as has already been pointed out, but with all the issues this site has every time they update the board, certs would only screw it up more, I'm sure! :rofl:

So reading a thread and came across this statement

"Even the neowin login page is not encrypted"

Now I thought to myself - that can not be true.. I know the page itself is not fully encrypted, but that is not an issue the sending of the username and password could be using a https post, etc.

So figured I would take a look see.... Oddly enough, the post for the login looks to be in the clear from the page source

	<form action="https://www.neowin.net/forum/index.php?app=core&module=global&section=login&do=process" method="post" id='login'>

Now I said -- hmmm, I know a little bit about html, but maybe I am missing something and I am looking at it wrong or something. So I did what I know better and that is looking at network sniffs... So I took one while logging in..

And what you know - my password right there in the clear?? That is not a very safe practice... I know its only a forum and such, and I agree you sure don't have to encrypt the whole site - but not the sending of the username and password?? That needs to be corrected!!

Now my password is complex random - but I assure you it was in the clear.

post-14624-0-50929000-1361862547.png

Not sure what that auth part is there I highlighted, but hid it as well.

So am I correct in that everyone that is logging into neowin is sending username and password in clear??

Off-topic a bit, but how did you do that? I'd like to test a few sites

So why did this turn into a SSL discussion, when the cheaper and easier solution that also doesn't nag about the site being mixed https and http so to simply encrypt/hash/salt the password before sending. and not store the clear text password in the database.

you'd think the fact that the passwords are stored in clear text would be the real worry here.

How many people's clear text passwords could someone steal by hacking the neowin database. but at least neowin is secure and always running the latest up to date IPB version so there should be no worries of that... ;) :p

So why did this turn into a SSL discussion, when the cheaper and easier solution that also doesn't nag about the site being mixed https and http so to simply encrypt/hash/salt the password before sending. and not store the clear text password in the database.

you'd think the fact that the passwords are stored in clear text would be the real worry here.

How many people's clear text passwords could someone steal by hacking the neowin database. but at least neowin is secure and always running the latest up to date IPB version so there should be no worries of that... ;) :p

Erm, except it's not US sending cleartext passwords, it is the person logging in sending a password that could be sniffed with a keylogger or something. Our member passwords are encrypted/hashed/salted on our servers.

This needs to be sorted , every other day sites and people get hacked this is not helping , if neowin gets hacked how many 1000s of people details will be lost.

I know this is just you to the server problem.

As I already pointed out, nothing about your password is stored on our servers as plain text, What YOU send however could be picked up by network sniffing, just like someone could steal your phone and then call any of your contacts on it (if the phone was unlocked).

  • Like 1

As I already pointed out, nothing about your password is stored on our servers as plain text, What YOU send however could be picked up by network sniffing, just like someone could steal your phone and then call any of your contacts on it (if the phone was unlocked).

After i read your post above i edited my post , sorry for not reading the whole thread before i posted.

We already have a donations page. Except we don't call those people donors, we call them subscribers. ;)

Some people might 'donate' more if they know the money will be going towards certificate signing. I, for one, would.

But looking at the comments here, this seems unlikely to happen..

Or secure yourself and sign in using Facebook or Twitter. As an added bonus you only need to sign in once and you can log in to many sites without having to enter anything at all.

But I agree, logging in should really go over SSL. Certificate cost shouldn't be a problem, RapidSSL's certificates are perfectly fine and trusted in all browsers and operating systems and only cost $49 for neowin.net or $199 for *.neowin.net. That shouldn't be too hard.

Your password can't just get sniffed on your computer but on any public network you connect to. When our school's WiFi wasn't secured we could sniff hundreds of passwords in a few minutes by just launching a Firefox plugin. You can't completely secure yourself as a user, but when Neowin decides to let logins go over SSL you are perfectly fine.

It's 2013 now, we've come to a point where even regular Google searches happen over SSL. Any site where you can only login over an unencrypted connection should be banned from the internet.

  • Like 4

To be honest, I do find it funny that it has not come up since that 2006 thread. To be honest, I was in the middle of posting how a site does not have to be fully https to have a secure login in that other thread.. I was quite sure that neowin would be doing the best practice thing of using https for the login portion.

But as always - better check your facts.. And figured I would use the code as example of how its done, etc..

So is this something that is going to be fixed? Could not seem to tell which way this is going.. Now back in 2006 the likely hood of wifi sniff was a lot less, not everyone was on a tablet surfing the web whenever and wherever, etc.. But as mentioned, in 2013 there is a browser addon to gather such info ;)

I normally don't like using fb or twitter logins - but if they are secure I might have to switch. Is there a actual openid method of logging in?

Erm, except it's not US sending cleartext passwords, it is the person logging in sending a password that could be sniffed with a keylogger or something. Our member passwords are encrypted/hashed/salted on our servers.

So it's the USERS fault that your login page doesn't pre-encrypted/hashed before being sent, or using SSL.

a keylogger is kind of invalid argument since at that point your computer is already fully compromised and it doesn't matter where it's encrypted unless you have a keyboard with a TPM chip that encrypts the password before the computer sees it, which is kind of unreasonable and besides the point :)

point is the password can be hashed client side before they're sent without "expensive" SSL certs.

As it is, even if they're not stored as clear text, someone could inject bad code to your site, and have all the cleartext passwords sent to you every day passed on .

This topic is now closed to further replies.
  • Posts

    • If you have the budget...! Some solo or indies just want to either learn or start their game and aren't in a capacity to pay salaries or to contractors... Get real.
    • Source and more 35 years old?! And if my maths is mathing, that means she was around 10 when The Ring came out?! Damn...scariest 10 year old I think I've ever seen. 
    • Adobe Acrobat Reader DC 2026.001.21677 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Everybody will complain, but probably will sell like hotcakes......
    • HONOR launches the HONOR Watch 6 along with early bird discounts and gifts by Steven Parker Global leading AI device ecosystem company HONOR today announced the launch of the HONOR Watch 6. Engineered to unlock your healthiest potential, HONOR Watch 6 is a cutting-edge smartwatch that flawlessly integrates a light and elegant design with professional sports modes and continuous health tracking powered by the latest HONOR AI capability, catering to those who pursue optimal fitness, sports performance, and holistic health. The HONOR Watch 6 is designed to provide professional-grade workout supports and beyond. Featuring a striking Racing Dashboard Design, The HONOR Watch 6 seamlessly draws inspiration from high-performance air intakes to create a visually dynamic and hardcore technological look. Constructed from recyclable aluminum alloy, this device weighs as little as 41 grams​, achieving exceptional lightness and outstanding durability, making it a reliable companion for active everyday wear. The exterior of the smartwatch is accentuated by precision-crafted beveled edges, enhancing its overall three-dimensional visual effect and perfectly blending ultimate hardcore performance with cutting-edge trend expression. Furthermore, the watch's meticulously polished body undergoes an exquisite and delicate sandblasting process, delivering a luxurious texture comparable to titanium alloy and exuding a highly premium tactile experience. Embracing this bold technological aesthetic, the smartwatch caters to modern sensibilities, offering a flawless blend of high-performance design and premium craftsmanship for discerning users. Equipped with an impressive 120+ sports modes, the new smartwatch offers exceptionally comprehensive tracking that truly stands out by bringing professional-grade analysis right to the wrist. Highlighting this elite capability are specialised sports mode for activities like Trail Running, Badminton, and Football. The Trail Running experience places a special focus on outdoor performance, empowering runners with an AI running coach, detailed climbing and distance metrics, and intelligent route deviation alerts, all tracked precisely by the AccuTrack system dual-band six-star GPS. To ensure flawless operation in any environment, the display features advanced water-touch control, guaranteeing the screen reacts perfectly even with wet hands or during rainy scenarios. For court and field sports, the smartwatch delivers professional-level data—such as badminton smash speeds, consecutive rally tracking, and comprehensive football heat and trajectory maps—providing users with advanced insights to elevate their competitive training. Additionally, the HONOR Watch 6 features IP691 water and dust resistance and is powered by a robust 980mAh battery​, the smartwatch claims to deliver extra durability and a remarkable ultra-long battery life of up to 35 days. This exceptional endurance makes it the perfect companion for rigorous outdoor workouts and extended adventures, ensuring users stay active, fully tracked, and continuously supported without the hassle of frequent charging. The HONOR Watch 6 is designed to make advanced health tracking accessible and effortless for everyday life, seamlessly monitoring vital metrics such as heart rate, blood oxygen, stress levels, and sleep cycles.​ Featuring a Quick Health Scan, users can instantly obtain a comprehensive health analysis of key indicators, offering valuable insights into their physical well-being at any time. An automatic daily report delivers a convenient summary every morning to help start the day with a clear understanding, while the all-day health tracking features continuously monitor essential indicators such as body energy, blood oxygen, and sleep cycles, promoting both physical and mental wellness. Supported by the HONOR IntelliSense system—which utilises richer, more uniform signal acquisition than traditional PPG modules—the watch ensures highly precise heart rate and blood flow tracking. Elevating everyday convenience, the new smartwatch features an ultra-bright display reaching 3,000 nits of peak brightness for crystal-clear visibility in direct sunlight. Adding a dynamic level of customisation, the innovative Video Watch Face allows users to set live photos or short videos under 10 seconds as highly personalised, moving backgrounds. Built for maximum efficiency, the device supports dual-phone pairing to centralise notifications from two smartphones, alongside a built-in AI Recorder that automatically generates smart voice notes and summaries for life on the go. Hands-free control is made effortless through intuitive wrist-twist gestures, letting users silence alarms, manage calls, and skip songs without touching the screen. Rounding out the smart experience, advanced NFC integration supports Mastercard and Visa​5, enabling seamless daily payments without the hassle of pre-loading funds. Pricing and Availability The HONOR Watch 6 will be available in Twilight Brown and Shadow Black to suit diverse tastes. Starting from June 18th 2026 customers can purchase the HONOR Watch from £169.99. For more information on availability and purchasing options, please visit the HONOR online store at www.honor.com/uk/. For the first month on-sale, HONOR is offering an early bird discount of £80 in addition to a gift with purchase of HONOR Choice Earbuds Clip, priced in the UK at £59.99. Look out for our review of it, coming in early July.
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      541
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      78
    4. 4
      neufuse
      64
    5. 5
      Michael Scrip
      63
  • Tell a friend

    Love Neowin? Tell a friend!