(ANSWERED)Various issues around login/passwords
(ANSWERED)Various issues around login/passwords
Author
Discussion

Digital

Original Poster:

420 posts

261 months

Sunday 1st January 2017
quotequote all
Having changed my PH account password earlier, there are a few things I noticed that really need to be tightened up on.

  1. PH login page is served over HTTP, therefore there is the potential for Javascript to be injected to hijack the password of anyone logging in.
  2. The username and password are sent over HTTP, therefore rendering the login process completely insecure. I wouldn't login to PH over a public wifi network as a result (regardless of the fact my credentials are valid only for PH).
  3. The change password page does not allow the new password to be pasted in. This is poor design, and prevents the use of password managers, which are intended to enhance security of passwords.
  4. The changed password is sent over HTTP, again leaving it open to be intercepted.
For the size of site that Pistonheads now is, and the amount of traffic going through it, it really needs to be upgraded to HTTPS as soon as possible.

Sebring440

3,196 posts

125 months

Sunday 1st January 2017
quotequote all
Digital said:
For the size of site that Pistonheads now is, and the amount of traffic going through it, it really needs to be upgraded to HTTPS as soon as possible.
By gosh, I think you're onto something!

And, believe it or not, many agree with you:


http://www.pistonheads.com/gassing/topic.asp?h=0&a...

Jack Mansfield

3,279 posts

119 months

PH TEAM

Tuesday 3rd January 2017
quotequote all
Hi digital,

Thank you for your feedback, we are aiming to get this sorted asap!

Cheers,

Jack