Page 1 of Firefox flags unencrypted site logins as unsecure

General Forum

Firefox flags unencrypted site logins as unsecure

RJS (undefined) posted this on Tuesday, 21st March 2017, 20:21

https://arstechnica.com/security/2017/03/firefox-gets-complaint-for-labeling-unencrypted-login-page-insecure/

Quote:
The operator of a website that accepts subscriber logins only over unencrypted HTTP pages has taken to Mozilla's Bugzilla bug-reporting service to complain that the Firefox browser is warning that the page isn't suitable for the transmission of passwords.

"Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International, is not wanted and was put there without our permission," a person with the user name dgeorge wrote here (the link was made private shortly after this post went live). "Please remove it immediately. We have our own security system, and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business."

He might want to change that claim...

Quote:
Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit. Multiple people claimed that passwords were stored in plaintext rather than the standard practice of using cryptographic hashes.

There isn't any excuse these days for not using HTTPS and one way password hashing.

(Btw to anyone reading this, we went HTTPS last year and one way password hashing many years before)

Editor
MYREVIEWER.COM

My Flickr Photostream

Go back to General Forum threads, or All Forum threads