Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Internet
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
Closed Thread Start New Thread
 
Old 05-17-2015, 09:22 AM
 
695 posts, read 997,190 times
Reputation: 578

Advertisements

I've noticed that when signing on to city-data, the address bar is not showing a secure website: https. Is this the case for everyone on here? Is this a security issue for users?

 
Old 05-17-2015, 09:44 AM
 
41,813 posts, read 51,032,070 times
Reputation: 17864
A third party could potentially obtain your password. There is two potential vectors for exploit.

  • If you were using the DM system for personal data which you shouldn't be anyway.
  • If you are using the same password for other sites. For example someone obtains your password and looks up your email address in your profile. They can try getting into your email using that password. Now they are in you email and can look around and see what bank you use....
For the second case the more likely possibility which happens quite a bit is a hacker obtains access to the database and gets everyone passwords and email addresses. This is not something you can prevent or prevented with HTTPS.


This is why it's important to use different passwords on different sites especially sites like this where security is not going to be the same you would expect from banking sites etc.



Use a password manager: KeePass Password Safe
 
Old 05-17-2015, 09:50 AM
 
695 posts, read 997,190 times
Reputation: 578
Quote:
Originally Posted by thecoalman View Post
A third party could potentially obtain your password. There is two potential vectors for exploit.

  • If you were using the DM system for personal data which you shouldn't be anyway.
  • If you are using the same password for other sites. For example someone obtains your password and looks up your email address in your profile. They can try getting into your email using that password. Now they are in you email and can look around and see what bank you use....
For the second case the more likely possibility which happens quite a bit is a hacker obtains access to the database and gets everyone passwords and email addresses. This is not something you can prevent or prevented with HTTPS.


This is why it's important to use different passwords on different sites especially sites like this where security is not going to be the same you would expect from banking sites etc.



Use a password manager: KeePass Password Safe
Thanks for the comment. I use a totally different password for each login (it's a long list!). But I am concerned with a hacker getting into the profile and then the email address (though the email uses a totally different password). However, when I just went to my profile, I could not find my email address listed. Do you know where it is in the profile? (Send DM if you prefer on that last question.) Is anyone else on CD concerned with lack of https when logging in?
 
Old 05-17-2015, 09:59 AM
 
41,813 posts, read 51,032,070 times
Reputation: 17864
My Settings >> Edit details >> Edit Email and Password

Quote:
But I am concerned with a hacker getting into the profile and then the email address (though the email uses a totally different password).
Other than getting spam I'm not sure what your concern would be. It's useless as long as you have different passwords. The only potential is what they can do to your account here and that is largely irrelevant and very unlikely unless it's personal.
 
Old 05-17-2015, 10:03 AM
 
695 posts, read 997,190 times
Reputation: 578
Quote:
Originally Posted by thecoalman View Post
My Settings >> Edit details >> Edit Email and Password



Other than getting spam I'm not sure what your concern would be. It's useless as long as you have different passwords. The only potential is what they can do to your account here and that is largely irrelevant and very unlikely unless it's personal.
That makes sense. The key is having different passwords. It's not likely that spam bots can scan that deep into accounts to capture email addresses. I've never had issues with changes to an account here. I appreciate your comments.
 
Old 05-17-2015, 01:08 PM
 
622 posts, read 526,756 times
Reputation: 564
Provided you're not using Internet Explorer to browse with, install Zenmate which encrypts all traffic: https://zenmate.com/
 
Old 05-17-2015, 01:31 PM
 
41,813 posts, read 51,032,070 times
Reputation: 17864
Quote:
Originally Posted by Xircal View Post
Provided you're not using Internet Explorer to browse with, install Zenmate which encrypts all traffic: https://zenmate.com/
The data is still not encrypted between this server and theirs. That service also has access to all your traffic, passwords etc.

Last edited by thecoalman; 05-17-2015 at 01:53 PM..
 
Old 05-17-2015, 05:16 PM
 
26,143 posts, read 19,827,945 times
Reputation: 17241
HTTPS isnt really needed for a site like this...

ONLY BANKING SITES,etc should have SSL enabled......

Quote:
Originally Posted by Xircal
Provided you're not using Internet Explorer to browse with, install Zenmate which encrypts all traffic: https://zenmate.com/
What would be wrong with using IE? (IE is as good as any other browser (Its the END USER who determines it))
 
Old 05-17-2015, 08:32 PM
 
41,813 posts, read 51,032,070 times
Reputation: 17864
Quote:
Originally Posted by Dude111 View Post
HTTPS isnt really needed for a site like this...

ONLY BANKING SITES,etc should have SSL enabled......
Computer/web security is a matter of layers and site owners need to take the initiative to protect their users from their own stupidity, e.g. same passwords. Potential vulnerabilities no matter how big or hoe small should always be addressed.

While HTTPS is not really needed site wide on site like this it should be enabled for logins etc. I don't have it on my own sites but it's coming.
 
Old 05-18-2015, 08:43 AM
 
622 posts, read 526,756 times
Reputation: 564
Quote:
Originally Posted by thecoalman View Post
The data is still not encrypted between this server and theirs. That service also has access to all your traffic, passwords etc.
I queried those points earlier and was assured that all data regardless of the connection is encrypted.

You can check for yourself by going to Whoer.net - find out IP address: Extended version both before and after you login to Zenmate.

Also, they don't retain data.
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Closed Thread


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Internet
Similar Threads

All times are GMT -6.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top