I don't want the notice of insecure password/log-in on my website
bugzilla.mozilla.org
I don't want the notice of insecure password/log-in on my website
1–10 of 13 posts
Re: I don't want the notice of insecure password/log-in on my website
#2Re: I don't want the notice of insecure password/log-in on my website
#3Re: I don't want the notice of insecure password/log-in on my website
#4Oh no.. they've locked it to authorised users only. Anyone get a screengrab?
Re: I don't want the notice of insecure password/log-in on my website
#5Oh no.. they've locked it to authorised users only. Anyone get a screengrab?
https://www.reddit.com/r/programming/comments/60jc69/company...
Re: I don't want the notice of insecure password/log-in on my website
#6i.e. dell.com/nz/ -> 'My Account' looks like it's done over plain HTTP. Is my assumption correct?
Re: I don't want the notice of insecure password/log-in on my website
#7Re: I don't want the notice of insecure password/log-in on my website
#8You have to login to view this bug. No thanks.
Re: I don't want the notice of insecure password/log-in on my website
#9> Update: Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit.
> Multiple people claimed that passwords were stored in plaintext
> the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.
[1] https://arstechnica.com/security/2017/03/firefox-gets-compla...
Re: I don't want the notice of insecure password/log-in on my website
#10Oh no.. they've locked it to authorised users only. Anyone get a screengrab?
http://archive.is/53Cbd
Oh my... HTTPS was already well established 15 years ago... are people like this in charge of nuclear facilities, too?