Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

291–300 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#291

it-doesnt-matter-because-that-isnt-the-point.com

What is the point?

Buying every domain name that could possibly be confused with yours would be unnecessary in this context if you fixed the issue of an attacker being able to redirect to another name.

(Banks should also protect against easily phishable domain names but that's a also losing game, and in that case the technical solution is not as simple or complete).

Re: HTTPS on Your Landing Page Is Important

#292

Earlier quoted context omitted.

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.

I had this problem, too. I fixed it by deleting my non-Skype account & waiting about 60 days.[1] Changing the email of the non-Skype account might have worked, too, but I didn't need two accounts & didn't mind waiting.

[1] https://support.microsoft.com/en-us/help/12412/microsoft-acc...

Re: HTTPS on Your Landing Page Is Important

#293
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

[deleted]

Re: HTTPS on Your Landing Page Is Important

#294

Earlier quoted context omitted.

T-Mobile called me back one time instead of me waiting on hold. This was after I went through the song and dance of giving the automated system my details. The first thing this representative wanted to do was, again, confirm I am who I said I was. I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on ho…

My bank actually gets this right. They very, very rarely call me, but when they do it's "Hello, am I talking to Nick Lamb?" "Yes, this is me" "OK, I'm calling from Example Bank and our confirmatory password is Melons" [not the actual bank or password] "Thanks, that checks out, what can I do for you?" This happened because I had one of those conversations you're talking about, and they were like "Aha! We have somethin…

This reminds me of something my local credit union used to do. They had something where you picked an image during signup that they would always show you during subsequent sign-ons so that you knew you were actually signing into their site.

Re: HTTPS on Your Landing Page Is Important

#295
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.

It is even worse if you work for a large company with Office 365 that uses your organizations domain for authentication. I think there are about 6 redirects to get logged in. Even worse than that, they made us create a "personal" account with the exact same username for accessing MSDN because it wasn't compatible with our SSO at the time. So every time I log in, I have to type in my username, wait for the redirect, then choose personal account, wait for redirect, etc...

Re: HTTPS on Your Landing Page Is Important

#296
post #93

Earlier quoted context omitted.

Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...

Perhaps the reverse would be better. If a site doesn't use HTTPS, call it unsecured.

This is expected to be the long term outcome of (at least) Google and Mozilla's current trajectory.

Google specifically says (without naming a date) that their long term intent is to put a UI like a red triangle plus the phrase "Not Secure" in the URL bar for all HTTP sites on their desktop browser. This is the same treatment you get today for a site with a bogus SSL certificate and similar to the treatment HTTP sites get now in Incognito mode.

Re: HTTPS on Your Landing Page Is Important

#297

A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…

I've never heard of him, and probably so haven't a lot of people on Twitter. I don't see why we should give him authority

Re: HTTPS on Your Landing Page Is Important

#298
post #280
post #69

Earlier quoted context omitted.

The funny thing is, checking their web site they still haven't managed to secure their landing page. You'd think they'd get the message when everyone's just laughing at them...

To play devil's advocate: everyone = Hacker News Mostly likely not their customers; whom they have a vested interest in keeping money with.

True.

My care factor is probably very different to most non techies, by assumption. Then again, there's probably a bunch of things I do that would annoy(?) {them} greatly - that I'm not even aware of.

Re: HTTPS on Your Landing Page Is Important

#299

Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.

Are you suggesting that Troy Hunt is involved in illegal pentesting ( pwning their db )? I really doubt that. He is an industry professional. The problem is not pissing off Troy Hunt; but more that they are advertising that their website is vulnerable and that they don't care.

Flagged hey? I'm serious, look at his LinkedIn if you don't believe me. His professional title is PluralSight author which he put on his senate inquiry docs. His CV for that was his LinkedIn page

Re: HTTPS on Your Landing Page Is Important

#300
post #103

Earlier quoted context omitted.

And it's so easy for anyone nowadays to get SSL with Let's Encrypt... I remember a few years ago when there was no way you could do it for side projects because certs were 100/yr., now they're free.

It is not easy if you are on a shared domain and it is not supported by your host. Please don't run around saying it is easy for everyone.

Cloudflare has you covered here. If you don't like them, there are many other options as well. If you have anything more important than a blog that doesn't have https enabled, you need to rethink how you're doing things.
Post reply on HN