Linked by Thom Holwerda on Thu 19th Jun 2008 20:23 UTC, submitted by Mark Wielaard
Thread beginning with comment 319346
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[3]: Scare Mongering - cost also
by jabbotts on Fri 20th Jun 2008 14:19
in reply to "RE[2]: Scare Mongering - login prompt"
It gives me the willies every time I have to use a plaintext login form but some sites are worth it for the limited risk presented. As you add though, most users don't have a different uname/passwd for each login. Once you get there site account or MSN Chat off the wire you've got the keys too the kingdom.
In terms of websites, I think cost is a big part. A self signed cert is not going to be trusted by people who don't know the website well (or us security geeks for that matter). A CA signed cert means involving a third party for a strictly two party discussion along with the absorbitant cost charged by most CA for the privellege of useing what should have replaced http long ago.





Member since:
2005-07-06
MSN, Yahoo, ICQ and the other chat clients all send uname/passwd in plain text also even if you use "off the record" or some other enryption for the chat. In the case of the first two, they use your email account for authentication so you can't even use a protocol specific password; may as well just hang a sign out from saying "this is my email, please hijack my account and use it for whatever you want".
Damn me and my ethics. I'd have been rich by now if I didn't develop those pesky things early in life.
I agree. But I think that is worse is the fact that many people here will also use the same password for this website as they do for their email, internet banking and numerous other facilities. Its shocking that this website doesn't do logging in via ssl.