Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   PeachParts Mercedes-Benz Forum > Mercedes-Benz Tech Information and Support > Tech Help

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 03-08-2017, 02:51 PM
newbie
 
Join Date: Apr 2012
Posts: 464
Logging issues non secured website

When I logged on this website, I am using Firefox browser. The latest update on Firefox browser included user warnings for non-secure HTTP pages with logins. Firefox now displays a “This connection is not secure” message when users click into the username and password fields on pages that don’t use HTTPS.

Here is this article on the logging issue: https://support.mozilla.org/t5/Protect-your-privacy/Insecure-password-warning-in-Firefox/ta-p/27861

Should I be concern about logging on this website? Any comment/feedback on this issue?

Reply With Quote
  #2  
Old 03-11-2017, 05:28 PM
Registered User
 
Join Date: Jul 2005
Location: Seattle, WA
Posts: 598
i wouldn't be too anxious over that. it's commonly presumed that most web sites are not
secured. the only ones you should have a heightened awareness over is if the site you are
on is not secured and you are about to input personal, financial, or confidential information
e.g. paypal, ebay, your bank, credit cards, amazon...you get the picture
__________________
-- raymond~
47º 34'N 122º 18'W
Reply With Quote
  #3  
Old 03-25-2017, 04:03 PM
newbie
 
Join Date: Apr 2012
Posts: 464
Thanks raymond for your imput. I appreciated it.
Reply With Quote
  #4  
Old 03-25-2017, 07:29 PM
okyoureabeast's Avatar
Rogue T Tolerant
 
Join Date: Jul 2009
Location: North America
Posts: 1,675
Just make sure your password here isn't the same as your banking, email, or other sensitive accounts.
__________________
-Typos courtesy of my mobile phone.
Reply With Quote
  #5  
Old 03-26-2017, 05:19 AM
Stretch's Avatar
...like a shield of steel
 
Join Date: Sep 2009
Location: Somewhere in the Netherlands
Posts: 14,461
Not only not the same - similar pattern if there happens to be one.

In this day and age, however, there really ought to be more done to protect user accounts. Benz World had a great big paddy about their service provider being hacked and all the account information being published some where for "criminals". Sure it was "just" email addresses and site passwords - still personal data which is meant to looked after responsibly.

Whether it is irresponsible or responsible or not will come down to opinion. Many more traders' site are now htpps encrypted and slowly forums are going that way too. It will eventually "look" like people are not being responsible if they too don't use https.
__________________
1992 W201 190E 1.8 171,000 km - Daily driver
1981 W123 300D ~ 100,000 miles / 160,000 km - project car stripped to the bone
1965 Land Rover Series 2a Station Wagon CIS recovery therapy!
1961 Volvo PV544 Bare metal rat rod-ish thing

I'm here to chat about cars and to help others - I'm not here "to always be right" like an internet warrior



Don't leave that there - I'll take it to bits!
Reply With Quote
  #6  
Old 03-27-2017, 02:39 PM
Registered User
 
Join Date: Jul 2008
Posts: 1,236
Quote:
Originally Posted by Stretch View Post
Not only not the same - similar pattern if there happens to be one.

In this day and age, however, there really ought to be more done to protect user accounts. Benz World had a great big paddy about their service provider being hacked and all the account information being published some where for "criminals". Sure it was "just" email addresses and site passwords - still personal data which is meant to looked after responsibly.

Whether it is irresponsible or responsible or not will come down to opinion. Many more traders' site are now htpps encrypted and slowly forums are going that way too. It will eventually "look" like people are not being responsible if they too don't use https.
As someone who works in the industry, I can tell you that we are already well past that point. https is now the standard, and plain-text sites like this are considered obsolete and risky. Even google searches are now https by default. It really isn't all that much work to get SSL working, you just need a certificate and a few configuration changes.

I highly encourage the admins here to catch up and get this site secured. Not having a secure site effects all sorts of metrics, including search ranking. You are leaving yourself unprotected and losing out on search hits by not having this site secured. You are also exposing your users to potential data breaches and scams.

Just remember - your password is sent across the wire in plain text here. That means anyone with a network traffic sniffer can -easily- get your account credentials. This includes the site administrator and everything they have access to.
__________________
-tp


1990 300SE "Corinne"- 145k daily driver - street modified differential - PARTING OUT OR SELLING SOON - PORTLAND OR. AREA - PM ME FOR DETAILS
1988 560SEL "Gunther"- 190K passes anything except a gas station
1997 S420 - 265k just bought it with a rebuilt trans. Lovely condition
Reply With Quote
  #7  
Old 03-31-2017, 04:50 AM
Stretch's Avatar
...like a shield of steel
 
Join Date: Sep 2009
Location: Somewhere in the Netherlands
Posts: 14,461
Quote:
Originally Posted by tinypanzer View Post
As someone who works in the industry, I can tell you that we are already well past that point. https is now the standard, and plain-text sites like this are considered obsolete and risky. Even google searches are now https by default. It really isn't all that much work to get SSL working, you just need a certificate and a few configuration changes.

I highly encourage the admins here to catch up and get this site secured. Not having a secure site effects all sorts of metrics, including search ranking. You are leaving yourself unprotected and losing out on search hits by not having this site secured. You are also exposing your users to potential data breaches and scams.

Just remember - your password is sent across the wire in plain text here. That means anyone with a network traffic sniffer can -easily- get your account credentials. This includes the site administrator and everything they have access to.
So how would you apply pressure to the administrators then?
__________________
1992 W201 190E 1.8 171,000 km - Daily driver
1981 W123 300D ~ 100,000 miles / 160,000 km - project car stripped to the bone
1965 Land Rover Series 2a Station Wagon CIS recovery therapy!
1961 Volvo PV544 Bare metal rat rod-ish thing

I'm here to chat about cars and to help others - I'm not here "to always be right" like an internet warrior



Don't leave that there - I'll take it to bits!
Reply With Quote
  #8  
Old 03-31-2017, 07:23 AM
tbomachines's Avatar
ಠ_ಠ
 
Join Date: Mar 2009
Location: Philadelphia
Posts: 8,093
Agreed on all of the above (Also work in the industry). I would start by showing them the concerns of members here, and also that Google ranks https pages higher than non ssl pages, so they'll likely see an organic traffic boost in the long run. Short answer is they should get with the times, it's practically a standard now.

__________________
TC
Current stable:
- 2004 Mazda RALLYWANKEL
- 2007 Saturn sky redline
- 2004 Explorer...under surgery.

Past: 135i, GTI, 300E, 300SD, 300SD, Stealth
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 09:20 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2024 Pelican Parts, LLC - Posts may be archived for display on the Peach Parts or Pelican Parts Website -    DMCA Registered Agent Contact Page