Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

ffr

(22,672 posts)
Wed Feb 1, 2017, 09:07 PM Feb 2017

Is the DU login page unencrypted? Thus user credentials passed as plain text over the Internet?

Admins? Why doesn't the DU login page change to HTTPS to encrypt our login credentials to and from DU?

Sorry if this has been asked before. I couldn't find any information about this being asked before using a quick search.

9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies

ffr

(22,672 posts)
3. But DU was hacked November 9th. Packets sniffed would be in plain text.
Wed Feb 1, 2017, 09:16 PM
Feb 2017

And it's super simple for DU to implement HTTPS for login, just as all major E-mail sites (Gmail, Yahoo, Outlook, etc) do.

Purchase an inexpensive SSL certificate from Godaddy, for instance. DU admins install it. Voila. HTTPS and now all our user credentials are encrypted as they go over the Internet.

 

scscholar

(2,902 posts)
5. It is a huge hassle to keep up with SSL certs...
Wed Feb 1, 2017, 09:25 PM
Feb 2017

so I understand why this site doesn't want to. Even the free Let's Encrypt certs are a huge hassle since they expire so quickly as is their policy in order to make them difficult to use.

ffr

(22,672 posts)
6. We must be talking about two different things then. SSL certificates
Wed Feb 1, 2017, 09:38 PM
Feb 2017

are usually renewed every 3 to 5 years. Revising the SSL encryption can be performed more often, but that's up to the admin.

What SSL certificates are you talking about?

 

scscholar

(2,902 posts)
7. The Let's Encrypt ones expire after 90 days.
Thu Feb 2, 2017, 02:19 PM
Feb 2017

They have over half of the HTTPS page loads now according to:

https://letsencrypt.org/stats/

They're a pain to keep up with. With the nearly three hundred we have where I work, we're updating over three certs a day on average.

ffr

(22,672 posts)
8. How much is your time worth? Doesn't seem like Let's Encrypts' certificates are free to me
Thu Feb 2, 2017, 02:24 PM
Feb 2017

if you're spending man hours chasing your tail. Just buy SSL certificates that don't expire in 90 days like the FREE ones.

Am I missing something?

hunter

(38,331 posts)
9. What's the worst that could happen?
Thu Feb 2, 2017, 03:05 PM
Feb 2017

I remember a couple of incidents here on DU where someone started posting under another user's name, but it's usually been that someone had physical access to a member's computer.

Years ago I got into trouble with Wikipedia because I'd forgotten to log out and my teenage kids and their friends decided they'd have some fun adding silly stuff to various Wikipedia pages.

Wow, did I learn how fiercely protective people are of their Wikipedia turf.

If the same happened here on DU I'm certain regulars would notice it wasn't me posting and admin would patch over any damage done.

I do expect reasonable security on my email accounts and I use a different password on every site that requires a password.

Latest Discussions»The DU Lounge»Is the DU login page unen...