Insecure login?

If you found a bug in Illarion or need help ask here. / Wenn Du einen Fehler in Illarion gefunden hast oder Hilfe benötigst, frage hier.

Moderator: Developers

Post Reply
User avatar
Charlotte-ate-wilbur
Posts: 228
Joined: Sun Mar 12, 2017 6:42 pm

Insecure login?

Post by Charlotte-ate-wilbur »

I remember seeing a post in the past about social media accounts being hacked, and couldn't help but notice in both the forum and home sites that the passwords are in fact not secure, according to firefox the security algorithm (whatever that means) is disabled.

I personally have different passwords for everything however I'm not sure I like the idea of logging into an insecure server all the time, can this be fixed, is it something on my end?

If this is something being abused, I would hope something is being done to secure our passwords?

Hope this helps. https://support.mozilla.org/en-US/kb/in ... =inproduct
User avatar
S'rrt
Posts: 957
Joined: Thu Oct 09, 2008 10:14 pm
Location: Finland

Re: Insecure login?

Post by S'rrt »

I'm curious about this too.

EDIT: Wait a minute, wasn't this discussed already? Haven't got the topic URL though (and can't be arsed to find it)
Last edited by S'rrt on Fri May 26, 2017 12:14 am, edited 1 time in total.
User avatar
Tyan Masines
Posts: 448
Joined: Fri Jan 18, 2013 2:11 pm

Re: Insecure login?

Post by Tyan Masines »

I have experienced the same notification while using the Opera browser.

I believe it was only referring to the autofill of the username, though.
I've never let a browser save my password and I wouldn't recommend doing that despite the website.
User avatar
Nitram
Developer
Posts: 7638
Joined: Fri Oct 31, 2003 9:51 am
Contact:

Re: Insecure login?

Post by Nitram »

So the login on the homepage is in fact not encrypted currently.
The reason for this is that we originally chose a provider for the encryption certificate that was never accepted as certificate authority into the major browsers, so using this certificate causes all browsers to show a giant red window showing telling you basically that the page was in fact hacked.

For that reason we didn't activate the encryption on the public pages. By now things have changed and there are things like "Lets encrypt" we could use to encrypt the page. We just haven't got around to do this.

Best regards,
Nitram
Post Reply