follow ft86club on our blog, twitter or facebook.
FT86CLUB
Ft86Club
Speed By Design
Register Garage Community Calendar Today's Posts Search

Go Back   Toyota GR86, 86, FR-S and Subaru BRZ Forum & Owners Community - FT86CLUB > Off-Topic Discussions > Site Announcements / Questions / Issues


User Tag List

Reply
 
Thread Tools Search this Thread
Old 11-09-2017, 11:03 AM   #15
runfrodorun
Member
 
Join Date: Aug 2016
Drives: Red 2013 BRZ Premium 6MT
Location: Chicago, IL
Posts: 58
Thanks: 13
Thanked 24 Times in 16 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by Ultramaroon View Post
Meh. Don't use this password for anything else and don't post anything you don't want the whole world to see.

Problem solved.
There's more you can do without HTTPS than just steal info. HTTPS guarantees that only the server can decrypt the message to it, and only the particular client can decrypt the message from the server. Without that guarantee, then anyone can intercept messages coming back from the server to you and modify them and you would not know.

So for example, I just met up with somebody from the forums last night. It could have been a gang that fed me a false location and phone number by intercepting my request to the server to load the message that he gave me and modified it before it was displayed on my screen, and then stabbed me and took my car after meeting up somewhere. Extreme example, but there are creative people that could probably find a successful way to take advantage of members.

Historically there have been many, many creative abuses of sites that do not use HTTPS and they vary vastly beyond stealing passwords.
runfrodorun is offline   Reply With Quote
The Following 2 Users Say Thank You to runfrodorun For This Useful Post:
spike021 (11-11-2017), Ultramaroon (11-09-2017)
Old 11-09-2017, 12:12 PM   #16
Skeneypoo
Senior Member
 
Skeneypoo's Avatar
 
Join Date: Jul 2014
Drives: 2013 Satin White Pearl BRZ Limited
Location: Thousand Oaks
Posts: 132
Thanks: 11
Thanked 36 Times in 25 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
VPNs and Password Managers for the win. I don't have any duplicate passwords, it's beautiful.

That said, I agree. Should be HTTPS.
Skeneypoo is offline   Reply With Quote
The Following 2 Users Say Thank You to Skeneypoo For This Useful Post:
ScoobsMcGee (11-10-2017), why? (10-08-2018)
Old 11-09-2017, 02:22 PM   #17
Ultramaroon
義理チョコ
 
Ultramaroon's Avatar
 
Join Date: Sep 2014
Drives: a 13 e8h frs
Location: vantucky, wa
Posts: 31,865
Thanks: 52,120
Thanked 36,513 Times in 18,917 Posts
Mentioned: 1106 Post(s)
Tagged: 9 Thread(s)
Quote:
Originally Posted by runfrodorun View Post
Historically there have been many, many creative abuses of sites that do not use HTTPS and they vary vastly beyond stealing passwords.
It's always the damn Russians.
__________________
Ultramaroon is offline   Reply With Quote
The Following User Says Thank You to Ultramaroon For This Useful Post:
Tcoat (11-10-2017)
Old 11-10-2017, 07:51 PM   #18
Gunman
Senior Member
 
Join Date: Mar 2013
Drives: 2019 Mazda Miata RF
Location: Earth
Posts: 2,105
Thanks: 979
Thanked 1,317 Times in 736 Posts
Mentioned: 23 Post(s)
Tagged: 1 Thread(s)
Garage
fwiw I use the https everywhere plugin, and ssl on my own NAS.

I agree, anything with a password should use https.
Gunman is offline   Reply With Quote
Old 11-13-2017, 10:44 PM   #19
KR-S
Sporadic Member
 
KR-S's Avatar
 
Join Date: Nov 2015
Drives: 2016 Halo FR-S M/T
Location: Earth
Posts: 3,145
Thanks: 5,221
Thanked 3,552 Times in 1,746 Posts
Mentioned: 50 Post(s)
Tagged: 33 Thread(s)
I actually had this same concern a year ago when this was brought up on the thread concerning the hack on JB Autosport's network.

I ran Wireshark (on a private network of course - NEVER on a public network) to see if I could sniff my password from the packets. Interestingly, what I found was that the password was still somehow encrypted. Maybe this was due to other factors I wasn't aware about, but I was pretty surprised.

I think HTTPS is a good idea, but with that said, a lot of people don't really see this as an issue since for them, it's just a forum account with no personal information. As long as people aren't reusing passwords, they should be fine.
__________________
Quote:
Originally Posted by klearfade View Post
Is that gel in your hair?!
Quote:
Originally Posted by HueyLooie View Post
Nah, homes. It's your dadda's hot goopey goop.
KR-S is offline   Reply With Quote
Old 02-25-2018, 05:03 PM   #20
kb3dow
Member
 
Join Date: Feb 2018
Drives: Honda Accord
Location: Laurel, MD
Posts: 12
Thanks: 11
Thanked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Looks like this issue is still not resolved. Looks like this site may not be managed on a continual basis - perhaps someone set it up and then its running purely on user posts to forums.
kb3dow is offline   Reply With Quote
Old 02-25-2018, 11:07 PM   #21
finch1750
Undisputed El Presidente
 
finch1750's Avatar
 
Join Date: Jun 2012
Drives: Zenki 37J ZN6
Location: Stockton, CA
Posts: 11,571
Thanks: 9,382
Thanked 9,397 Times in 5,261 Posts
Mentioned: 374 Post(s)
Tagged: 33 Thread(s)
Quote:
Originally Posted by kb3dow View Post
Looks like this issue is still not resolved. Looks like this site may not be managed on a continual basis - perhaps someone set it up and then its running purely on user posts to forums.
There are like 2 active mods left, but really if it is that large a concern a PM to the admin and main mod @ichitaka05 would probably go farther then a thread that may not get checked (until now that I tagged a mod)
__________________

"Just like how a strut bar somehow enables you to corner 20MPH faster around a cloverleaf on-ramp, when the reality is, you can do it already but you just don't have to balls to do it." - CSG David
finch1750 is offline   Reply With Quote
Old 02-25-2018, 11:35 PM   #22
ichitaka05
Site Moderator
 
ichitaka05's Avatar
 
Join Date: Oct 2009
Drives: ichi 86 Project
Location: Middle of No where
Posts: 20,965
Thanks: 7,663
Thanked 19,051 Times in 8,326 Posts
Mentioned: 677 Post(s)
Tagged: 27 Thread(s)
Quote:
Originally Posted by finch1750 View Post
There are like 2 active mods left, but really if it is that large a concern a PM to the admin and main mod @ichitaka05 would probably go farther then a thread that may not get checked (until now that I tagged a mod)
Yeah... sadly, I don’t have much power over this part. Admin Hachiroku or other admin FT-HS do those kind of things.
__________________
ichitaka05 is offline   Reply With Quote
Old 02-26-2018, 08:09 AM   #23
Tcoat
Senior Member
 
Tcoat's Avatar
 
Join Date: Jul 2014
Drives: 2020 Hakone
Location: London, Ont
Posts: 69,845
Thanks: 61,656
Thanked 108,283 Times in 46,456 Posts
Mentioned: 2495 Post(s)
Tagged: 50 Thread(s)
Quote:
Originally Posted by kb3dow View Post
Looks like this issue is still not resolved. Looks like this site may not be managed on a continual basis - perhaps someone set it up and then its running purely on user posts to forums.
And the person hiding behind a new user name instead of using their normal one is worried about it? Paranoid much?
__________________
Racecar spelled backwards is Racecar, because Racecar.
Tcoat is offline   Reply With Quote
Old 02-26-2018, 10:53 AM   #24
kb3dow
Member
 
Join Date: Feb 2018
Drives: Honda Accord
Location: Laurel, MD
Posts: 12
Thanks: 11
Thanked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by Tcoat View Post
And the person hiding behind a new user name instead of using their normal one is worried about it? Paranoid much?
Well everyone here has a pseudonym so you dont have to be sarcastic about me hiding behind a new user name. When I login using firefox it warns the password is not encrypted, and https does not work. I agree that there is nothing confidential here and I don't use common passwords on different sites - so it is not a show stopper
kb3dow is offline   Reply With Quote
Old 02-26-2018, 11:11 AM   #25
Tcoat
Senior Member
 
Tcoat's Avatar
 
Join Date: Jul 2014
Drives: 2020 Hakone
Location: London, Ont
Posts: 69,845
Thanks: 61,656
Thanked 108,283 Times in 46,456 Posts
Mentioned: 2495 Post(s)
Tagged: 50 Thread(s)
Quote:
Originally Posted by kb3dow View Post
Well everyone here has a pseudonym so you dont have to be sarcastic about me hiding behind a new user name. When I login using firefox it warns the password is not encrypted, and https does not work. I agree that there is nothing confidential here and I don't use common passwords on different sites - so it is not a show stopper
The point is that the rest of us have only one.
__________________
Racecar spelled backwards is Racecar, because Racecar.
Tcoat is offline   Reply With Quote
Old 02-27-2018, 04:01 PM   #26
ScoobsMcGee
Junior Senior with Cheese
 
ScoobsMcGee's Avatar
 
Join Date: Aug 2014
Drives: 15 BRZ
Location: York, PA
Posts: 2,998
Thanks: 6,795
Thanked 7,013 Times in 2,337 Posts
Mentioned: 13 Post(s)
Tagged: 2 Thread(s)
To be fair, a poorly managed HTTPS site doesn't offer that much more security than plain text, while increasing the complexity. SSL or TLSv1.0 encryption isn't too difficult to attack given the proper circumstances. Unless Hachi or FT-HS go all-in on properly locking down and maintaining the site, simply getting a cert and enabling HTTPS is setting things up to break once that cert expires. Not much else.
ScoobsMcGee is offline   Reply With Quote
The Following 3 Users Say Thank You to ScoobsMcGee For This Useful Post:
bcj (02-27-2018), Spuds (02-27-2018), Ultramaroon (02-27-2018)
 
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Does ft86club.com support secure https:// ? jonnyozero3 Site Announcements / Questions / Issues 0 04-30-2015 01:16 PM
https://scontent-a-atl.xx.fbcdn.net/hphotos-xfa1/v/t1.0-9/1796528_366899856806734_765 jhusey Forced Induction 4 11-05-2014 09:32 PM


All times are GMT -4. The time now is 03:43 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
User Alert System provided by Advanced User Tagging v3.3.0 (Lite) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.

Garage vBulletin Plugins by Drive Thru Online, Inc.