Jump to content

Forum insecure login


barmar

Recommended Posts

If you are concerned about this... when you get the login page at:

http://www.bridgebase.com/forums/index.php?app=core&module=global&section=login

 

change it to

https://www.bridgebase.com/forums/index.php?app=core&module=global&section=login

 

And when asked, click only show material sent securely. The fancy format stuff goes away, but the login options are there.

 

If you use Hotmail or gmail on public (non-encrypted) wifi, you can do that too... type for instance https://www.hotmail.com etc instead of the normal http

Link to comment
Share on other sites

Your conclusion does not follow from this premise.

 

OK, not directly. You might be upper- or lowercasing everything before running it through a hash function. But it would definitely feel a lot more secure if passwords were case-sensitive!

Link to comment
Share on other sites

I haven't discussed this much with the owners, but my personal opinion:

 

Yes people are indeed having difficulty remembering capitalization. This is a Bridge club, not WOW. Many more members are older than average, less computer savvy than average. Being able to help some less computer savvy people discover BBO and get online is an accomplishment in itself. Because of this, I'm pretty sure the password thing is deliberate.

 

I don't know if it's true, but I've always suspected Fred wrote BBO for his mom. Ask him!

Link to comment
Share on other sites

I'm going to assume that was an honest question. Generally, everything on the internet, no matter how seemingly irrelevant, is tempting to attack. The attackers can be wannabe hackers in training - they often randomly choose forums (sometimes based on searching google for keywords and choosing randomly from the results) and try to deface them to "get their name out there", in a way. Sometimes they're politically motivated and are trying to get their message across no matter where, but this forum is likely not very good for that.

Another type of attacker that doesn't care about the target is people distributing malware. The odds of someone clicking a malicious link in a private message is considerably higher if it comes from a friend, rather than a newly registered member.

A third type is the standard "people hoping the password to your forum account is also the password to your email". If I can break down exhaustively searching someone's password to two phases, first of all guessing the letters in the right order then guessing the capitalization, I need significantly less computing power - it's like playing mastermind :)

Link to comment
Share on other sites

Who would want to hack a Bridge Forum? lol

 

I loathe the day that someone posts on BBF using the username P-H-I-I or P-C-I-A-Y-T-O-N. Not that anyone would even do that on the main site. Well, not recently anyway :angry: :P

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...