vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   Suggestion: SSL Support (https://vborg.vbsupport.ru/showthread.php?t=145006)

Patria 04-16-2007 11:43 AM

Suggestion: SSL Support
 
Hello vBulletin team,

it would be great if you could enable SSL Support on vbulletin.org. :)

Paul M 04-16-2007 11:48 AM

I think that's unlikely - for what reason would you want it ?

Patria 04-16-2007 11:52 AM

Quote:

Originally Posted by Paul M (Post 1228931)
I think that's unlikely - for what reason would you want it ?

For Security & Privacy reasons.

Paul M 04-16-2007 03:59 PM

Sorry but that's a pretty vague answer, what security and privacy reasons exactly ?

Patria 04-16-2007 04:21 PM

Quote:

Originally Posted by Paul M (Post 1229053)
Sorry but that's a pretty vague answer, what security and
privacy reasons exactly ?

If I change/enter my password it flows unencrypted over the internet, HTTPS would be useful there for example. The next point is that my nickname also flows unencrypted over the internet and that harms my privacy.

Paul M 04-16-2007 07:39 PM

vbulletin does not send unencrypted passwords over the net, they are hashed using MD5.

As for your nickname - are you serious - what possible harm to your privacy does that cause (given that everyone who visits the site can clearly see it).

(I take it you don't use e-mail, given how highly insecure that actually is).

Patria 04-16-2007 08:34 PM

Quote:

Originally Posted by Paul M (Post 1229185)
vbulletin does not send unencrypted passwords over the net, they are hashed using MD5.

Ok.

But ... insecure in some kind. (you could capture the MD5 checksum and run it via brute force against a wordlist) ;)

Quote:

As for your nickname - are you serious - what possible harm to your privacy does that cause (given that everyone who visits the site can clearly see it).
I fear our ISPs in combination with our goverments and the data retention laws not the vB.org visitors/members.
Quote:

(I take it you don't use e-mail, given how highly insecure that actually is).
I use TLS and PGP.

"Just because you're paranoid doesn't mean they aren't after you" - Kurt Cobain :p

Paul M 04-16-2007 08:45 PM

You might use TLS, SMTP servers don't use it to send your e-mail from server to server.

If you are that paranoid then maybe you shouldn't be on the internet. ;)

nexialys 04-17-2007 12:33 AM

SSL support would be a good alternative to MD5 coding in most of the very-secure situations...

for the reason you list, you may have a good point... maybe it would be good for you to hire a professional coder with a good knowledge of security and SSL so he/she can recode the parts you may require to be recoded like the login and general authentication system... it's not quite complicated to rebuild, it's just changing a MD5 structure to a SSL one...

Dismounted 04-17-2007 06:16 AM

He's asking for this on vB.org, not his own site :p.


All times are GMT. The time now is 06:41 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01091 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete