https support? (Full Version)

All Forums >> [Cellar Talk] >> CellarTracker Support



Message


anubis -> https support? (4/4/2010 7:54:21 PM)

Having just returned home from a trip to Thailand and using various PUBLIC internet (fixed and wireless) terminals, I refrained from logging onto CT (or GS) from these public spots as there is no HTTPS support at the CT/GS login page [that I could find].

I know my collection is probably not on any-body's hit list if they do find out my ID and password, but I still couldn't bring my self to logon from these spots.

Is there any consideration of at least making the login to CT/GS and the discussions HTTPS capable in the future. Preferably, the whole site should be HTTPS enabled just to keep everything secret from prying eyes...

Thanks




Eric -> RE: https support? (4/4/2010 7:58:13 PM)

In the future I will be doing an authentication overhaul including HTTPS login and then some session/password hashing. For now the site is low-tech and low-security. No point going halfway on this stuff.




Eric -> RE: https support? (10/28/2011 12:39:18 PM)

FYI, following up on this, as of last night CellarTracker has moved to industry best practice for password and cookie handling:
  https://www.cellartracker.com/forum/tm.asp?m=166607




Page: [1]

Valid CSS!




Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI
0.125