Not an issue SSL Login?

Status
Not open for further replies.
I've considered implementing this many times, and it is entirely possible, however each time it comes down to "why?", especially since implementing it for just login changes nothing.

The rest of the content would still be hosted over http as it is too expensive CPU wise to do everything over HTTP, and since after login a cookie is set session hijacking is still possible (sure, the attackers might not have your username/password but they have your session, and can do anything they want as you).

Unless we (osnn.net management) decided to go fully SSL secured, and take the CPU/caching hit, having SSL secured login would be a false sense of security.

If you are browsing from a network that you believe has been compromised you shouldn't be doing any browsing unless you VPN to a remote server that can be trusted, and you have verified your own computer hasn't been compromised. SSL secured logins won't help against computers that have been compromised locally. Internet Cafe computers for example are always suspect and should always be used with caution.
 
Status
Not open for further replies.

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,494
Members
5,623
Latest member
AndersonLo
Back