BBO Discussion Forums: Forum insecure login - BBO Discussion Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Forum insecure login

#1 User is offline   barmar 

  • PipPipPipPipPipPipPipPipPipPipPipPip
  • Group: Admin
  • Posts: 22,142
  • Joined: 2004-August-21
  • Gender:Male

Posted 2011-January-12, 16:41

I was having a discussion about secure vs. insecure login forms in another forum, and decided to check the BBO Forum's login page. It doesn't use HTTPS to send the username and password. That's bad.

#2 User is offline   inquiry 

  • PipPipPipPipPipPipPipPipPipPip
  • Group: Admin
  • Posts: 14,566
  • Joined: 2003-February-13
  • Gender:Male
  • Location:Amelia Island, FL
  • Interests:Bridge, what else?

Posted 2011-January-12, 19:22

If you are concerned about this... when you get the login page at:
http://www.bridgebas...l&section=login

change it to
https://www.bridgeba...l&section=login

And when asked, click only show material sent securely. The fancy format stuff goes away, but the login options are there.

If you use Hotmail or gmail on public (non-encrypted) wifi, you can do that too... type for instance https://www.hotmail.com etc instead of the normal http
--Ben--

#3 User is offline   Rain 

  • PipPipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 6,592
  • Joined: 2003-February-13
  • Gender:Male
  • Location:Singapore

Posted 2011-January-12, 19:48

Gerardo has made a change to https, but thinks it applies to logins only. Thank you for bringing this up.
"More and more these days I find myself pondering how to reconcile my net income with my gross habits."

John Nelson.
0

#4 User is offline   Gerardo 

  • PipPipPipPipPipPipPip
  • Group: Admin
  • Posts: 2,523
  • Joined: 2003-February-12
  • Gender:Male
  • Location:Dartmouth, NS, Canada

Posted 2011-January-12, 19:44

HTTPS now forced at login time.

#5 User is offline   mgoetze 

  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 4,942
  • Joined: 2005-January-28
  • Gender:Male
  • Location:Cologne, Germany
  • Interests:Sleeping, Eating

Posted 2011-January-13, 04:31

This is a very small issue compared to the fact that BBO still stores all passwords in plaintext on its server! Make sure you never ever use your BBO password for anything else!
"One of the painful things about our time is that those who feel certainty are stupid, and those with any imagination and understanding are filled with doubt and indecision"
    -- Bertrand Russell
0

#6 User is offline   mohitz 

  • PipPipPipPip
  • Group: Full Members
  • Posts: 357
  • Joined: 2008-May-19
  • Gender:Male
  • Location:India

Posted 2011-January-13, 05:02

View Postmgoetze, on 2011-January-13, 04:31, said:

This is a very small issue compared to the fact that BBO still stores all passwords in plaintext on its server! Make sure you never ever use your BBO password for anything else!


And how do you know that?
All your ace are belong to us!
0

#7 User is offline   mgoetze 

  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 4,942
  • Joined: 2005-January-28
  • Gender:Male
  • Location:Cologne, Germany
  • Interests:Sleeping, Eating

Posted 2011-January-13, 06:28

View Postmohitz, on 2011-January-13, 05:02, said:

And how do you know that?


Because I can log in with different capitalisations of my pASswoRd.
"One of the painful things about our time is that those who feel certainty are stupid, and those with any imagination and understanding are filled with doubt and indecision"
    -- Bertrand Russell
0

#8 User is offline   fred 

  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 4,615
  • Joined: 2003-February-11
  • Gender:Male
  • Location:Las Vegas, USA

Posted 2011-January-13, 09:11

View Postmgoetze, on 2011-January-13, 06:28, said:

Because I can log in with different capitalisations of my pASswoRd.

Your conclusion does not follow from this premise.

Fred Gitelman
Bridge Base Inc.
www.bridgebase.com
0

#9 User is offline   mgoetze 

  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 4,942
  • Joined: 2005-January-28
  • Gender:Male
  • Location:Cologne, Germany
  • Interests:Sleeping, Eating

Posted 2011-January-13, 10:19

View Postfred, on 2011-January-13, 09:11, said:

Your conclusion does not follow from this premise.


OK, not directly. You might be upper- or lowercasing everything before running it through a hash function. But it would definitely feel a lot more secure if passwords were case-sensitive!
"One of the painful things about our time is that those who feel certainty are stupid, and those with any imagination and understanding are filled with doubt and indecision"
    -- Bertrand Russell
0

#10 User is offline   cherdano 

  • 5555
  • PipPipPipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 9,520
  • Joined: 2003-September-04
  • Gender:Male

Posted 2011-January-13, 10:17

Is "OK, not directly." a new way of saying "OK, I was completely wrong."?
The easiest way to count losers is to line up the people who talk about loser count, and count them. -Kieran Dyke
1

#11 User is offline   georgeac 

  • PipPipPipPip
  • Group: Full Members
  • Posts: 135
  • Joined: 2007-September-02

Posted 2011-January-17, 17:03

lol
0

#12 User is offline   Antraxxx 

  • PipPipPip
  • Group: Full Members
  • Posts: 87
  • Joined: 2010-October-21
  • Gender:Male

Posted 2011-January-18, 02:01

This is actually a rather curious treatment, though. Regardless of how passwords are stored, case insensitivity is considerably easier to brute force. Are people really having that much difficulty remembering their original capitalisation?
0

#13 User is offline   Rain 

  • PipPipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 6,592
  • Joined: 2003-February-13
  • Gender:Male
  • Location:Singapore

Posted 2011-January-18, 09:57

I haven't discussed this much with the owners, but my personal opinion:

Yes people are indeed having difficulty remembering capitalization. This is a Bridge club, not WOW. Many more members are older than average, less computer savvy than average. Being able to help some less computer savvy people discover BBO and get online is an accomplishment in itself. Because of this, I'm pretty sure the password thing is deliberate.

I don't know if it's true, but I've always suspected Fred wrote BBO for his mom. Ask him!
"More and more these days I find myself pondering how to reconcile my net income with my gross habits."

John Nelson.
0

#14 User is offline   Antraxxx 

  • PipPipPip
  • Group: Full Members
  • Posts: 87
  • Joined: 2010-October-21
  • Gender:Male

Posted 2011-January-19, 09:52

I thought I did. No offense intended to whomever made the (obviously deliberate) choice, but was this thought out? People who are less computer savvy are more likely to choose a weak password, and accepting all capitalization would render such a password even weaker.
0

#15 User is offline   mtvesuvius 

  • Vesuvius the Violent Volcano
  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 3,216
  • Joined: 2008-December-04
  • Gender:Male
  • Location:Tampa-Area, Florida
  • Interests:SLEEPING

Posted 2011-January-19, 11:18

Who would want to hack a Bridge Forum? lol
Yay for the "Ignored Users" feature!
0

#16 User is offline   Antraxxx 

  • PipPipPip
  • Group: Full Members
  • Posts: 87
  • Joined: 2010-October-21
  • Gender:Male

Posted 2011-January-19, 13:29

I'm going to assume that was an honest question. Generally, everything on the internet, no matter how seemingly irrelevant, is tempting to attack. The attackers can be wannabe hackers in training - they often randomly choose forums (sometimes based on searching google for keywords and choosing randomly from the results) and try to deface them to "get their name out there", in a way. Sometimes they're politically motivated and are trying to get their message across no matter where, but this forum is likely not very good for that.
Another type of attacker that doesn't care about the target is people distributing malware. The odds of someone clicking a malicious link in a private message is considerably higher if it comes from a friend, rather than a newly registered member.
A third type is the standard "people hoping the password to your forum account is also the password to your email". If I can break down exhaustively searching someone's password to two phases, first of all guessing the letters in the right order then guessing the capitalization, I need significantly less computing power - it's like playing mastermind :)
0

#17 User is offline   Phil 

  • PipPipPipPipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 10,094
  • Joined: 2008-December-11
  • Gender:Male
  • Location:North Texas, USA
  • Interests:Mountain Biking

Posted 2011-January-19, 13:48

View Postmtvesuvius, on 2011-January-19, 11:18, said:

Who would want to hack a Bridge Forum? lol


I loathe the day that someone posts on BBF using the username P-H-I-I or P-C-I-A-Y-T-O-N. Not that anyone would even do that on the main site. Well, not recently anyway :angry: :P
Hi y'all!

Winner - BBO Challenge bracket #6 - February, 2017.
0

#18 User is offline   mtvesuvius 

  • Vesuvius the Violent Volcano
  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 3,216
  • Joined: 2008-December-04
  • Gender:Male
  • Location:Tampa-Area, Florida
  • Interests:SLEEPING

Posted 2011-January-19, 14:47

pciayton and phii is already taken :(
Yay for the "Ignored Users" feature!
0

#19 User is offline   Phil 

  • PipPipPipPipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 10,094
  • Joined: 2008-December-11
  • Gender:Male
  • Location:North Texas, USA
  • Interests:Mountain Biking

Posted 2011-January-19, 14:57

View Postmtvesuvius, on 2011-January-19, 14:47, said:

pciayton and phii is already taken :(


I won't bother to check if M-T-V-E-S-U-V-L-U-S is.
Hi y'all!

Winner - BBO Challenge bracket #6 - February, 2017.
0

#20 User is offline   mtvesuvius 

  • Vesuvius the Violent Volcano
  • PipPipPipPipPipPipPip
  • Group: Advanced Members
  • Posts: 3,216
  • Joined: 2008-December-04
  • Gender:Male
  • Location:Tampa-Area, Florida
  • Interests:SLEEPING

Posted 2011-January-19, 15:02

:)
Yay for the "Ignored Users" feature!
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users