Author Topic: * Security *  (Read 2035 times)

0 Members and 1 Guest are viewing this topic.

Offline Hyperacme

  • Administrator
  • Hero Member
  • *****
  • Posts: 13608
* Security *
« on: September 27, 2019, 10:14:16 AM »
Doran can explain this better then I can …
Our forum software doesn't have the best security .. So might be a good idea to change your password to something stronger and different from any other password you use for other sites.
My password for the forum wasn't very "Strong" so made some changes.

Also …
Got a email in my spam folder from "Cafepress" saying they had a "Data Security Incident".
So might be  a good idea to change your password there also.
I don't know if this is true or some kind of spam/fishing …


Offline dorelse

  • Administrator
  • Hero Member
  • *****
  • Posts: 5987
Re: * Security *
« Reply #1 on: September 27, 2019, 10:05:33 PM »
Yeah, let me help.

Our site is using http, not https.  So...when you log into the forums...your password is sent in plain text to log in...therefore, if someone were tracing your keystrokes (its called a keystroke logger/keylogger/logger) or looking at your network traffic...your password to the forums would be exposed.  Http is older technology and not secure, https encrypts the traffic and is scrambled (ie, more secure).

All that is typically fine since we're just a boating site.  Where it gets you into trouble is IF you use the same password for multiple sites.

SO..here's a very simple rule.  When you're logging into the forums here, your password to this site needs to be unique to only this site.

Since its plain text, a complex password is better to prevent a hack, but if your keystrokes are being logged, that won't really matter.  (though better, random is always better)

Implementing https is a bit more complicated (and costs money)...hopefully we'll get it implemented someday, but until then, best to be safe.  (We do keep up to date on security patches for the forums btw, but http isn't the highest level.)

Follow this one rule:  Use a password unique to this site, and this site only.   That way...if someone does get your password to this site, the damage is only to this site. 


Thanks guys!

(that's why Chrome says 'Not Secure' in red in the URL)



« Last Edit: September 27, 2019, 10:11:06 PM by dorelse »
1990 Sierra 1700

Offline Hyperacme

  • Administrator
  • Hero Member
  • *****
  • Posts: 13608
Re: * Security *
« Reply #2 on: September 27, 2019, 10:17:43 PM »
Thank you Doran ..
Has any one else gotten a email from Cafepress ?

Offline Villager19

  • Full Member
  • ***
  • Posts: 97
Re: * Security *
« Reply #3 on: September 28, 2019, 04:28:03 PM »
I haven't received any sort of notification from cafepress.

On my browser it shows https //

Illinois Dave

1979 Glastron Carlson CVX-18
2014 Crownline 215 SS

Offline Terry_Curran

  • Donate members
  • Hero Member
  • *****
  • Posts: 567
Re: * Security *
« Reply #4 on: September 29, 2019, 08:09:21 AM »
I received the same email as Gregg

Offline Mrs.TheDeuceMan

  • Donate members
  • Hero Member
  • *****
  • Posts: 1092
Re: * Security *
« Reply #5 on: September 29, 2019, 10:23:18 AM »
I also got the email from cafepress


Sent from my iPhone using Tapatalk Pro
1990 Glastron Futura V249