"artofmemory.com" login/browsing is completely unencrypted. Please acquire an SSL cert for this domain

3 posts / 0 new
Last post
#1 29 December, 2015 - 08:26
Offline
Joined: 1 year 10 months ago

"artofmemory.com" login/browsing is completely unencrypted. Please acquire an SSL cert for this domain


The entire signup/browsing of "artofmemory.com" is completely unencrypted. Just by sniffing packets from someone browsing this website on some public wifi network it is trivial to steal their credentials/browser sessions and act as these people. It's doubly worse since authentication also doesn't appear to be encrypted for people who are using the same password on this site as they are on other websites.

I would be happy to throw in a few bucks to help fund the SSL cert and I'm sure several others on this forum would as well.

Thanks :)

--
shuff

29 December, 2015 - 09:38
Offline
Joined: 2 years 8 months ago

I was thinking about using this. Any thoughts on that service or is it better to buy one?

29 December, 2015 - 19:42
Offline
Joined: 1 year 10 months ago

I'm a huge fan of the let's encrypt project and its mission. If the service is actually available for websites to use then yeah -- I would say go ahead. If it isn't (I don't think it currently is), then buying one is the only other option. I personally have used godaddy for my own personal certs for tiny websites, and it is only because that is where I've registered my domains, and I just didn't really want to mess with any other sites. Once letsencrypt is publicly available I will definitely be moving my personal cert over to it to show my support for the project (not necessarily because of the cost of the cert).

Download our free ebook! Just click the "Sign up" button below to create an account, and we'll send you a free ebook with tips on how to get started.

Related content: