Retro Information Safety On Non-SSL retros

TheRealMoonman

I eat babies
Sep 30, 2014
360
74
Sorry if this is in the wrong section, but I do believe it is a issue that must be addressed in regards to the safety of user information on Non-SSL retros.
POC:


The point of this thread is not to try portray retros without SSL like they are trying to get you're information, I'm just trying to suggest you exercise more caution, because most are still in their little skid dos warfare phase.
 

MayoMayn

BestDev
Oct 18, 2016
1,423
683
Sorry if this is in the wrong section, but I do believe it is a issue that must be addressed in regards to the safety of user information on Non-SSL retros.
POC:


The point of this thread is not to try portray retros without SSL like they are trying to get you're information, I'm just trying to suggest you exercise more caution, because most are still in their little skid dos warfare phase.
Using CF Flexible SSL doesnt protect shit neither.
What you're doing doesnt matter if they have SSL or not, since you're just checking the request headers that you sent.
 

TheRealMoonman

I eat babies
Sep 30, 2014
360
74
Using CF Flexible SSL doesnt protect shit neither
Rip, I never tested that because I haven't got a SSL enabled domain on any VPS, I was just using Aux's for POC, but i assumed SSL would be protected due to prior experience with session hijacking at McDonalds lmfao
 

MayoMayn

BestDev
Oct 18, 2016
1,423
683
Rip, I never tested that because I haven't got a SSL enabled domain on any VPS, I was just using Aux's for POC, but i assumed SSL would be protected due to prior experience with session hijacking at McDonalds lmfao
You're simply just "recording" request headers which can be done on any website, so SSL or not that is pretty useless, as it only works for your network.
 

CosmoPeak

PeakRP.com
May 15, 2016
271
268
This is how the internet works... The client sends the password to the server. SSL encrypts the data between the client and the server. The data is still decrypted at the end of the connection and the hotel owner can do whatever they want with the password. I think you're misunderstanding here.
 

TheRealMoonman

I eat babies
Sep 30, 2014
360
74
This is how the internet works... The client sends the password to the server. SSL encrypts the data between the client and the server. The data is still decrypted at the end of the connection and the hotel owner can do whatever they want with the password. I think you're misunderstanding here.
I know how SSL works, I should of just made the title different, its basically spreading just trying spreading awareness of what could happen and idk why I thought having no SSL would contribute to the matter.
 

Weasel

👄 I'd intercept me
Nov 25, 2011
4,132
2,456
I know how SSL works, I should of just made the title different, its basically spreading just trying spreading awareness of what could happen and idk why I thought having no SSL would contribute to the matter.
The possibility of 2 users of a retro that aren't family members or close friends to be on the same network and wanting to hack the other is almost impossible. Retro's don't need an SSL connection.
 

MayoMayn

BestDev
Oct 18, 2016
1,423
683
The possibility of 2 users of a retro that aren't family members or close friends to be on the same network and want to hack the other is almost impossible. Retro's don't need an SSL connection.
Especially a CF Flexible "SSL" just makes it even worse.
 

Default

https://forcehotel.org
Oct 9, 2011
74
16
SSL for a retro is a waste of money.
All the big ones still use cloudflare.
I'd rather know that users can visit my site in confidence that their data is safe and that it isn't a phishing site.. rather than avoiding it, also if you get a lot of profit on your site because users see that https on the address bar then that small price for an SSL certificate was totally worth it
 

Sledmore

Chaturbate Livestreamer
Staff member
FindRetros Moderator
Jul 24, 2010
5,194
3,901
Good luck to newbies using LetsEncrypt when they're on a Windows VPS.

Tbh, that is even easier! :p There is like 4 reputable clients made for Windows. They're just simple shell scripts, that you press the stage number for and it's done in a heartbeat.
 

MayoMayn

BestDev
Oct 18, 2016
1,423
683
Tbh, that is even easier! :p There is like 4 reputable clients made for Windows. They're just simple shell scripts, that you press the stage number for and it's done in a heartbeat.
Oh shit, I always thought it was a hell generating keys on Windows.
Well, it is a hell using CLI.
 

Users who are viewing this thread

Top