Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   Pelican Parts is NOT a secure site (http://forums.pelicanparts.com/off-topic-discussions/1025742-pelican-parts-not-secure-site.html)

James Brown 04-05-2019 12:57 PM

Pelican Parts is NOT a secure site
 
lots of juicy info ripe for the picking, wonder why it's not secure or encrypted? Or does it matter.

Tervuren 04-05-2019 01:17 PM

It is publicly searchable.

Logic dictates that even with secure protocols that the nature of being public makes taking time for security a pointless effort.

Alan A 04-05-2019 01:36 PM

Quote:

Originally Posted by James Brown (Post 10417600)
lots of juicy info ripe for the picking, wonder why it's not secure or encrypted? Or does it matter.

You need a little more aluminium sheet in that hat methinks.
It’s a forum. Most forums are public.

Dmitry at Pelican Parts 04-05-2019 02:25 PM

We're still working on switching our forum to the 'secure' https:// version (but as others have mentioned, the security risk here is fairly low.. this isn't tied to our e-commerce system at all)

stomachmonkey 04-05-2019 02:29 PM

Quote:

Originally Posted by James Brown (Post 10417600)
lots of juicy info ripe for the picking, wonder why it's not secure or encrypted? Or does it matter.

I can find out more about virtually anyone here with a quick google search than can be gleaned from the data passed on this site.

Hint, ya'll are creatures of habit.

cabmandone 04-05-2019 02:38 PM

http://forums.pelicanparts.com/uploa...1554500288.jpg

emcon5 04-06-2019 04:21 PM

Quote:

Originally Posted by stomachmonkey (Post 10417710)
Hint, ya'll are creatures of habit.

Which is the problem. The only real vulnerability is the login, because the credentials are sent plain text.

The whole "creatures of habit" thing is when lazy people use the same username and password for multiple different things.

scottmandue 04-06-2019 04:42 PM

Quote:

Originally Posted by stomachmonkey (Post 10417710)
I can find out more about virtually anyone here with a quick google search than can be gleaned from the data passed on this site.

Hint, ya'll are creatures of habit.

I hacked into your blink... and those slippers do NOT go with that robe... just sayin!

stomachmonkey 04-06-2019 05:23 PM

Quote:

Originally Posted by emcon5 (Post 10418742)
Which is the problem. The only real vulnerability is the login, because the credentials are sent plain text.

The whole "creatures of habit" thing is when lazy people use the same username and password for multiple different things.


What I meant by “the data passed here” is people drop breadcrumbs about themselves in their posts. They drop some of the same breadcrumbs all over the internet. You just need to have a knack for spotting them.

I don’t even know my passwords.

I went to a password manager a while back.

Let it gereate random passwords every time I create a new account.

Opt in for two factor whenever it’s offered.

Use a security token app on any site that supports it.

Pelican not secure? Meh.

James Brown 04-06-2019 06:01 PM

well i get an alert from apple every time i sign in warning me my info is not secure on this site. little things like city, state, date of birth, friends/family names. The same things the DOD warn us about in cyber classes. thanks for working the security upgrades.

"We're still working on switching our forum to the 'secure' https:// version (but as others have mentioned, the security risk here is fairly low.. this isn't tied to our e-commerce system at all)"

cstreit 04-06-2019 06:51 PM

Quote:

Originally Posted by James Brown (Post 10418815)
well i get an alert from apple every time i sign in warning me my info is not secure on this site. little things like city, state, date of birth, friends/family names.

They're not secure anyway if you use any social media... Thats much easier to socially engineer then intercepting routed data traffic through a car forum.

KFC911 04-07-2019 05:37 AM

Apple....security? ...LOL ;)

Alan A 04-07-2019 05:45 AM

Quote:

Originally Posted by James Brown (Post 10418815)
well i get an alert from apple every time i sign in warning me my info is not secure on this site. little things like city, state, date of birth, friends/family names. The same things the DOD warn us about in cyber classes. thanks for working the security upgrades.

"We're still working on switching our forum to the 'secure' https:// version (but as others have mentioned, the security risk here is fairly low.. this isn't tied to our e-commerce system at all)"

That’s just a scam to sell certificates to web sites.
All it means is that TLS isn’t enabled. If anyone’s tapped into your connection or performing an MITM attack there’s more pressing issues than the thought that your posts or *gasp* your password could in theory be intercepted.


All times are GMT -8. The time now is 12:47 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.