<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;Insecure Discussion Forums “Login” link&amp;quot; in Community Site Feedback</title>
    <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307932#M7578</link>
    <description>Are members aware that the Discussion Forums “Login” link is insecure if using the Plusnet Login link? &lt;BR /&gt;Plusnet Home page = &lt;A href="https://www.plus.net/" target="_blank"&gt;https://www.plus.net/&lt;/A&gt; = Secure&lt;BR /&gt;Member Centre = &lt;A href="https://portal.plus.net/index_nlp.html" target="_blank"&gt;https://portal.plus.net/index_nlp.html&lt;/A&gt; = Secure&lt;BR /&gt;Discussion Forums = &lt;A href="http://community.plus.net/forum/" target="_blank"&gt;http://community.plus.net/forum/&lt;/A&gt; = OK for viewing only.&lt;BR /&gt;Clicking on the Discussion Forums link “Login” takes me to: - &lt;A href="http://community.plus.net/forum/index.php?action=login" target="_blank"&gt;http://community.plus.net/forum/index.php?action=login&lt;/A&gt; = Not secure.&lt;BR /&gt;I have created a favourite/bookmark (I should not have had to do this) to take me to &lt;A href="https://community.plus.net/forum/index.php?action=login" target="_blank"&gt;https://community.plus.net/forum/index.php?action=login&lt;/A&gt;&lt;BR /&gt;How many people are logging in to the Plusnet Community Site forums using the Plusnet provided “Login” link taking them to the insecure login page and then entering their username and password?&lt;BR /&gt;I have only been with Plusnet since February so how long has this breach been happening for and are Plusnet aware of it and sorting it?&lt;BR /&gt;Not good.&lt;BR /&gt;</description>
    <pubDate>Mon, 21 Mar 2016 16:36:31 GMT</pubDate>
    <dc:creator>Madeleyite</dc:creator>
    <dc:date>2016-03-21T16:36:31Z</dc:date>
    <item>
      <title>"Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307932#M7578</link>
      <description>Are members aware that the Discussion Forums “Login” link is insecure if using the Plusnet Login link? &lt;BR /&gt;Plusnet Home page = &lt;A href="https://www.plus.net/" target="_blank"&gt;https://www.plus.net/&lt;/A&gt; = Secure&lt;BR /&gt;Member Centre = &lt;A href="https://portal.plus.net/index_nlp.html" target="_blank"&gt;https://portal.plus.net/index_nlp.html&lt;/A&gt; = Secure&lt;BR /&gt;Discussion Forums = &lt;A href="http://community.plus.net/forum/" target="_blank"&gt;http://community.plus.net/forum/&lt;/A&gt; = OK for viewing only.&lt;BR /&gt;Clicking on the Discussion Forums link “Login” takes me to: - &lt;A href="http://community.plus.net/forum/index.php?action=login" target="_blank"&gt;http://community.plus.net/forum/index.php?action=login&lt;/A&gt; = Not secure.&lt;BR /&gt;I have created a favourite/bookmark (I should not have had to do this) to take me to &lt;A href="https://community.plus.net/forum/index.php?action=login" target="_blank"&gt;https://community.plus.net/forum/index.php?action=login&lt;/A&gt;&lt;BR /&gt;How many people are logging in to the Plusnet Community Site forums using the Plusnet provided “Login” link taking them to the insecure login page and then entering their username and password?&lt;BR /&gt;I have only been with Plusnet since February so how long has this breach been happening for and are Plusnet aware of it and sorting it?&lt;BR /&gt;Not good.&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Mar 2016 16:36:31 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307932#M7578</guid>
      <dc:creator>Madeleyite</dc:creator>
      <dc:date>2016-03-21T16:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307933#M7579</link>
      <description>Why should it use https - checking on the multiple forums I use and I only found one using it</description>
      <pubDate>Mon, 21 Mar 2016 16:41:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307933#M7579</guid>
      <dc:creator>Oldjim</dc:creator>
      <dc:date>2016-03-21T16:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307934#M7580</link>
      <description>https works fine on the forum..</description>
      <pubDate>Mon, 21 Mar 2016 16:43:23 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307934#M7580</guid>
      <dc:creator>dvorak</dc:creator>
      <dc:date>2016-03-21T16:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307935#M7581</link>
      <description>but you have to change it yourself as linking from the main site doesn't use it</description>
      <pubDate>Mon, 21 Mar 2016 16:46:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307935#M7581</guid>
      <dc:creator>Oldjim</dc:creator>
      <dc:date>2016-03-21T16:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307936#M7582</link>
      <description>Dunno, Jim - I logged into the forums so long ago I can't remember which link I used, but my header definitely reads 'https://'</description>
      <pubDate>Mon, 21 Mar 2016 16:50:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307936#M7582</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2016-03-21T16:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307937#M7583</link>
      <description>No http ot https shown in FF here but clicking on the little 'i' to the left of the address bar and I get a message that 'Connection is not secure'.</description>
      <pubDate>Mon, 21 Mar 2016 17:36:29 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307937#M7583</guid>
      <dc:creator>Mav</dc:creator>
      <dc:date>2016-03-21T17:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307938#M7584</link>
      <description>Are you sure that's not just telling you certain items on the page are insecure Mav? Things like externally hosted images in signatures blocks/avatars probably won't be.&lt;BR /&gt;The login link should force SSL IMO and I believe it will when the community gets upgraded in the not too distant future.</description>
      <pubDate>Mon, 21 Mar 2016 21:25:11 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307938#M7584</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2016-03-21T21:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307939#M7585</link>
      <description>Not sure so I've attached a screenshot:&lt;BR /&gt;&lt;IMG src="http://i67.tinypic.com/1z3wehy.jpg" /&gt;</description>
      <pubDate>Tue, 22 Mar 2016 00:36:01 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307939#M7585</guid>
      <dc:creator>Mav</dc:creator>
      <dc:date>2016-03-22T00:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307940#M7586</link>
      <description>As a publicly viewable site I guess having HTTP access makes some sense but I can't help thinking the login page, at least, should be HTTPS only.&lt;BR /&gt;What are the real risks of entering a username and password on a plain HTTP page?&amp;nbsp; (I ask because I genuinely don't really know)&lt;BR /&gt;In case anyone wants to state the obvious that unique usernames and passwords should be used for every different sites, we all probably know someone who doesn't do this so shouldn't all login pages be secure by default?</description>
      <pubDate>Tue, 22 Mar 2016 09:26:17 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307940#M7586</guid>
      <dc:creator>w23</dc:creator>
      <dc:date>2016-03-22T09:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307941#M7587</link>
      <description>New community's going live next week so this will become a non-issue (from a login perspective). @Mav, you're browsing over HTTP by the looks of things. You can force HTTPS by manually prefixing the URL with 'https://'.</description>
      <pubDate>Sat, 02 Apr 2016 11:06:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307941#M7587</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2016-04-02T11:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307942#M7588</link>
      <description>A bit moot now, really, but I have just added https:// before the URL.&lt;BR /&gt;I get a padlock with a red line through it and right-clicking still gives me a message 'Connection is not secure.'.&lt;BR /&gt;Not worth investigating but thought I'd post my results.&lt;BR /&gt;</description>
      <pubDate>Sat, 02 Apr 2016 11:14:03 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307942#M7588</guid>
      <dc:creator>Mav</dc:creator>
      <dc:date>2016-04-02T11:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307943#M7589</link>
      <description>There are some unsecured scripts</description>
      <pubDate>Sat, 02 Apr 2016 12:05:08 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307943#M7589</guid>
      <dc:creator>dvorak</dc:creator>
      <dc:date>2016-04-02T12:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307944#M7590</link>
      <description>Will the new site login page be https by default?</description>
      <pubDate>Sat, 02 Apr 2016 19:26:48 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307944#M7590</guid>
      <dc:creator>w23</dc:creator>
      <dc:date>2016-04-02T19:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: "Insecure Discussion Forums “Login” link"</title>
      <link>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307945#M7591</link>
      <description>The entire site should be https by default. Otherwise, your login cookie would be exposed the same way as the username and password would be if the login page isn't https.</description>
      <pubDate>Sat, 02 Apr 2016 19:32:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Community-Site-Feedback/quot-Insecure-Discussion-Forums-Login-link-quot/m-p/1307945#M7591</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2016-04-02T19:32:10Z</dc:date>
    </item>
  </channel>
</rss>

