<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Plusnet Member Centre not secure! in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272952#M66113</link>
    <description>Please sort out Plusnet as the member centre login is not secure see below:&lt;BR /&gt;</description>
    <pubDate>Tue, 10 Nov 2015 17:45:15 GMT</pubDate>
    <dc:creator>goldenfibre</dc:creator>
    <dc:date>2015-11-10T17:45:15Z</dc:date>
    <item>
      <title>Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272952#M66113</link>
      <description>Please sort out Plusnet as the member centre login is not secure see below:&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2015 17:45:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272952#M66113</guid>
      <dc:creator>goldenfibre</dc:creator>
      <dc:date>2015-11-10T17:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272953#M66114</link>
      <description>I've had the attached available in Waterfox for a long time.</description>
      <pubDate>Tue, 10 Nov 2015 18:10:58 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272953#M66114</guid>
      <dc:creator>Strat</dc:creator>
      <dc:date>2015-11-10T18:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272954#M66115</link>
      <description>For the member centre login, from the Browser console it's:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;18:15:50.662 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online.gif" on a secure page[Learn More] mTag.js:1:0&lt;BR /&gt;18:15:50.665 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online-9-9.gif" on a secure page[Learn More] mTag.js:1:0&lt;BR /&gt;18:15:50.667 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online-busy.gif" on a secure page[Learn More] mTag.js:1:0&lt;BR /&gt;18:15:50.669 Loading mixed (insecure) display content "http://sales.liveperson.net/visitor/liveperson/chat-button/transparent.gif" on a secure page[Learn More]&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;i.e. images related to live chat</description>
      <pubDate>Tue, 10 Nov 2015 18:24:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272954#M66115</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2015-11-10T18:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272955#M66116</link>
      <description>Which doesn't make the rest insecure, right?</description>
      <pubDate>Tue, 10 Nov 2015 19:34:40 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272955#M66116</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2015-11-10T19:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272956#M66117</link>
      <description>Well, it can't be that bad, because Firefox loaded the images anyway.&lt;BR /&gt;Unlike the google analytics javascript that Firefox blocks if you browse these forums over https.&lt;BR /&gt;The padlock status colour does look worse for the mixed content allowed case though.</description>
      <pubDate>Tue, 10 Nov 2015 20:01:38 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272956#M66117</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2015-11-10T20:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272957#M66118</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;What is mixed content?&lt;BR /&gt;HTTP is a system for transmitting information from a web server to your browser. HTTP is not secure, so when you visit a page served over HTTP, your connection is open for eavesdropping and man-in-the-middle attacks. Most websites are served over HTTP because they don't involve passing sensitive information back and forth and do not need to be secured.&lt;BR /&gt;When you visit a page fully transmitted over HTTPS (green padlock in the address bar), like your bank, your connection is authenticated and encrypted and hence safeguarded from eavesdroppers and man-in-the-middle attacks.&lt;BR /&gt;However, if the HTTPS page you visit includes HTTP content, the HTTP portion can be read or modified by attackers, even though the main page is served over HTTPS. When an HTTPS page has HTTP content, we call that content “mixed”. The page you are visiting is only partially encrypted and even though it appears to be secure, it isn't. &lt;BR /&gt;&lt;BR /&gt;What are the risks of mixed content?&lt;BR /&gt;An attacker can replace the HTTP content on the page you're visiting in order to steal your credentials, take over your account, acquire sensitive data about you, or attempt to install malware on your computer. &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 10 Nov 2015 20:33:54 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272957#M66118</guid>
      <dc:creator>jelv</dc:creator>
      <dc:date>2015-11-10T20:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272958#M66119</link>
      <description>Unsecured images are the least of the problems with their TLS setup.&lt;BR /&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=portal.plus.net&amp;amp;s=212.159.8.2&amp;amp;hideResults=on" target="_blank"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=portal.plus.net&amp;amp;s=212.159.8.2&amp;amp;hideResults=on&lt;/A&gt;&lt;BR /&gt;They still support RC4 (broken), are only using TLS 1.0, use common 1024 primes (logjam) and don’t support the modern cipher suites. If plusnet are running the latest apache and openssl then it’s a easy fix.&lt;BR /&gt;&lt;A href="https://mozilla.github.io/server-side-tls/ssl-config-generator/" target="_blank"&gt;https://mozilla.github.io/server-side-tls/ssl-config-generator/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://weakdh.org/sysadmin.html" target="_blank"&gt;https://weakdh.org/sysadmin.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2015 21:15:32 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272958#M66119</guid>
      <dc:creator>OB</dc:creator>
      <dc:date>2015-11-10T21:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272959#M66120</link>
      <description>Oh, so we are going to see a TalkTalk next week then maybe &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@6BD5E1FD9194A889D807C8E641344CF1/images/emoticons/sad.gif" alt="Sad" title="Sad" /&gt;</description>
      <pubDate>Thu, 12 Nov 2015 04:00:35 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272959#M66120</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2015-11-12T04:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272960#M66121</link>
      <description>Given TalkTalk's recent experiences they will have been/will be considerably tightening things up. Plusnet's way has always been to take action after it all blows up in their face - scheduled improvements (unless it's something marketing driven) always take for ages (secure email?).&lt;BR /&gt;So yes, if security of ISP systems is a major concern I'd say moving to TalkTalk would be a very smart move.</description>
      <pubDate>Thu, 12 Nov 2015 08:58:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272960#M66121</guid>
      <dc:creator>jelv</dc:creator>
      <dc:date>2015-11-12T08:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Member Centre not secure!</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272961#M66122</link>
      <description>Google Analytics is also set to protocol absolute instead of protocol relative meaning it always loads in http and on some browsers throws a security warning, it's also a very old version of GA code that was deprecated well over a year ago...</description>
      <pubDate>Fri, 13 Nov 2015 10:50:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Member-Centre-not-secure/m-p/1272961#M66122</guid>
      <dc:creator>drunkenmonkey</dc:creator>
      <dc:date>2015-11-13T10:50:15Z</dc:date>
    </item>
  </channel>
</rss>

