Jump to content

Candle Security


Recommended Posts

Hi All,

 

Okay, one of my Software engineer friends figured this out ... if you wish to share a link to a specific Candle thread, please do not copy the URL when you are in POST mode, i.e. in the middle of posting to the thread. This will enable anyone with that link to POST responses to that thread under your ID.

 

*sigh* that was an eye-opening and humbling experience when he told me. I never would have thought of it.

 

P.J.

Link to comment

Hmm... well if the urls are that persistent to encode a login, given that http is used, that means anyone going through a logged proxy can be impersoniated by anyone with access to the proxy logs then?

And since https is not used for the login, nor even digest security, there are lots of security holes I would bet.

Link to comment

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
×
×
  • Create New...