dhlab-epfl / dhwriter

11 stars 2 forks source link

Insecure log in and account creation #11

Closed m4n closed 10 years ago

m4n commented 10 years ago

Because there currently is no SSL encryption (https), passwords are submtted as clear text when logging in or registering an account.

cyrilbornet commented 10 years ago

This is a deployment feature and is not specifically related to dhwriter. We activated https on dhwriter.org, so please feel free to use it :-)

m4n commented 10 years ago

Going to https://dhwriter.org I am presented with a browser alert saying that the security certificate is invalid (error code: ssl_error_bad_cert_domain).

Closing this as invalid/wontfix won't help. It is still an issue. A big one. One that can be fixed.

cyrilbornet commented 10 years ago

As said before this is a deployment/server issue, so it doesn't have to be listed here. If you still feel it's an issue for your personal use you are free to deploy your own copy of dhwriter and use it to redact your dh2014 abstract.