Community discussions

MikroTik App
 
rmichael
Forum Veteran
Forum Veteran
Topic Author
Posts: 718
Joined: Sun Mar 08, 2009 11:00 pm

FORUM SECURITY request

Thu Dec 30, 2010 4:01 am

Could you please enable SSL encryption on the login page so the passwords are encrypted? I'm too lazy to change my password every time I access this forum through via open WIFI.

thank you.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: FORUM SECURITY request

Thu Dec 30, 2010 4:06 am

+1

There really isn't any reason anymore to not run the whole thing via SSL, not just the login pages. Slap an accelerator card into the server and the penalty on the server becomes negligible.
Yeah, VPN on open networks, blah blah, I'm too lazy for that, too.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26815
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: FORUM SECURITY request

Thu Dec 30, 2010 7:38 am

I don't think PHPBB supports this.
 
blake
Member
Member
Posts: 426
Joined: Mon May 31, 2010 10:46 pm
Location: Arizona

Re: FORUM SECURITY request

Thu Dec 30, 2010 10:07 am

I don't think PHPBB supports this.
Look under 'Cookie Secure.'
http://www.phpbb.com/support/documentat ... er_cookies

And Server Protocol…
http://www.phpbb.com/support/documentat ... r_settings
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26815
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: FORUM SECURITY request

Thu Dec 30, 2010 10:15 am

this would result in all forum running on https all the time, it would be a massive performance impact.
 
rmichael
Forum Veteran
Forum Veteran
Topic Author
Posts: 718
Joined: Sun Mar 08, 2009 11:00 pm

Re: FORUM SECURITY request

Thu Dec 30, 2010 10:23 am

I don't think PHPBB supports this.
You can use http rewrite to send only logins to https server:

http://www.phpbb.com/community/viewtopi ... 5&start=15
 
dssmiktik
Forum Veteran
Forum Veteran
Posts: 732
Joined: Fri Aug 17, 2007 8:42 am

Re: FORUM SECURITY request

Fri Dec 31, 2010 1:07 pm

I also have been wanting this for awhile now too. SSL is the way to go for login/password forms at least.
 
changeip
Forum Guru
Forum Guru
Posts: 3833
Joined: Fri May 28, 2004 5:22 pm

Re: FORUM SECURITY request

Fri Dec 31, 2010 6:31 pm

Think about it. If you are using open wifi without a vpn back to somewhere safe then your just asking for trouble. The MT forums have little to do with security at that point :) Having SSL would be nice of course.
 
rmichael
Forum Veteran
Forum Veteran
Topic Author
Posts: 718
Joined: Sun Mar 08, 2009 11:00 pm

Re: FORUM SECURITY request

Sun Jan 02, 2011 7:54 am

All shared hosting sites prohibit proxies and vpns/ssh tunnels (except a few that are running thor and are using your traffic as a smoke screen) . Collocated servers, vps or even ec2 are pretty expensive.

That said I don't think VPN would be a substitute for https - especially now that ISPs are very much into data mining.

Who is online

Users browsing this forum: Bing [Bot], McSee, RobertsN, silviub, smirgo and 38 guests