4 ms·
They connect on port 80 (HTTP instead of HTTPS) on startup. That's unacceptable for a privacy company.
by mobitar 9y ago
They connect on port 80 (HTTP instead of HTTPS) on startup. That's unacceptable for a privacy company.
- nilved 9y agoIt's worse than that. Back when I used PIA a few years ago, they would pass your username and password around in the query string, completely plain-text. That was their session mechanism. I sent them an email explaining the problem and got a refund. Their security mistakes, and the fact that they are based in the US, disqualify them for me. I really wish people would recommend someone else.
- Kadin 9y agoI would be interested to know more about this; why they were doing it at the time and if it's still being done. The use of port 80 is not really important; I'm not sure if the article's author is using "port 80" as shorthand for "unencrypted" but that's sloppy writing if so; you can certainly establish encrypted connections over port 80, of course. I used to do SSH on port 80 all the time to get around stupid firewalls...
- Hnrobert42 9y agoRasengan answers above the port 80 call is for non-sensitive data and is signed.
- jwfxpr 9y ago> That's unacceptable for a privacy company. Why? The fact of a connection being established in port 80 is to do with how TCP/IP works. You aren't even claiming to understand what protocol is in use on port 80, not to mention whether the data is in the clear, what it is for, etc. This isn't analysis, it's... something far short of analysis that I can't think of a kind name for.
- deleted 9y ago[deleted]
- jlgaddis 9y agoThat, in and of itself, is not an issue. Your browsers, for example, download Certificate Revocation Lists over plain-text HTTP as well -- but they are digitally signed.