5 ms·
Haha. Very sensitive code over http!
by gprasanth 13y ago
Haha. Very sensitive code over http!
- theboss 13y agoNot even just the code....your password and email are both over http.......
- jimktrains2 13y agoThe form action for login appears to be https, but not the code... I don't know why people bother not just httpsing everything if they have the cert. It avoids these types of worries and appearance.
- Torgo 13y agoThe cert is expired anyway.
- jimktrains2 13y agoI didn't even check. It expired in Jan 2013....wow I'm betting the project isn't maintained anymore?
- logn 13y agoThe whois record mentions a contact at http://www.digital-z.net/ http://www.digital-z.net/ which returns <html> <head> <title>One...</title> </head> <body> <center> May you live in not too interesting dreams.<br> Thank you and good night.<br> </center> </body> </html> ... which would indicate they're gone. And the deadmansswitch.org has a footer that points to http://binarymonkey.com http://binarymonkey.com which has a 2008 copyright date. In one year the app's domain will expire which could be unfortunate if anyone expected an actual dead man's switch.
- Houshalter 13y agoThe bottom of the site says copyright 2014.
- blueskin_ 13y agoThat could just be using a date() -type function.
- theboss 13y agoThe form action for registration is not https. Also, they have nothing to prevent a MITM from changing where the form action goes. Why would anyone use this...
- jimktrains2 13y agoI see this: <form method="post" action="https://deadmansswitch.org/userhome.html"> Email:<br /> <input type="text" name="email" /><br /> Password:<br /> <input type="password" name="password" /><br /> <input type="submit" name="login" value="Log in" /><br /> <a href="/createaccount.html" title="Create an account">Create an account</a> </form> Also, what does/can anyone do to prevent a MITM attack? Even if thy sent a HSTS header or a redirect, they're still subject to that.
- theboss 13y agoThat is the login form. I'm not sure how to paste code onto hacker news so here is a pastebin of the registration form. http://pastebin.com/Ctkw6S2h http://pastebin.com/Ctkw6S2h Well a better practice would be all HTTPS for the site. There are a lot of problems with this and I will probably write a blog post about it. Everything about this site misses every best practice. 1. No CSRF tokens 2. Small secret tokens to trigger the switch. 3. passwords over http... It's a joke.
- jimktrains2 13y ago/me is unable to read :( sorry abotu that Yeah, it is. Especially since their cert is over a year dead.