[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-07-09 Thread anatoly techtonik
anatoly techtonik added the comment: https does help those with security knowledge to login safely. -- nosy: +techtonik ___ PSF Meta Tracker metatrac...@psf.upfronthosting.co.za http://psf.upfronthosting.co.za/roundup/meta/issue518

[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-06-28 Thread R David Murray
R David Murray added the comment: As Martin (I think) has said, just how damaging would compromising this password be? Tracker changes are all reversible. On the other hand I'm in favor of using https in general. This was discussed on the infrastructure list, and the issue is that bugs is

[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-06-28 Thread R David Murray
R David Murray added the comment: Well, yes, I know that is common. Unfortunately, https doesn't solve that lack of security knowledge, since if one account gets cracked because of insecure servers, the rest of their accounts are also compromised.