Jump to content

Photo

When logging in, password is transmitted in cleartext


  • Please log in to reply
No replies to this topic

#1
Non Sequitur

Non Sequitur

    Journeyman

  • Members
  • Pip
  • 34 posts
I noticed in a packet capture today that Nexus login information (username & password) is sent over the net unencrypted. I'm sure the Nexus admins are aware of this, but I was just surprised and curious as to why you don't use SSL for logging in, given the obvious security problems associated with shouting your password across the Internet. I know SSL can be a pain to set up, especially for large sites.




Page loaded in: 1.266 seconds