Jump to content

Suggestion: Default to https for entire site to avoid MITM attacks


Nx01King

Recommended Posts

I use the secure form of http when I connect to the site only for it to be downgraded upon logging in at nexusmods (dot) com proper. This is a security and privacy risk as username and passwords are out in the clear. Meaning the site, our information, can be subject MITM attacks! I can force https for the whole site but downloads would break due to them being unsecured, http.

 

Fixing these two issues would ensure:

1) confidence in the users being who they are and not some bots through compromised accounts.

1) confidence in the files uploaded and downloaded being what they are meant to be. (still scan though)

 

Thank you for this lovely site and community.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...