Secure login on the website

Started by UncleMion

UncleMion Lv 1

The website doesn't use https when users log in. It somewhat removes the benefit of forcing strong passwords if they'll just be sent unencrypted.

(I was able to use https://fold.it/ by typing it into the address bar, and clicking links keeps me in https, but once I submit a form it usually switches me back to http)

Makes me wonder: does the game itself use secure connections?

UncleMion

spmm Lv 1

not sure if this is still a problem for anyone, if not we can close it.

brow42 Lv 1

I haven't sniffed the packets for my password, but we do know that the client does set up SSL. Presumably before it sends the password.

The client is next scheduled to turn into a pumpkin in 9 months (April 27, 2014).