Website security problems (https not enforced) - Fuelly Forums

Click here to see important news regarding the aCar App

Reply
 
Thread Tools Display Modes
 
Old 08-28-2014, 08:04 AM   #1
qqq
Registered Member
 
Join Date: Jun 2011
Posts: 2
Country: United States
Website security problems (https not enforced)

When you visit http://www.fuelly.com, the site allows you to log in or change your password and submits that over http. Fuelly should enforce https at least for these actions, if not for the whole site. The workaround is to always visit https://www.fuelly.com instead.
__________________

qqq is offline   Reply With Quote
Old 08-30-2014, 01:32 PM   #2
Registered Member
 
RobertV's Avatar
 
Join Date: Feb 2013
Posts: 1,900
Country: United States
Location: San Antonio, TX
We may be moving to all https soon, but this has been noted for review.
Thanks!
__________________

RobertV is offline   Reply With Quote
Old 09-01-2014, 01:39 PM   #3
qqq
Registered Member
 
Join Date: Jun 2011
Posts: 2
Country: United States
Thanks for the response!
qqq is offline   Reply With Quote
Old 09-05-2014, 06:43 AM   #4
Registered Member
 
Join Date: May 2012
Posts: 1
Country: United States
Location: Grand Marais, MN
+1 for this... the login page is currently not forced to https, which is a big risk for anyone on public wifi networks.
shadowhand is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


» Fuelly iOS Apps
Powered by vBadvanced CMPS v3.2.3


All times are GMT -8. The time now is 12:25 AM.


Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2024, vBulletin Solutions, Inc.