Page 1 of 1

Should I be worried?

Posted: Thu Mar 07, 2024 10:13 am
by Ian Fitzpatrick
Logging on this morning (and yesterday) :_

Web Protection by Bitdefender
This page was blocked for your protection
http://www.c4countdown.co.uk/ucp.php?mode=login

An attempt to send your password unencrypted, in plain text, was prevented on this page. View more details in the Notifications area of your Bitdefender security solution.

Re: Should I be worried?

Posted: Thu Mar 07, 2024 11:00 am
by Gavin Chipper
Seems a bit weird. Is that a forum thing or local to you, do you think?

Re: Should I be worried?

Posted: Thu Mar 07, 2024 12:52 pm
by Ian Volante
Might be something to do with the lack of https. I'm unable to visit a different forum from my work machine which doesn't have this feature; I presume I can only use this place because it's either set up better, or it's locally hosted.

Re: Should I be worried?

Posted: Thu Mar 07, 2024 12:57 pm
by Graeme Cole
c4countdown.co.uk still uses unencrypted HTTP rather than HTTPS. I suspect this has always been the case and we've only just noticed.

I think C4C ought to have HTTPS and an SSL certificate like Apterous and most other websites do nowadays. AFAIK Charlie controls the domain so only he can set that up.

Re: Should I be worried?

Posted: Thu Mar 07, 2024 1:03 pm
by Fiona T
yeah don't use the same password for c4c as your bank...

Re: Should I be worried?

Posted: Thu Mar 07, 2024 1:14 pm
by Graeme Cole
I've opened an Apterous ticket. It seems strange to raise tickets on Apterous for things related to C4C, but precedent exists.

Re: Should I be worried?

Posted: Fri Mar 08, 2024 10:15 am
by Ian Fitzpatrick
Graeme Cole wrote: Thu Mar 07, 2024 1:14 pm I've opened an Apterous ticket. It seems strange to raise tickets on Apterous for things related to C4C, but precedent exists.
thanks Graeme

Re: Should I be worried?

Posted: Thu Mar 21, 2024 4:33 pm
by Arthur Page
Hmm, just received this message this morning
https://drive.google.com/file/d/1E8jogo ... p=drivesdk
Fortunately I use a nonce password for this website but I would definitely be careful if you use the same password and email for other websites.

Re: Should I be worried?

Posted: Thu Mar 21, 2024 6:00 pm
by Mark Deeks
Fortunately I use a nonce password
(hehe)

Re: Should I be worried?

Posted: Thu Mar 21, 2024 6:05 pm
by Gavin Chipper
Mark Deeks wrote: Thu Mar 21, 2024 6:00 pm
Fortunately I use a nonce password
(hehe)
Nonce passwords are kept more secure, for obvious reasons. Mine is J1mmy5av1l3.

Re: Should I be worried?

Posted: Sat Mar 23, 2024 12:57 pm
by Gavin Chipper
I was reading a random article about Bitcoin and it mentioned nonce and that it meant single-use, so there you go. It's not something you readily Google. (I could have looked it up in a print dictionary obviously.)

Re: Should I be worried?

Posted: Sat Mar 23, 2024 1:40 pm
by Arthur Page
Gavin Chipper wrote: Sat Mar 23, 2024 12:57 pm I was reading a random article about Bitcoin and it mentioned nonce and that it meant single-use, so there you go. It's not something you readily Google. (I could have looked it up in a print dictionary obviously.)
Better to have a nonce password than a nonce username imo ;)