Made with Love

Quick bit about online safety

  • Thread starter Thread starter Warl0ck
  • Start date Start date
W

Warl0ck

Guest
When you are logging into ANY site you should always make sure the site is using TLS (formerly called SSL). TLS = Transport Layer Security and in laymen terms it means your browser is allowing a secure session with the host server. You can tell this because up where you type Google you'll see it says Google

There are varying levels of security. For example go to the list of sites below and compare what you see up in the corner of the address area of the browser.

Google
Toronto Escorts, Canada Escorts, Independent Escorts, Erotic Massage, Review Board

Toronto Escort and Massage Reviews

then

www.pof.com


Now if you notice to the left of the URL (Google) you will see it says "SECURE" (using Chrome) in the first two examples. In the second it's secure but some photos, etc may not be. In www.pof.com there is no security. That means when you log in your password transmits in clear text (not cipher text) and anyone sniffing can see it . So is someone had a backdoor to the server, they could capture all that data.
 
:good: I never knew that :Crying2:

Many people don't. If you notice next to the URL, you'll see a bunch of symbols. You can click on them and it will give you a message in plain language what it means. Plenty of Fish is a great example of bad #Infosec. It did not use TLS (secure login) for years. And it mailed you your password in plain text. Anytime you go to submit ANY information across the internet, make sure it's not

Websites have what are called "certificates" which are issued to prove the site is who they say they are. Google.com is a good example of a secure site that's gone through all the hoops to prove it's who it says it is. Invalid certificates = danger and could be a "man in the middle" attack mean to collect your personal information. The concept of asymmetrical and symmetrical encryption is beyond the scope of this forum, but that's basically what this refers too.

Here is an example of when a site's certificate is bad and you should NOT proceed forward. Expired certificate windows - Google Search
 
When I right click on the little icon in the top left corner of a website without a Secure or green lock icon, I get a message that says "Your connection to this site is not fully secure. Attackers might be able to see the images you're looking at on this site and trick you by modifying them."

In contrast (thank you HUBGFE Admins) HUBGFE says "Secure connection. Your information (for example passwords, or credit card numbers) is private when it is sent to this site."
 
[h=1]Check if a site's connection is secure[/h]To see whether a website is safe to visit, you can check for security info about the site. Chrome will alert you if you can’t visit the site safely or privately.

  1. Open a page in Chrome on your computer.
  2. To check a site's security, to the left of the web address, look at the security status:
    • Secure
    • Info or Not secure
    • Not secure or Dangerous
  3. To see the site's details and permissions, click the icon. At the top of the panel, you'll see a summary of how private Chrome thinks the connection is.

[h=2]Fix "Your connection is not private" error[/h]If you see a full-page error message saying "Your connection is not private," your Internet connection or your computer isn't letting Chrome open the page securely. Learn how to troubleshoot "Your connection is not private" errors.
[h=2]What a security certificate is[/h]When you go to a site that uses HTTPS (connection security), the website's server uses a certificate to prove the website's identity to browsers, like Chrome. Anyone can create a certificate claiming to be whatever website they want.
To help you stay on safe on the web, Chrome requires websites to use certificates from trusted organizations.

 
Using HTTPS is no guarantee of security; as mentioned, certificates can be bought by anyone, or even spoofed or faked. Best bet: turn off the computer and go visit a lady. More secure.
 
As a FYI, when I click on the icon for the Alberta board this is the notification I get, and the log in page is not secure either:

Your connection to this site is not secure.

You should not enter any sensitive information on this site (for example passwords or credit cards) because it could be stolen by attackers.
 
So who is right or which one is it?.

Technically nothing is 100% secure. You cannot guarantee it. But there are ways to minimize risk. A certificate issued by a known CA is likely to be trusted. And it's likely to be secure. IT security is multi-layered. There are a whole bunch of factors involved including the user equation.
 
Well, someone has been trying to log into my account today. Thank you HUBGFE for the email warning. :good:

[FONT=wf_segoe-ui_normal]
Failed Login Notification on Canada Escort Review Forum and SP Directory

Canada Escort Review Forum and SP Directory <[email protected]>

Today, 7:21 AM


Dear escapefromstress,

Someone has tried to log into your account on Canada Escort Review Forum and SP Directory with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.

The person trying to log into your account had the following IP address:
209.171.**.*

All the best,
Canada Escort Review Forum and SP Directory

 
I tracked the IP and it says they're located in Woodbridge. Where the heck is that?
 
Woodbridge is a community just north of the city of Toronto.
 
WTF!! This angers me, cowards! Sorry to go off track but anyone sneaking around, and that is what trying to hack into someones accounts is, is a coward, bully and useless. If you have a problem with someone have the guts to face the person! Or is that to hard....All this online bullying and hacking is getting on my last nerve. I hope those doing it realize they're aren't invincible and they can be found and convicted.It is a crime.
 
If you're concerned with people logging into your account make sure you have a strong password. Also HUBGFE offers 2FA for added security. It uses Google authenticator.
 
If you're concerned with people logging into your account make sure you have a strong password. Also HUBGFE offers 2FA for added security. It uses Google authenticator.

I am impressed. For those not sure what 2FA means, it's Two Factor Authentication. It means you type in your password and another code at the same time (given by Google Authenticator). Without both you cannot log in.

As for a password, M@k31tT0ugh for people to crack or guess. If you use password questions "What is your Mom's maiden name", don't. Same for birth date. Use false information and write it down. A major bank with a green logo still uses those type of questions which baffles me. For safe email, use Gmail as it has 2FA. I believe that Outlook.com does too.

Now, it IS possible to hack 2FA, but it requires major effort. Black activist @deray had his phone & mail hacked but he used 2FA. If I recall the hackers had to call and socially engineer his phone company. They did because THEY USED those stupid "What is your Mom's maiden name" type question. Kevin Mitnick even commented to the guy. Mitnick = The Jesus of hacking. He is a legendary hacker who was on the run from the FBI and hid in plain site. He now owns a company which has a 100% success rate hacking it's clients. He has several good books including Ghost in the Wires.
 
If you have a hard time coming up with your own passwords, there's sites like this one that will generate them for you. Remember to record it somewhere safe.

Strong Password Generator
 
Back
Top Bottom