Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests and 4 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow EH-Netarrow News Items and General Discussion About EH-Netarrow Registration Experience, and Security
Ethical Hacker Community Forums
December 01, 2008, 06:23:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Registration Experience, and Security  (Read 2256 times)
0 Members and 1 Guest are viewing this topic.
jyxavier
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: August 15, 2008, 12:35:07 AM »

I have been perusing the info on ethical hacker for awhile now, and have finally decided to register. When registering, I was a bit surprised with the password requirements requiring alphanumeric, and upper and lower case characters, but then I thought this is a site about security so it makes sense. When I went to my email to check the verification link, I was a bit surprised to find my password there as I generally don't like receiving my password in an email since a lot of email communication is sent clear text. I also noticed the login to the forums was clear text as well.

Maybe I am making a mountain out of a mole hill by creating a post on this. I am by no means a security expert, and just trying to get my foot in the in IT, and security. But I am kind of interested why the forums require such a secure password, when the transmission protocols aren't secure? From a more experience security experts perspective, why the higher security password requirement without encrypted login? I ask mainly for ongoing learning, and to gain a better grasp on a security mindset. I typically use a lower level password for forum logins because I have the expectation that the process isn't really all that secure. I know I didn't have to divulge any real private information, but was kind of intrigued by my experience with the registration process.
Logged
dalepearson
Full Member
***
Offline Offline

Posts: 153


View Profile
« Reply #1 on: August 15, 2008, 02:36:45 AM »

jyxavier, first of welcome to the forum, and I hope you enjoy your stay here.
Don is probably best to answer your questions (so please feel free to remove my post if it is incorrect), but I will take a quick shot at it.

Using an alphanumeric password, should always be best practice really, and this is something that the forum can require as a minimum and is set that way accordingly. Its not a bad habit to get into.

Sending your password in the email is probably a function of the forum tool on first setup. I see where you are coming from about the security aspect, but at the same time it is just a password for a forum, not bank account credentials, and now you are signed up you could change your password online (I assume that doesnt generate another mail).

As for the forums not using HTTPS, again this is a forum, I dont think I can think of any that use HTTPS for forum authentication. It costs more money to have a secure protocol in use, and adds a small performance overhead and it just wouldnt be justified.

Again enjoy your visit, dont be afraid of the search button, I am sure many questions have been asked before, but dont be afraid to ask. We are all here to help, just try and keep the questions ethical.


This post is secure Smiley I just hope the lock isnt shimable.
Logged

don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #2 on: August 15, 2008, 05:03:14 AM »

Welcome to EH-Net. Thanks for coming out of silent-lurker status. We need more people like you.

No problem at all asking about the process. dale pretty much explained my thinking. But to add to it (and I know it's in the forum somewhere) one must also follow the concept of the right tool for the job. You wouldn't secure your local library the way you would Fort Knox, just as you wouldn't use a jackhammer on your dishes (except when I cook).

We don't ask for anything but your email address. No SS#, CC#, etc. etc. And the password you use for this or any other public site should NEVER be the same as the ones for you bank account, corp network, etc.

That being said, I have batted the https idea around in my head. I may revisit it now that I am on my last day at my regular job, and am leaving to dedicate time to EH-Net, ChicagoCon and other projects of interest.

Hope this helps,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #3 on: August 15, 2008, 06:39:33 AM »

...I am on my last day at my regular job...

Nervous?
Logged

A little bit of sanity:
http://www.infosanity.co.uk
oneeyedcarmen
Full Member
***
Offline Offline

Posts: 205

Klaatu, Borada,Necktie?


View Profile
« Reply #4 on: August 15, 2008, 08:05:30 AM »

Quote from: don
And the password you use for this or any other public site should NEVER be the same as the ones for you bank account, corp network, etc.

...lest ye end up with all your goodies posted on seclists.org as some of our esteemed colleagues recently have.
Logged

MCP, Security+, Associate (ISC)2
jyxavier
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #5 on: August 15, 2008, 08:28:53 AM »

Thanks for the replies. So basically it is just a best practice to require alphanumerics, which is regardless of security of the transfer protocol. I don't use the same password for everything as I know most people do, so I'm not worried about anything.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.047 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.