I'm on gaiaonline right now and i keep refreshing my internet browser and move to different parts of the site and apparently i keep still getting the slash throught the HTTPS. and the lock before it has an x on it.
go to this link for a picture of it.
http://tinypic.com/r/330bk39/7
Results 1 to 12 of 12
Thread: Gaia online now unsecured???
- 01 Jun. 2011 03:51pm #1
Gaia online now unsecured???
Last edited by granturismo; 01 Jun. 2011 at 04:02pm.
- 01 Jun. 2011 03:53pm #2
I don't remember Gaia ever fully supporting HTTPS.
- 01 Jun. 2011 03:56pm #3
well they did it just looks like a regular HTTPs with nothing going through it or the lock saying secured website but the regular sites have just HTTP thats it but gaia right now has a slash through it and may be a breaking point for us to steal some stuff from it like account info or some other crap like that.
- 01 Jun. 2011 04:39pm #4
I'm pretty sure the only way that makes a difference is if you can intercept someone logging into Gaia. Like Firesheep or whatever.
I thought so. It's never fully supported https. None of the links on the page are loaded via HTTPS. Clicking on any link will take you back to http://whatever vs https://whatever.
Last edited by Personoid; 01 Jun. 2011 at 04:54pm.
- 01 Jun. 2011 04:56pm #5
true but it was regularly not like this like it is now.
- 01 Jun. 2011 04:57pm #6
When you visit Gaia normally, it doesn't load with HTTPS.
i.e. Typing "gaiaonline.com" into the address bar doesn't result in https://www.gaiaonline.com/ . It's just http://www.gaiaonline.com
- 02 Jun. 2011 02:58am #7
The most likely scenario is that they're attempting to load a non-secure image/css/js file. i.e. from https:// they're attempting to load a resource using the http:// protocol. I guess, technically, it is a bit of a concern, as someone monitoring your network would be able to retrieve the session id stored in a cookie sent with the request. However, I would be very surprised if the login system system went from https -> http, so your username and password should be safe.
It's only really an issue if you're on an open or insecure network.
- 02 Jun. 2011 04:01pm #8
https://gaiaonline.com/auth/login actually does contain a form that submits to http://gaiaonline.com/auth/login and all links on pages loaded with https:// actually lead to unsecured pages.
- 02 Jun. 2011 04:08pm #9
agreed but lets find out why xD
- 02 Jun. 2011 04:48pm #10
- 02 Jun. 2011 04:50pm #11
ohh so thats why its so easy to hack them xD
- 02 Jun. 2011 04:59pm #12
No, the only way you can hack someone because of this is via Man-in-the-middle attack - Wikipedia, the free encyclopedia.