Solved

Password fields present on an insecure (http://) page. This is a security risk that allows user login credentials to be stolen.

Posted on 2014-09-08
9
8,699 Views
Last Modified: 2014-09-24
I get this error in firefox   I don't know what it is or how to fix it
0
Comment
Question by:vrosas_03
  • 5
  • 4
9 Comments
 
LVL 83

Accepted Solution

by:
Dave Baldwin earned 333 total points
ID: 40311037
No, the security risk is when they are sent to a page using HTTP instead of HTTPS.  If it is your website, you should fix it although there are many many pages with logins that do not use HTTPS.  If it is not your website, then you need to decide whether or not to go there.  Although I login to all kinds of pages, I have never seen that warning.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40311038
So you have a login form/inputs on an http page

Solution:
Have your login form on a secure page https

Many websites do it, but remember normal people don't have Firebug running so they never see that message
0
 
LVL 58

Expert Comment

by:Gary
ID: 40311057
No, the security risk is when they are sent to a page using HTTP instead of HTTPS
Gonna disagree, the tunnel could have already been intercepted and posting to https is not gonna make a difference at that point.
0
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 333 total points
ID: 40311090
the tunnel could have already been intercepted
What does that mean?  If I put up a login form and someone types their password into the form, at that point it has not even left their computer.  If the 'action' page is 'https://...', the first thing that happens when they submit the form is that an encrypted connection is negotiated Before any data is sent.

The most important part about HTTPS is that the connection is encrypted before Any data is sent.  No data is sent in the clear with an HTTPS connection.
0
3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

 
LVL 58

Expert Comment

by:Gary
ID: 40311097
Because the target could have already been replaced, the connection may be secure but the connection to where?
If it's loaded on an SSL connection to start with then it cannot be altered.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 40311131
That's one I never thought of.  But I guess if there is enough money involved, someone will try that.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40311140
Doesn't need that much money involved, pop into the local cafe with wi-fi, you could probably pick up login details and other stuff and Joe Bloggs would never know.

30 minutes later you could be ordering all kinds of things - worst case scenario I know but...has happened.
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 167 total points
ID: 40311143
http://www.ehacking.net/2013/06/irisking-security-by-not-securing-login.html

p.s.
I have an unsecure login form on one site, but I don't store any personal information. Still bad form on my part.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 40311421
I don't WiFi anywhere.  I have a wireless router though I don't use it for any of my own business.  Last time I checked, there were 52 wireless networks here.
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Advice on making a YouTube video that generates traffic 7 77
MySQL database data submission 7 59
Animated .jpg? 13 60
Office 365 Pass Username an Password in URL 3 43
Why do we like using grid based layouts in website design? Let's look at the live examples of websites and compare them to grid based WordPress themes.
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
This video teaches users how to migrate an existing Wordpress website to a new domain.
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now