• Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Normal Normal
    • 2013-07-22
    • None
    • Accounts, Admin

      The page where a user submits their username and password should be handled through HTTPS, to reduce the chance of username and passwords being intercepted, particularly when users are logging in at public hotspots over WiFi.

      Given that other sites like GMail and Facebook are now encrypting their entire traffic to overcome Firesheep (http://en.wikipedia.org/wiki/Firesheep) session cookie cloning attacks, it's seems very poor practice that passwords are being sent apparently in plain text.

          [MBS-2411] Login page should be encrypted (SSL/TLS)

          Kuno Woudt added a comment -

          Setting fix version to next release.

          This has been enabled on beta.musicbrainz.org, if it doesn't cause any problems there it should be enabled on production during the release.

          Kuno Woudt added a comment - Setting fix version to next release. This has been enabled on beta.musicbrainz.org, if it doesn't cause any problems there it should be enabled on production during the release.

          Ian McEwen added a comment -

          I am also removing the fix version – this needs to go forward, but it's definitely not in the next release.

          Ian McEwen added a comment - I am also removing the fix version – this needs to go forward, but it's definitely not in the next release.

          Ian McEwen added a comment -

          I don't know why this is marked as in review, but it's not, so I'm pulling it out

          Ian McEwen added a comment - I don't know why this is marked as in review, but it's not, so I'm pulling it out

          This is in review, but there is no open review. Status update please!

          Oliver Charles added a comment - This is in review, but there is no open review. Status update please!

          Kuno Woudt added a comment -

          Kuno Woudt added a comment - http://codereview.musicbrainz.org/r/2450/

          Kuno Woudt added a comment -

          TODO on this ticket:

          force SSL for login and registration.

          Kuno Woudt added a comment - TODO on this ticket: force SSL for login and registration.

          Ian McEwen added a comment -

          SSL is now available on production. There's at least one issue still, in that https://www.musicbrainz.org (in some situations) will redirect to non-SSL (http://codereview.musicbrainz.org/r/2395/) but the certificate is deployed and ready! SSL Labs test: https://www.ssllabs.com/ssltest/analyze.html?d=musicbrainz.org

          Ian McEwen added a comment - SSL is now available on production. There's at least one issue still, in that https://www.musicbrainz.org (in some situations) will redirect to non-SSL ( http://codereview.musicbrainz.org/r/2395/ ) but the certificate is deployed and ready! SSL Labs test: https://www.ssllabs.com/ssltest/analyze.html?d=musicbrainz.org

          The window for shipping this to beta testing has closed, so this will have to wait for the next release.

          Oliver Charles added a comment - The window for shipping this to beta testing has closed, so this will have to wait for the next release.

          Sadly there's a little more to do until we can ship this, so I'm pushing it to the next version.

          Oliver Charles added a comment - Sadly there's a little more to do until we can ship this, so I'm pushing it to the next version.

          Ian McEwen added a comment -

          https://www.ssllabs.com/ssltest/analyze.html?d=test.musicbrainz.org is the test page; the BEAST warning has to do with the fact we have a CBC ciphersuite listed first – and browsers have good workarounds for BEAST anyway. So, this is looking pretty good!

          Ian McEwen added a comment - https://www.ssllabs.com/ssltest/analyze.html?d=test.musicbrainz.org is the test page; the BEAST warning has to do with the fact we have a CBC ciphersuite listed first – and browsers have good workarounds for BEAST anyway. So, this is looking pretty good!

            warp Kuno Woudt
            Anonymous Anonymous
            Votes:
            9 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2013-07-22