Southwestern Ontario Media Forum

You are not logged in. Would you like to login or register?



February 6, 2016 5:24 PM  #1


IT Security: Re: Radio & other forums

First I must predicate, this is NOT me questioning the motivations of the moderator of this forum.  I believe the forum moderator set this forum up simply to allow the exchange of ideas.  /end

This is more for you, the employee, in radio using these forums.  When login features on this forum & others are not encrypted (there is no SSL).  That means your password travels in plain text viewable for anyone who wants it.  Further, the private messaging feature is also not secure.  That means whatever information you send in these type of forums could be readable by others.  Given I see people logging into this forum all the time but never posting, I will assume they're using the private messaging feature.  Further, these forums are "canned" packages and often have vulnerabilities.  Anyone remember the old Quad where I was often attacked?  It had a vulnerability where you could extract the IP from a post.  I knew who was attacking me & could have easily sent in the posts to their IT department (they were actually stupid enough to post from "work"). 

And overall when it comes to forum, live by the adage "trust no one". Don't imagine a fake email address or name is a form of security.  It's not.  A couple years ago two Southern Ontario forums (not radio forums) got into a real tit for tat.  Now, normally when you log into a forum your password is "hashed".  The hash is your password when it's encrypted.  The forum in question did not hash the passwords, but let them in plain text.  The moderator of the forum knew that people often "recycle" passwords so his assumption was that if you signed into forum A (his rival) with a email and password, you likely used the same one with his forum.  And he was right.  He then used that information to email users & spread lies about the other forum, intimidate people & even extort them. 

This is a very dog eat dog business now & friends become enemies.  Use caution when communicating to each other on ANY radio forum.  Don't imagine you are anonymous. Ever.  Even when you use Tor. 
 

 

February 6, 2016 8:25 PM  #2


Re: IT Security: Re: Radio & other forums

Hathaway wrote:

First I must predicate, this is NOT me questioning the motivations of the moderator of this forum.  I believe the forum moderator set this forum up simply to allow the exchange of ideas.  /end 

Add in the word "respectful" ahead of "exchange" and Hathaway has it correct. 

 

Board footera

 

Powered by Boardhost. Create a Free Forum