HTTPS is a must in our days

  • Christian Chat is a moderated online Christian community allowing Christians around the world to fellowship with each other in real time chat via webcam, voice, and text, with the Christian Chat app. You can also start or participate in a Bible-based discussion here in the Christian Chat Forums, where members can also share with each other their own videos, pictures, or favorite Christian music.

    If you are a Christian and need encouragement and fellowship, we're here for you! If you are not a Christian but interested in knowing more about Jesus our Lord, you're also welcome! Want to know what the Bible says, and how you can apply it to your life? Join us!

    To make new Christian friends now around the world, click here to join Christian Chat.

trofimus

Senior Member
Aug 17, 2015
10,684
794
113
Christian chat does not use https even for the login! So the password goes unencrypted through your (public) wifi.

Of course, emails, PM etc, too.
 
Last edited:
And I think its very easy to implement, some ssl keys are even free. Its really worth it.
 
I don't know for sure, but I imagine that vBulletin are the ones that would have to implement that
 
I don't know for sure, but I imagine that vBulletin are the ones that would have to implement that

I do not know what they use internally for forums, emails, PM and flash chat. But if people trust them with their emails, personal messages, personal profiles and passwords (and some of them pay real money for that service) administrators should take steps leading to their protection.

As I say, mainly today, when most of people connect through wi-fi or from various public places in city.
 
The reason this site doesn't need it is because there is no information worth taking. So, people who hack aren't typically going to waste their time other than to troll the site.

In terms of passwords, it is wise to use a unique password for every site you visit -- one could even use a password manager like last pass to make this, well, manageable. But, at minimum, for sites like these you should use password that only applies to unimportant sites -- don't use your bank login password or anything important like that (obviously).
 
The reason this site doesn't need it is because there is no information worth taking. So, people who hack aren't typically going to waste their time other than to troll the site.

In terms of passwords, it is wise to use a unique password for every site you visit -- one could even use a password manager like last pass to make this, well, manageable. But, at minimum, for sites like these you should use password that only applies to unimportant sites -- don't use your bank login password or anything important like that (obviously).

So instead of making the web page work properly we will need to just accept the fact that this password can be stolen anytime and make sure we use it only for this page and not for others?

And just accept the fact, that our ISP or anyone else in a cafe can read whatever we send in emails or PM?

This is not the right stance. Mistakes should be corrected, not accepted.

Even free services like free emails or game registration pages have https as the basic security precaution. It is standard these days.
 
Well basic rule of thumb for the past decade or more is don't use the same password twice. People who do accept the risks.
Though I do find it funny how you are so offended by this, but yet keep coming on. Hmmmmmm.............
 
I mean don't get me wrong this is a good idea to implement but not so terrifying as it is made out to be.
 
Good heavens! No ssl in 2016. Thanks op for this post, i didn't even notice this till now. Admin will you please do something to ensure that some fanatic doesnt hack our personal details i.e. essentially unguarded.
For Safety you MUST have https esp for logins. How else are you going to hide passwords from hackers??