Active
Project:
ACS Technologies
Version:
6.x-1.0-alpha3
Component:
ACS Auth Module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
1 Aug 2010 at 01:19 UTC
Updated:
3 Mar 2011 at 14:06 UTC
All pages taking in a username/password that could be an ACS account should go through an ssl (https) connection. Otherwise we are opening up their username/password to be sniffed. This could lead to personal information in ACS being obtained by a 3rd party who shouldn't have it.
Comments
Comment #1
esbon commentedI am concerned about the same thing, but don't these modules solve the problem? Secure Pages and Secure Pages Hijack Prevention. We use these modules on an e commerce site with ubercart and never had any problems.
mfer, would these 2 modules be enough? Any other suggestions to secure logins? Thanks for developing the module!