Bug 6702 - Security issues with SN
: Security issues with SN
Status: RESOLVED FIXED
Product: MySqueezebox.com
Classification: Unclassified
Component: Signon
: unspecified
: PC Windows XP
: P2 normal with 1 vote (vote)
: Future
Assigned To: Andy Grundman
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2008-01-21 12:09 UTC by Anoop Mehta
Modified: 2016-11-27 20:45 UTC (History)
1 user (show)

See Also:
Category: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Anoop Mehta 2008-01-21 12:09:41 UTC
Customer wrote this email to me today. 

I noticed that signing in to Squeezenetwork it is not an HTTPS connection.  
Also, when setting passwords on pay service Internet radio, such as Pandora, there is no security.  This means that the words 'password', 'username' and our passwords and usernames themselves are going from your users to your servers unencrypted.  I work in the Internet routing community, and know for a fact how easy it is to filter off this information.  I am sure that many people are using the same passwords for  more important accounts.  SSL/TLS security is very simple to implement on the web server login/password/user info pages.  I think you have a responsibilty to protect yourselves and your users information.  Could you PLEASE change this AS SOON AS POSSIBLE?  I love my Squeezebox and all the related services....... please keep your users safe and happy!
Comment 1 Blackketter Dean 2009-10-10 08:19:08 UTC
This is a dup of 10041, but I can't make that change anymore.
Comment 2 jwdevel 2011-09-06 14:54:40 UTC
This is also the case at the website http://www.mysqueezebox.com

The login credentials you enter in your browser get sent in the clear.
Comment 3 Michael Herger 2016-11-27 20:45:48 UTC
We need to update the certificate. But LMS 7.7.6+ is now using https if possible.