Bugzilla – Bug 6702
Security issues with SN
Last modified: 2016-11-27 20:45:48 UTC
Customer wrote this email to me today. I noticed that signing in to Squeezenetwork it is not an HTTPS connection. Also, when setting passwords on pay service Internet radio, such as Pandora, there is no security. This means that the words 'password', 'username' and our passwords and usernames themselves are going from your users to your servers unencrypted. I work in the Internet routing community, and know for a fact how easy it is to filter off this information. I am sure that many people are using the same passwords for more important accounts. SSL/TLS security is very simple to implement on the web server login/password/user info pages. I think you have a responsibilty to protect yourselves and your users information. Could you PLEASE change this AS SOON AS POSSIBLE? I love my Squeezebox and all the related services....... please keep your users safe and happy!
This is a dup of 10041, but I can't make that change anymore.
This is also the case at the website http://www.mysqueezebox.com The login credentials you enter in your browser get sent in the clear.
We need to update the certificate. But LMS 7.7.6+ is now using https if possible.