| Free £25 Bet! | Free £25 Bet! |

In association with Sports-Punter Free Bets Odds Comparison BetHelp Limso
We are the Official Forum of FreeBetting.net & FCBet.com
| Sports News | Sports Stats | Live Scores | OddsChecker | Place Bets | Suggest a Site |
| |||||||
| Poker Chat Forum Here's where you talk about anything poker related, that doesn't belong in Tourneys or Strategy, but remember this is not for general chat. In Association with PokerTrillion |
![]() |
| | Thread Tools | Display Modes |
| | #1 (permalink) |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 18 Jun 2005
Posts: 35,261
| Not impressed - just clicked on Tournament Lobby in Mansion and IE opened with the following URL..... https://www.mansion.com/Content/Zulu...er=******&pass=******* I've edited the asterisks in...... Although this is secure (https) the password was visible in the url bar - what this means is that the Mansion software (Presume it's a network issue rather than a site issue) is storing my password in memory, unencrypted (or at the very least, bi-directional encryption) - seems incredibly lax to me ![]() |
| | |
| | #2 (permalink) | |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 13 Dec 2006
Posts: 2,016
| Quote:
![]() | |
| | |
| | #3 (permalink) |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 18 Jun 2005
Posts: 35,261
| I'm surprised there hasn't been more reaction to this - I view it as quite a major issue Don't know if I'm overreacting ![]() Just to be clear - here's a screen print of what's happening (edited out of course) ![]() I have searched my registry for the password as well as the contents of my hard drive, without finding it, so that's some comfort.... I dont have the "remember password" box ticked on login ![]() |
| | |
| | #4 (permalink) |
| Vienti Tres ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 06 Aug 2005 Location: On the road Age: 40
Posts: 13,477
| I've just logged into Mansion and clicked on some buttons but my default browser is Firefox and some pages open with the address bar blank. It is quite worrying but I'm not sure why exactly. ![]()
__________________ You can spend your time alone re digesting past regrets, Or you can come to terms and realize you're the only one who can forgive yourself. Makes much more sense to live in the present tense. |
| | |
| | #5 (permalink) |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 18 Jun 2005
Posts: 35,261
| It's not normal for anything to store passwords in such a way that they can be known - they are usually encrypted with a one way encryption method - one way meaning you can encrypt it, but cannot (in theory) decrypt it.... Even for something non financial like PL, the password database is stored with a one way encrytion algorythm - if someone forgets their pasword, we cannot find it, and we cannot tell them what it is - all we can do is set a new password.... For something that deals in financial information, I'm stunned that the program stores your password in such a way that it can access it.....if it's there it can be exploited...... I got onto live chat on Mansion earlier and they've passed it to their technical team - will post the response here ![]() Have tried some other skins on the network, and the others dont seem to have the same issue - only Mansion so far seems to do it - however ultimately I'd view the issue with the whole network - if the mansion software can get ahold of your password, then it has to be available within the software for any of the skins.... Might post it up on 2plus2, they're pretty good at investigating this kind of thing, and have far better technical people than me who can get to the bottom of whether it's really an issue or not (Will wait for the reply from the Mansion technical team first) |
| | |
| | #6 (permalink) |
| Punter Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 06 Jan 2002 Location: Auckland Age: 37
Posts: 10,920
| I do see your point, I'd not want it displayed on screen for security point of view, someone could shoulder surf me whilst logged in and get my passed. In terms of web security thouhgt, isn't it 128bt SSL or something, secure enough I'd guess ?? |
| | |
| | #7 (permalink) |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 18 Jun 2005
Posts: 35,261
| Within the browser, yes it's secure (https), and I dont think that's so much the issue ..... I'm more concerned that this shows that a decrypted/decryptable version of my password is available from my machine (and as you say, anyone who can see my screen) |
| | |
| | #8 (permalink) |
| Busy...but still Hawk-Eye ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 20 Mar 2006 Location: Still in League One
Posts: 6,691
| I've tried clicking on various options within Mansion (lobby options, my account, cashier....) and am not getting anything displaying my password or the address showing like GaF's screen. Maybe the problem is in the browser in use? (not that I know about these things. I'm on erm....BT Yahoo I think ).
__________________ http://pl-avongirl.blogspot.com/ |
| | |
| | #9 (permalink) | |
| Vienti Tres ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 06 Aug 2005 Location: On the road Age: 40
Posts: 13,477
| Quote:
You make a request for information through the poker client(?) The poker client accesses the web site and requests the information to be shown through your browser(?) Its strange the way it does it but does the fact that your details are shown in the address bar mean that they are available from your machine without following the above process? ![]()
__________________ You can spend your time alone re digesting past regrets, Or you can come to terms and realize you're the only one who can forgive yourself. Makes much more sense to live in the present tense. | |
| | |
| | #11 (permalink) | |
| God Punter ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 18 Jun 2005
Posts: 35,261
| Quote:
| |
| | |
| | #12 (permalink) |
| Busy...but still Hawk-Eye ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 20 Mar 2006 Location: Still in League One
Posts: 6,691
|
__________________ http://pl-avongirl.blogspot.com/ |
| | |
| | #14 (permalink) | |
| Clint's Back ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: 03 Nov 2005 Location: Blackburn Age: 33
Posts: 3,226
| Quote:
Mind you with not being able to get tourny lobby's and having tons of trouble withdrawing from my account(i don't possess the card that i deposited with anymore and have no bank records to give them,i just can't get any money out of there,even though i put in a token £10 through Neteller i can't withdraw) then i just think there a set of useless gimboids.
__________________ Lois, before I found these movies, women only made me cry through my penis. Now they make me cry through my eyes. Peter Griffin. | |
| | |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
| Partner Sites | |||||||||||
| Football Betting Tips | Australian Free Bets HOT | Free Bets | Odds Comparison | Soccer Punter |
| Bookmakers | Livescore | SoccerVista | Asian Handicap Betting Guide | Euroleague Betting Picks |
| Soccer Picks | Super-1 |
© 2008 PuntersLounge.Com Ltd | Gambling Problems?
Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.