SSL is one of the easiest things you can do to increase security, I just don't understand why the GPWA still havn't added it.
SSL is one of the easiest things you can do to increase security, I just don't understand why the GPWA still havn't added it.
"Many of life's failures are people who did not realize how close they were to success when they gave up"
-Shay- (28 October 2019), DanHorvat (28 October 2019), Former Member 14 (4 November 2019)
Great to see GPWA is back up. Really missed having this great resource.
drifter8 (28 October 2019)
SSL does not stop over 90% of attacks or hacks.
Rick
Universal4
Do get the SSL to protect the important users.
I kind of tried to phrase that so you know what I mean without having to explain the problem and the solution explicitly. You know what SSL is used against.
Ironically, this was an encrypted message sent over a non-encrypted connection.
Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.
-Shay- (29 October 2019)
-Shay- (29 October 2019)
Joining everyone about the SSL talk, it is important, there are many services that can help such as - https://letsencrypt.org/
Passwords are hashed, so any local exploit can result in getting emails and usernames.
Hacks where big money or an impact - say anonymous hacking the Pentagon - is made is usaully a result of social engineering. People-to-people contact, and getting into the network through acting as clients, fake employees etc. There's ton of ways.
SSL doesn't protect crap. If a slightly above-average hacking network wants to target you - you're a done deal. But you got to be worth their money and time.
universal4 (29 October 2019)
I edited my original post with the following additional information:
Separately, the issue of the use, or rather the current lack of use SSL on the GPWA website has been raised in this post. We did begin a project some time ago to convert to SSL, and I expect that project to be concluded soon. I will be reporting progress on that project in a separate thread. However, we firmly believe the fact that SSL is not currently used on the GPWA website was not exploited in the attack.
Michael
GPWA Executive Director, Casino City CEO, Friend to the Village Idiot
Resources for Affiliates: iGamingDirectory.com, iGamingAffiliatePrograms.com, GamingMeets.com
For those who aren't savvy to what all this means. The following person explains this far better than I could
https://security.stackexchange.com/u.../thomas-pornin
This is his post to a question about passwords and data sent over non SSL.
https://security.stackexchange.com/q...ssl-connection
When data is exchanged over the Internet, it hops from router to router, starting with the source (your desktop computer) and ending with the destination (the authentication server to which you are sending the password). All the routers, by definition, "see" the data. Moreover, all machines which are directly plugged with the link between any two routers can also see the data.
In practice, for low-level attackers, password sniffing mostly occurs through three mechanisms:
- Close to the user (you). E.g. you are using your laptop and connecting through a WiFi access point; other machines connected to the same access point see all your traffic. Note that "taking steps" to prevent such local attackers can be quite difficult (for instance, forget it is WiFi is involved).
- Close to the server. Typically, servers are mass-hosted in some shared facilities, and indelicate server owners may spy on their neighbours. Whether this is possible or even easy depends a lot on the competence of the network administrators at the hosting site.
- Through active redirection. When you want to connect to a server, you actually type a name, and then the DNS finds the IP address which corresponds to that name. Your machine will send the packets to that IP address. However, the DNS, as a whole, is poorly protected, and can be altered by malicious individual. A bad guy may then transparently redirect your packets to his own machines; he may even inspect the data but still forward it to their true destination, which makes him a Man-in-the-Middle. At that point, the attacker sees all the data, including the password and whatever the password protects, and can hijack the connection at any time.
All three kinds of sniffing can be put into practice, and are actually applied, by students with a few hundreds of dollars of budget and a lack of morality. More advanced criminals can employ other active methods, e.g. trying to disturb dynamic routing mechanisms. Or simply bribe employees at network facilities (in particular Internet Service Providers).
SSL (now known as "TLS") fixes things in several ways:
- It encrypts all the data with a key that only the two end points (your machine and the server) know, effectively keeping out passive eavesdroppers.
- It uses the server's certificate, so that the client can gain some confidence that it is indeed talking to the intended genuine server, not an attacker-controlled fake. This is the point of the padlock picture and the scary warnings in Web browsers.
- SSL ensures continuous integrity, meaning that an active attacker cannot simply put himself in MitM position, forward data bytes back and forth, and then hijack the connection after the authentication has taken place. The protection granted by SSL is both for confidentiality (data is unreadable by outsiders) and integrity (data cannot be altered by outsiders), and this encompasses the complete connection, not just the initial steps.
With SSL active and no certificate validation issue, you can send your password with reasonable guarantee that only the intended server will see it. How the server verifies the password is irrelevant here. Moreover, and again thanks to SSL, the server can assume that the initial authentication is valid for all subsequent traffic over the same connection, because SSL guarantees that it will be talking to the same client all along.
Last edited by Former Member 14; 30 October 2019 at 7:32 pm. Reason: edit
Good to see you all back again!
drifter8 (5 November 2019)
I suspect that this site and the servers are not out of the woods yet. Long load times and blocked access to home page...
There were two separate issues we dealt with over the weekend.
We switched the ad server used to serve advertisements on the GPWA website, changing from the OpenX to the Revive ad server platform. This has been planned for a while, and is one of the steps involved in our plans to migrate the GPWA website to use https. We had some hiccups during the transition where some materials needed to render ads were not available, and the result was sometimes significant delays in rendering pages on the site. Since then we have consistently made sure that all advertisements are served within iframes, so that any disruption in our advertising servers can never again have an adverse effect on rendering other parts of pages.
On another front, a file was corrupted very early this past Saturday morning. Out of an abundance of caution we shut down all external access to the site until we fully assessed the situation, corrected the file corruption, and determined it was safe to bring the site back up.
In terms of the question about whether we are out of the woods yet, the answer is no. We have a lot of projects underway to improve security and improve our disaster recovery capabilities. Those projects will take a while to complete.
Michael
GPWA Executive Director, Casino City CEO, Friend to the Village Idiot
Resources for Affiliates: iGamingDirectory.com, iGamingAffiliatePrograms.com, GamingMeets.com
allaboutthebets (12 November 2019), Cash Bonus (11 November 2019), GPWA Maria (11 November 2019)
Michael. I could be wrong. Correct me, if I am. But, it seems as if you do a lot of coding in-house.
This is despite the fact that the market is full of solutions. There is a software available for every type of task out there. I'm not sure of the scale you operate in, but it's quite unnecessary to code most of your own stuff, when cheaper and more secure options are roaming the streets.
This is say, in reference to CasinoCity.
-Shay- (12 November 2019)
oh... I'm happy to see you guys here! I was worried about you, caisu I can't access and I don't know why. so, congrats to all that one of the best forum is live!