Discussion Forum: Thread 206445

 Author: tylerawalters View Messages Posted By tylerawalters
 Posted: Jun 9, 2016 08:31
 Subject: Why isn't the main page secure (https)?
 Viewed: 167 times
 Topic: Suggestions
 Status:Implemented
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

tylerawalters (718)

Location:  USA, North Carolina
Member Since Contact Type Status
Feb 7, 2013 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: MiniFigs & More
As far as I know, the main page has never been secure – at least not as long
as I've been a member. Given that this is where most people log in, this
is a huge problem. Their credentials are being sent over an unsecured connection.
Given that this site has had hacking issues in the past, one would think that
this would have been addressed by now. I'm disappointed to see in the new
design that this issue has not been addressed.

Not only is this bad for Bricklink's current users, but it makes the site
look amateurish to potential members, which in turn keeps them from being customers.

Please address this as soon as possible. Security shouldn't be seen as an
optional feature. It should be seen as mandatory for every site.
 Author: cosmicray View Messages Posted By cosmicray
 Posted: Jun 9, 2016 09:13
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 48 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

cosmicray (3484)

Location:  USA, Florida
Member Since Contact Type Status Collage
Oct 1, 2000 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
View Collage Pic
Store: Cosmic Toys
In Suggestions, tylerawalters writes:
  As far as I know, the main page has never been secure – at least not as long
as I've been a member. Given that this is where most people log in, this
is a huge problem. Their credentials are being sent over an unsecured connection.
Given that this site has had hacking issues in the past, one would think that
this would have been addressed by now. I'm disappointed to see in the new
design that this issue has not been addressed.

Not only is this bad for Bricklink's current users, but it makes the site
look amateurish to potential members, which in turn keeps them from being customers.

Please address this as soon as possible. Security shouldn't be seen as an
optional feature. It should be seen as mandatory for every site.

In the year of our lord 2016, this is an absolute necessary item.

Ray
 Author: tGo_lego View Messages Posted By tGo_lego
 Posted: Jun 9, 2016 14:55
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 36 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

tGo_lego (26)

Location:  USA, Arizona
Member Since Contact Type Status
May 8, 2016 Contact Member Buyer
Buying Privileges - OK
agree 1000%
 Author: therobo View Messages Posted By therobo
 Posted: Jun 9, 2016 16:40
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 61 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

therobo (9679)

Location:  Germany, Berlin
Member Since Contact Type Status
Oct 20, 2001 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Area of Bricks 'n Studs
In Suggestions, tylerawalters writes:
  As far as I know, the main page has never been secure – at least not as long
as I've been a member. Given that this is where most people log in, this
is a huge problem. Their credentials are being sent over an unsecured connection.
Given that this site has had hacking issues in the past, one would think that
this would have been addressed by now. I'm disappointed to see in the new
design that this issue has not been addressed.

Not only is this bad for Bricklink's current users, but it makes the site
look amateurish to potential members, which in turn keeps them from being customers.

Please address this as soon as possible. Security shouldn't be seen as an
optional feature. It should be seen as mandatory for every site.

I already addressed that when they released the preview site.
I was told that this is not part of the redesign.
My workaround is to have a bookmark to MyBrickLink.
If not logged in it gives you a https login page (as it used to).
 Author: ToddMyers View Messages Posted By ToddMyers
 Posted: Jun 9, 2016 19:31
 Subject: (Cancelled)
 Viewed: 47 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

ToddMyers (356)

Location:  USA, Ohio
Member Since Contact Type Status
Feb 7, 2013 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Myers Sets
(Cancelled)
 Author: therobo View Messages Posted By therobo
 Posted: Jun 10, 2016 05:03
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 37 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

therobo (9679)

Location:  Germany, Berlin
Member Since Contact Type Status
Oct 20, 2001 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Area of Bricks 'n Studs
In Suggestions, ToddMyers writes:
  In Suggestions, therobo writes:

  I was told that this is not part of the redesign.

Between this gem and the comment from Bricklink to another user that mobile views
are not supported by the site, I'm just blown away by the sheer incompetence
of it all. Whoever made these two decisions should be escorted off the premises.
Is there such a thing as web development malpractice?

SMH

Original quote:
"The security issue has not been neglected. However, we cannot tackle all
issues at once. This has by no means been de-prioritized. It just means that
it is simply not a part of the project you are speaking about. The preview release
is simply the preview release and is meant as a face-lift to bring the website
up to modern times and make it easier for new users. The security issue will
be addressed separately, but it is most definitely not being ignored. This is
just protocol. If we were to try to address all issues at once there would be
no organization among the company."
 Author: ToddMyers View Messages Posted By ToddMyers
 Posted: Jun 10, 2016 07:03
 Subject: (Cancelled)
 Viewed: 39 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

ToddMyers (356)

Location:  USA, Ohio
Member Since Contact Type Status
Feb 7, 2013 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Myers Sets
(Cancelled)
 Author: WoutR View Messages Posted By WoutR
 Posted: Jun 10, 2016 17:21
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 36 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

WoutR (919)

Location:  Netherlands, Zuid-Holland
Member Since Contact Type Status
Mar 8, 2011 Contact Member Buyer
Buying Privileges - OK
In Suggestions, ToddMyers writes:
  In Suggestions, therobo writes:

  I was told that this is not part of the redesign.

Between this gem and the comment from Bricklink to another user that mobile views
are not supported by the site, I'm just blown away by the sheer incompetence
of it all. Whoever made these two decisions should be escorted off the premises.
Is there such a thing as web development malpractice?

SMH

Looking at how many features on the new design depend on hovering over an item,
I am not surprised that there is no support for anything mobile, tablet or using
touch screen.

Did we just upgrade from 1999 to 2006?
 Author: tylerawalters View Messages Posted By tylerawalters
 Posted: Jun 9, 2016 20:40
 Subject: Re: Why isn't the main page secure (https)?
 Viewed: 50 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

tylerawalters (718)

Location:  USA, North Carolina
Member Since Contact Type Status
Feb 7, 2013 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: MiniFigs & More
That's not an acceptable answer. I just go to another page too, but most
people will not. The fact they have secure methods of logging in means they have
the capability to do it here as well. Any hole in security makes all of us insecure
– not just those who log in with the insecure page.

Security is a requirement for all sites. This is not something that should ever
be seen as optional. Ever.

This is highly disappointing.

In Suggestions, therobo writes:
  In Suggestions, tylerawalters writes:
  As far as I know, the main page has never been secure – at least not as long
as I've been a member. Given that this is where most people log in, this
is a huge problem. Their credentials are being sent over an unsecured connection.
Given that this site has had hacking issues in the past, one would think that
this would have been addressed by now. I'm disappointed to see in the new
design that this issue has not been addressed.

Not only is this bad for Bricklink's current users, but it makes the site
look amateurish to potential members, which in turn keeps them from being customers.

Please address this as soon as possible. Security shouldn't be seen as an
optional feature. It should be seen as mandatory for every site.

I already addressed that when they released the preview site.
I was told that this is not part of the redesign.
My workaround is to have a bookmark to MyBrickLink.
If not logged in it gives you a https login page (as it used to).
 Author: tylerawalters View Messages Posted By tylerawalters
 Posted: Jun 9, 2016 20:55
 Subject: (Cancelled)
 Viewed: 33 times
 Topic: Suggestions
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

tylerawalters (718)

Location:  USA, North Carolina
Member Since Contact Type Status
Feb 7, 2013 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: MiniFigs & More
(Cancelled)