Closed Thread
Page 1 of 2 1 2 LastLast
Results 1 to 10 of 15

Thread: No SSL on login?

  1. #1
    Nifty
    Join Date
    Jul 2016
    Posts
    52
    World
    Sandycove

    Exclamation No SSL on login?

    I'm getting a warning on the login screen that there is no SSL and in addition a warning on the password reset screen that there is no SSL.

    The lack of SSL on the main site is one thing but to have no SSL on password screens is unacceptable.

  2. #2
    Ruler of the Land TheVictorious's Avatar
    Join Date
    May 2012
    Posts
    1,078
    World
    Sandycove
    Yeah got same issue, it is not really good thing or even minor, I noticed even with https and valid certificate, it is redirect you to normal http, someone seems forgot to comment or uncomment code in main site
    Hello People

  3. #3
    Wordsmith Durin_d's Avatar
    Join Date
    Mar 2012
    Location
    FIN
    Posts
    744
    World
    Northisle
    The homepage is not secured with SSL but the login is still done with a SSL secured request.

    You can see it if you follow the network traffic of your browser when you press the login button.

  4. #4
    Community Manager
    Ruler of the Land BB_Saqui's Avatar
    Join Date
    Aug 2016
    Posts
    1,790
    World
    Newfoundland
    Quote Originally Posted by Durin_d View Post
    The homepage is not secured with SSL but the login is still done with a SSL secured request.

    You can see it if you follow the network traffic of your browser when you press the login button.
    This is true, as well any transactions on the shop.

  5. #5
    Erudite Pioneer
    Join Date
    May 2012
    Posts
    98
    World
    Newfoundland
    The login for this game is insecure (as it has always been). The login request over SSL only protects against a passive listener from seeing your password. A man-in-the middle (can for example be anyone offering wifi) can quite easily intercept the login credentials by changing the (unprotected) login from to NOT use SSL anymore or to submit it to a different site, owned by the attacker (which could possibly also redirect/relay the request to the real server, such that everything appears normal and people don't get suspicious).

    So it is good when a browser warns for this.
    It is bad that even if you try to login securely by requesting the site via https (which the server accepts) you get redirected back to the http version.

  6. #6
    Ruler of the Land Xibor's Avatar
    Join Date
    Sep 2014
    Location
    New Zealand
    Posts
    2,258
    World
    Sandycove
    Use a unique password for the game. Then you have very little risk. Anything can be hacked. Absolutely anything - if the attacker is skilled and interested enough.

    Please don't use the same password for (example) your banking and your gaming. That's just asking for it.

    Also, I recommend a low balance credit card (I have one I use online with only a $750 limit). Even though most of the time banks will back you up if you claim a fraud, it helps prevent large hassles.
    Sorry, but I've slept since then...

  7. #7
    Nifty
    Join Date
    Jul 2016
    Posts
    52
    World
    Sandycove
    Doing some more research and the problem is that you have not provided the protection against a man in the middle attacker from extracting the password
    Last edited by BB_Saqui; 10.03.17 at 11:14. Reason: Link deleted

  8. #8
    Ruler of the Land TheVictorious's Avatar
    Join Date
    May 2012
    Posts
    1,078
    World
    Sandycove
    Quote Originally Posted by BB_Saqui View Post
    This is true, as well any transactions on the shop.
    Our issue is lately we get this box when we try to login:
    Hello People

  9. #9
    Community Manager
    Ruler of the Land BB_Saqui's Avatar
    Join Date
    Aug 2016
    Posts
    1,790
    World
    Newfoundland
    Quote Originally Posted by TheVictorious View Post
    Our issue is lately we get this box when we try to login:
    You will see this error because not all of our website uses HTTPS. However, all the important stuff like shops, logins, etc are all secured with HTTPS. If you'd like to verify this, you can pull up confirmation via a browser's console on those respective pages.

    As for that popup box: you can either completely ignore it, or click "learn more" and there should be a way to whitelist the site.

  10. #10
    Ruler of the Land TheVictorious's Avatar
    Join Date
    May 2012
    Posts
    1,078
    World
    Sandycove
    Quote Originally Posted by BB_Saqui View Post
    You will see this error because not all of our website uses HTTPS. However, all the important stuff like shops, logins, etc are all secured with HTTPS. If you'd like to verify this, you can pull up confirmation via a browser's console on those respective pages.

    As for that popup box: you can either completely ignore it, or click "learn more" and there should be a way to whitelist the site.
    I understand, but it was not here before, it is new maybe with the newest versions?
    also, in chrome update 56 added this:


    I don't think it is really expensive to make it HTTPS for the main site as well, I do understand what do you mean, but I think it must be passed to developers to make it for the whole domain, it is really good I think, also, most of sites that care about privacy specially with those information that descried here:
    https://legal.ubi.com/privacypolicy/en-INTL

    And I see the settlers do some tracking on us:


    also, if you look into most ubisoft sites including games, all are secured.

    It will confuse users, maybe better just to put that SSL on domain, really most of new users or who already using settlers will not feel so comfortable with those warnings around, actually I'm not as well, even I know really many technical and development details, but still, not really so comfortable .
    Hello People

Closed Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Ubisoft uses cookies to ensure that you get the best experience on our websites. By continuing to use this site you agree to accept these cookies. More info on our privacy.