Beta
×

Welcome to the Slashdot Beta site -- learn more here. Use the link in the footer or click here to return to the Classic version of Slashdot.

Thank you!

Before you choose to head back to the Classic look of the site, we'd appreciate it if you share your thoughts on the Beta; your feedback is what drives our ongoing development.

Beta is different and we value you taking the time to try it out. Please take a look at the changes we've made in Beta and  learn more about it. Thanks for reading, and for making the site better!

Orkut quietly removes https login

hlh_nospam (178327) writes | more than 7 years ago

Privacy 0

When I tried to access my Orkut account on Monday morning, I got an "Unable to Connect" message. I just assumed that they were having some temporary problems. When I couldn't login on Tuesday, I thought maybe the company had tightened down the firewall, so I tried later that evening from home with the same result. So I did a Google search to see if anything had been reported, and found a Wikipedia entry. Other than that, it seems very few people noticed this security problem.When I tried to access my Orkut account on Monday morning, I got an "Unable to Connect" message. I just assumed that they were having some temporary problems. When I couldn't login on Tuesday, I thought maybe the company had tightened down the firewall, so I tried later that evening from home with the same result. So I did a Google search to see if anything had been reported, and found a Wikipedia entry. Other than that, it seems very few people noticed this security problem.

From Wikipedia: "On and around April 17, 2007 secure (https) access to the orkut login server was no longer available. This may lead to compromise of orkut accounts and by extension google accounts as well as gmail accounts since the password for login is transmitted via cleartext."

Sure enough, the http login comes up (I had been using a shortcut to the secure login site). Note that the password used by Orkut is tied to your gmail account, so sending your login password via plaintext may compromise your other Google accounts. If you use Orkut, and you have signed in since April 17th, you should immediately change your gmail password, and avoid Orkut until they fix the secure login.

cancel ×

0 comments

Sorry! There are no comments related to the filter you selected.

Check for New Comments
Slashdot Login

Need an Account?

Forgot your password?

Submission Text Formatting Tips

We support a small subset of HTML, namely these tags:

  • b
  • i
  • p
  • br
  • a
  • ol
  • ul
  • li
  • dl
  • dt
  • dd
  • em
  • strong
  • tt
  • blockquote
  • div
  • quote
  • ecode

"ecode" can be used for code snippets, for example:

<ecode>    while(1) { do_something(); } </ecode>