# Is login to SDMB secure?

**URL:** <https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317>\
**Category:** About This Message Board\
**Created:** [November 14, 2007, 1:47am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317 "2007-11-14T01:47:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![qubed](https://avatars.discourse-cdn.com/v4/letter/q/f07891/32.png) [@qubed](https://boards.straightdope.com/u/qubed)\
**Post date:** [November 14, 2007, 1:47am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/1 "2007-11-14T01:47:57Z")

</div>

I just noticed today that when logging in, the URL is http://… not https://…

So, are our passwords being sent in plain text?

---

<div class="post-metadata">

**Author:** ![Bagistan](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@Bagistan](https://boards.straightdope.com/u/Bagistan)\
**Post date:** [November 14, 2007, 2:24am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/2 "2007-11-14T02:24:00Z")

</div>

No, the passwords are not sent in plaintext, only the [hash sum](http://en.wikipedia.org/wiki/Cryptographic_hash_function) of the password is sent. This is made possible by a javascript hash function that executes in the browser at the users side of the connection. Everything else is sent unencrypted (as plaintext).

This is not as secure as an encrypted connection (indicated by https://…), but better than none at all.

---

<div class="post-metadata">

**Author:** ![qubed](https://avatars.discourse-cdn.com/v4/letter/q/f07891/32.png) [@qubed](https://boards.straightdope.com/u/qubed)\
**Post date:** [November 14, 2007, 2:27am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/3 "2007-11-14T02:27:51Z")

</div>

Do you know if the hash is salted?

---

<div class="post-metadata">

**Author:** ![Bagistan](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@Bagistan](https://boards.straightdope.com/u/Bagistan)\
**Post date:** [November 14, 2007, 3:03am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/4 "2007-11-14T03:03:26Z")

</div>

[QUOTE=alanak]  
Do you know if the hash is salted?  
[/QUOTE]

No, I don’t know. I can’t see anything that looks like it’s being salted, but I’m not that good at Javascript (or determined) that I can rule it out.

The Javascript function in question is at [http://boards.straightdope.com/sdmb/clientscript/vbulletin\_md5.js](http://boards.straightdope.com/sdmb/clientscript/vbulletin_md5.js) and its usage is visible from the html source of the login pages for the curious. There’s probably a manual of some sort for vBulletin that could tell us.

For everyone concerned: Never use the same password for more than one website. Failing that - at least tack something new to the end of your standard one each time.

---

<div class="post-metadata">

**Author:** ![qubed](https://avatars.discourse-cdn.com/v4/letter/q/f07891/32.png) [@qubed](https://boards.straightdope.com/u/qubed)\
**Post date:** [November 14, 2007, 3:32am UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/5 "2007-11-14T03:32:42Z")

</div>

[QUOTE=Bagistan]

For everyone concerned: Never use the same password for more than one website. Failing that - at least tack something new to the end of your standard one each time.  
[/QUOTE]

I know i should do this, but just in practice i never do. Which is why i am concerned about this board’s security.

---

<div class="post-metadata">

**Author:** ![Turek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/turek/32/18782_2.png) [@Turek](https://boards.straightdope.com/u/Turek)\
**Post date:** [November 14, 2007, 1:43pm UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/6 "2007-11-14T13:43:53Z")

</div>

[QUOTE=alanak]  
I know i should do this, but just in practice i never do. Which is why i am concerned about this board’s security.  
[/QUOTE]

Then it’s probably not “best practices” that you broadcast that fact on a public forum.

---

<div class="post-metadata">

**Author:** ![qubed](https://avatars.discourse-cdn.com/v4/letter/q/f07891/32.png) [@qubed](https://boards.straightdope.com/u/qubed)\
**Post date:** [November 14, 2007, 6:06pm UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/7 "2007-11-14T18:06:11Z")

</div>

[QUOTE=Turek]  
Then it’s probably not “best practices” that you broadcast that fact on a public forum.  
[/QUOTE]

Well, when i noticed that this board’s wasn’t encrypted, i changed my password on this site to something unique. So, i think i’m ok.

---

<div class="post-metadata">

**Author:** ![Toast\_Museum](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@Toast\_Museum](https://boards.straightdope.com/u/Toast_Museum)\
**Post date:** [November 14, 2007, 6:45pm UTC](https://boards.straightdope.com/t/is-login-to-sdmb-secure/426317/8 "2007-11-14T18:45:58Z")

</div>

[QUOTE=Bagistan]  
Never use the same password for more than one website. Failing that - at least tack something new to the end of your standard one each time.  
[/QUOTE]

That’s what I do. Each site gets my main password plus the first two letters of their domain name.  
And when an email is involved, I use my websites’ open naming where I can add any number of aliases. Each site gets their own domain name as the user name followed by @mydomain.org Thus, should spam start to arrive from a site, I know for sure it was them that passed out my email, and on top I can block it easily with a filter.
