[liberationtech] No HTTPS on IGF registration AGAIN

Alex Comninos alex.comninos at gmail.com
Wed Jun 18 08:57:05 PDT 2014


Hi All,

for what I can count as the third time at least, there is no HTTPS on
the registration form for the Internet Governance Forum website. Last
time at least an HTTPS form was embedded in the HTTP site (bad
practice I believe). However the registration confirmation with all
personal data were send in the clear
(http://apc.org/en/blog/igf-cybersecurity-fail-website-leaks-personal-data).

There was also the issue of the database containing user names and
passwords, which was leaked last year, and nobody was informed in the
breach.

I would appreciate your thoughts on the matter, as well as a way forward.

Kind regards,
Alex



More information about the liberationtech mailing list