Security issue: Please SSL encrypt the Axoloti Order Form!


#1

Hi @Johannes & Axoloti Community

Just a warning/advisory: The Axoloti online order form is NOT encrypted / not SSL secured. While it is true that if you use Paypal your credit card information will (hopefully) be protected, credit card numbers are not the only hazard! Any orders of Axoloti are sending your name, address, house number, phone number and Email unencypted and in the open. This is a real problem in regards to the potential for identity theft and is absolutely not up to modern web privacy standards. I would recommend any potential Axoloti buyers refrain from making purchases until this issue is fixed, as will I.


SSL Certificate expired
#2

A second note -- it shouldn't cost you anything to SSL encrypt the order form! @Johannes, the "Let's Encrypt" project can hook you up with an SSL certificate to do this: https://letsencrypt.org/

Likewise the logins to the Axoloti community forum aren't SSL encypted. This means any sufficiently motivated intermediary can receive your username/password and use that to log in as you. This kind of thing can and does happen online. I realize there are those who would argue, what possible damage could someone do in a special topic forum such as the Axoloti community is. However the possibility that someone could take your account info opens you up to the possibility that that person could then attempt to use those same login credentials on other websites. If users use the same username/password on other websites, this is potentially a significant problem! On this point I strongly urge you to SSL encrypt the community forum login.


#3

8 months and no change in status of this issue: Still no SSL / https security available for forum login and for address / order form for Axoloti core. I will try to raise this issue regularly until it gets fixed. It IS an issue.


#4

… and getting valid Let's Encrypt certificates for free and with automatic reissue is no-brainer nowadays …


#5

Indeed, please do this, if you have a decent hosting company it is trivial. Should we ask @thetechnobear maybe?


#6

I’ve done this on another sever.
But unfortunately I don’t have access to the host for axoloti forum just moderation/admin rights in discourse