Hacker News new | ask | show | jobs
by rikkus 4391 days ago
This is what I wrote in their 'Contact' form, which returned an error:

'The form you submitted contained the following errors Missing Data.(DIFFERENT_IP) Return to Previous Page'

I used your password checker here:

http://www.getsafeonline.org/themes/passwrdcheck/index.html

I notice that it has set the form field to hide my password as I type it, that there are two lock symbols next to the password box, and that the box is surrounded by a metallic looking image.

These factors would probably lead one to believe that you were treating my password with care, ensuring that it would only be relayed to yourselves and no-one else would be able to read it.

As an untrusting person, I typed something which is not one of my passwords into the box, just to see what would happen. When I submitted the form, my password was transmitted in clear text over the Internet, where it could be read by anyone who happened to be in a position to sniff traffic. This includes my office network!

For a site named 'Get safe online', this seems like the most incredible irony. I will be spreading the word that this site is utterly unsafe to visit, as it is unlikely that I have co-incidentally found the single problem.

I notice you advise people that a password 'like' 'SP1D3Rm@n' is secure. This is patently false as such a password is very simple to crack.

Again, this one issue I found, after choosing a single page to test, gives me a complete lack in confidence in the advice of the site. I will also be telling people not to heed advice found here.

Please get some real expert advice on security as the advice you are giving to others, and the problem[s] with your site are likely to cause real problems for people.

1 comments

I did a WHOIS, and seeing a domain registration date back to 2005 gave an air of credibility. So then I visited Internet Archive and browsed several pages https://web.archive.org/web/20080701000000*/http://getsafeon...

They seem like experts... experts in subtle verbal manipulation for those without technical understanding, at least that is how it reads for me.

Over years of archives, including the OP post, 'protect your family' continually appears as a headline. Monetisation is not explicitly outlined, it appears to be government or PPP funded.

Scare tactics, targeted at those probably less internet aware then the HN crowd, rather than education, appear to fund this website by whatever means.

"We have short time to beat powerful computer attack"

And see how pixelated their main banner image is?

Not only bad grammar, but poor images. Really am ammeter website.

Here's an "ammeter" website for you: ammeters.compare99.com
spell-check strikes again (dang keyboard!)