republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » US Cable Support » Cox HSI » [ALL] Wash Post criticizes Cox over email security
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[AZ] New Cable Box firmware? »
« [AZ] Need help! No explanation for downtime!  
AuthorAll Replies


SoonerAl
Old Enough To Know Better
Premium,MVM
join:2002-07-23
Norman, OK

 reply to coxengr
Re: [ALL] Wash Post criticizes Cox over email security

said by coxengr See Profile :

I can confirm this is in the works. Will be forthcoming shortly.....
Any updated information to share?
--
"When all else fails, read the instructions..."


coxengr
Premium,VIP
join:2002-03-09
Atlanta, GA
reply to short09
I can confirm this is in the works. Will be forthcoming shortly.....

short09

join:2006-07-21

reply to NoVA_CoxUser
said by NoVA_CoxUser See Profile :

And to make matters worse, your "base" e-mail password IS your Cox online account management password!
yup......that makes it twice as easy for a hacker to steal the password.....a hacker could have complete access to a subscribers account if they wanted to


pbvan

join:2003-02-09
Fairfax, VA
reply to NoVA_CoxUser
Thanxs for the link. Your condensed version was great and the link provided further explanation in terms I could understand.


NoVA_CoxUser
Stand back from the cage -- The RF bites
Premium
join:2004-07-06
Alexandria, VA
·Cox HSI


4 edits
reply to pbvan
said by pbvan See Profile :

... when logging into cox.net, the »https:// page is where I log into for my email accounts. The actual page showing my email boxes is ».
I think you might find the explanation provided in the following page helpful: »www.michaelhorowitz.com/securesubmit.html

To summarize:

1) Just because the page where you enter personal info is SSL-secured, doesn't mean that your personal info will be (or won't be) SSL-secured in-transmission when you click "login" ...

... It CAN however give you some assurance that the page which you are viewing is "genuine" if you verify the certificate's name and signing chain -- in other words, just because you have an SSL connection to a site doesn't necessarily mean that it's to the site to which you mean to be SSL-connected.

What IS important is whether the code underlying the "login" button is "http" or "https". (explained in the "Bad News" section in the earlier link)

2) Similarly, just because the "post-login" pages you receive from a site aren't SSL-secured, doesn't necessarily mean that your UID/Password was transmitted "in the clear"

Our own DSLR "SSL Log in" is one such example:

While your actual username/password are SSL-secured when transmitted ... specifically by this section of the page ...
FORM ACTION="https://secure.dslreports.com/r3/login"
... neither the initial DSLR "SSL Log in" page, or the subsequent DSLR pages displayed are themselves SSL-secured.

Unfortunately, Cox's webmail authentication is only insecure, so regardless of what page you're reaching it from, your username/password is always transmitted "in the clear."


pbvan

join:2003-02-09
Fairfax, VA

reply to NoVA_CoxUser
NoVa_cox user ..... when logging into cox.net, the »https:// page is where I log into for my email accounts. The actual page showing my email boxes is ». When I want to view my account both login and the page displaying my account info is »https://.

Does this mean that my login info IS secure regardless of my inbox NOT being secure? I don't use my Cox mailbox for anything other than its an active email for those sites that require one that I don't care about.

I have email accounts with earthlink using server port 587. Now are these emails also NOT secure?

I too read the Post article and was somewhat surprised that Cox doesn't use SSL when viewing emails. I know just enough to look for that lock or »https:// when transmitting personal info.

Also I am now using a MacBook Pro using Safari (its ok, better than IE6) and the Mac Mail program now.


NoVA_CoxUser
Stand back from the cage -- The RF bites
Premium
join:2004-07-06
Alexandria, VA

1 edit
reply to Radardan
And to make matters worse, your "base" e-mail password IS your Cox online account management password!
Forums » US Cable Support » Cox HSI[AZ] New Cable Box firmware? »
« [AZ] Need help! No explanation for downtime!  


Thursday, 10-Dec 21:44:39 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [136] AT&T Launching New 24 Mbps U-Verse Tier
· [87] AT&T Hints At Usage-Based iPhone Data Pricing
· [82] 3G Network Test Says AT&T Is Tops
· [74] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [55] Average American Consumes 34 Gigabytes Daily
· [51] The Future Of Wi-Fi Is Bright
· [50] Sprint, T-Mobile Merger Rumor Lives
Most people now reading
· New Mediacom Email [Mediacom]
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· ICC strats [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· ICC Strats??? [World of Warcraft]
· Equal speeds ruling [Canadian Broadband]
· Lawyers Claim Palin Hack Suspect's PC Had Spyware [Security]