I have a question for those of you more hack savvy than I.
Our office uses a piece of vendor software [...] on the web.
I have always been uncomfortable that none of it is in https.
But, just recently, I looked at the page source to try to find a problem, and found something completely unexpected--my user name and password!
It's in some javascript at the top of the page--
std_vars = { user : "xxxxxxx",
password : "xxxxx",
somevar : "xxxxx"};
Egad! Should I be as freaked about this as I am?
Unfortunately, I'm the resident tech nerd, so it's up to me to figure it out.
Help!
Thoughts? I need a REAL tech nerd
Edited to add: all the data is stored on a remote server several states away owned by the vendor; it isn't retrieved from our office server.
[editted at bug's request - Terry]
Our office uses a piece of vendor software [...] on the web.
I have always been uncomfortable that none of it is in https.
But, just recently, I looked at the page source to try to find a problem, and found something completely unexpected--my user name and password!
It's in some javascript at the top of the page--
std_vars = { user : "xxxxxxx",
password : "xxxxx",
somevar : "xxxxx"};
Egad! Should I be as freaked about this as I am?
Unfortunately, I'm the resident tech nerd, so it's up to me to figure it out.
Help!
Thoughts? I need a REAL tech nerd
Edited to add: all the data is stored on a remote server several states away owned by the vendor; it isn't retrieved from our office server.
[editted at bug's request - Terry]
Last edited by a moderator: