Data leak in 6.50B11

This is the place to help test and discuss Version 6 Beta releases.

Data leak in 6.50B11

Postby aglenday » Sat Jul 13, 2013 8:25 pm

When searching the search request goes out via HTTPS (good), the results come back via HTTPS (still good). If no results are found the 'NO RESULTS SEARCHING ON SUBJECT "Acme Publishing" ' message is sent back via HTTP resulting is data leakage.

Having said that I think it's wonderful software. The biggest problem I find with Usenet is trying to find what I'm after and NewsBin is doing a wonderful job of indexing most groups.
aglenday
n00b
n00b
 
Posts: 3
Joined: Fri Jul 12, 2013 7:19 am

Registered Newsbin User since: 01/13/13

Re: Data leak in 6.50B11

Postby Quade » Sat Jul 13, 2013 9:42 pm

I'll mention this to Dex. See if he can make the URLS https.
User avatar
Quade
Eternal n00b
Eternal n00b
 
Posts: 44984
Joined: Sat May 19, 2001 12:41 am
Location: Virginia, US

Registered Newsbin User since: 10/24/97

Re: Data leak in 6.50B11

Postby dexter » Sat Jul 13, 2013 11:01 pm

I didn't see any point to having error messages come back as https. It's been like this for years. Your searches and search results are https.

I can look into it if you think it's important for any errors to be sent back as https.
User avatar
dexter
Site Admin
Site Admin
 
Posts: 9514
Joined: Fri May 18, 2001 3:50 pm
Location: Northern Virginia, US

Registered Newsbin User since: 10/24/97

Re: Data leak in 6.50B11

Postby aglenday » Sun Jul 14, 2013 1:32 am

I just figured it had been overlooked. If the request and results are sent and received as https for privacy it makes sense for anything that could leak data to be also received as https.

It's only a small thing.
aglenday
n00b
n00b
 
Posts: 3
Joined: Fri Jul 12, 2013 7:19 am

Registered Newsbin User since: 01/13/13

Re: Data leak in 6.50B11

Postby dexter » Wed Jul 17, 2013 8:05 pm

Any search errors you receive are being returned over https now.
User avatar
dexter
Site Admin
Site Admin
 
Posts: 9514
Joined: Fri May 18, 2001 3:50 pm
Location: Northern Virginia, US

Registered Newsbin User since: 10/24/97

Re: Data leak in 6.50B11

Postby aglenday » Sat Jul 27, 2013 12:27 am

Thank you for doing that Dexter.
aglenday
n00b
n00b
 
Posts: 3
Joined: Fri Jul 12, 2013 7:19 am

Registered Newsbin User since: 01/13/13


Return to Newsbin Version 6 Beta Support

Who is online

Users browsing this forum: No registered users and 2 guests