You are viewing a single comment's thread from:

RE: A brief rant on password security [Edit: Not so brief after all]

in #security9 years ago

Ahh, yes. That's a misconfiguration on their part; looks like the raw domain, without the www, is configured to point to their mailserver, so emails@dashlane.com will work correctly (poorly done, should've had the A record point to the website and the MX record point to the mailserver), so if you manually type https://dashlane.com, it breaks.

That is badly insecure, because it means they don't have HSTS on dashlane.com, only on www.dashlane.com, meaning I could sslstrip them as you described, and the address bar would read dashlane.com instead of www.dashlane.com.

Coin Marketplace

STEEM 0.07
TRX 0.29
JST 0.047
BTC 66826.63
ETH 1989.70
USDT 1.00
SBD 0.51