Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
Story Views
Now:
Last hour:
Last 24 hours:
Total:

SSL Now More Secure on Unseen.is + Friendly Hackers

% of readers think this story is Fact. Add your two cents.


We just completed the security upgrade our team has been working on for the past several weeks.  Everything is behind the scenes, so there’s not much to notice until you look under the hood, but these changes will definitely improve the security of the site.  It took us a couple of tries to get it right, but it’s now in production.  Thanks everyone for your patience and now you should clear your cache, reload the home page and then go change your password.  It’s now a lot more secure.

First, we upgraded the protection for CSRF (Cross Site Request Forgery).  Here’s what wiki says about that:

Cross-site request forgery, also known as a one-click attack or session riding and abbreviated as CSRF (sometimes pronounced sea-surf[1]) or XSRF, is a type of malicious exploit of a website whereby unauthorized commands are transmitted from a user that the website trusts.[2] Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user’s browser.

In layman’s terms that’s where someone tries to login and the site returns a session ID.  Someone else grabs that session ID and then masquerades as that person, successfully logging in to the site as them.  We’ve now repaired and patched that issue.  We haven’t heard of any user who was negatively affected by this issue.

The other major change is the way we use SSL for login on the site.  We’ve now added one other major security feature to our SSL login.  We kept the cute padlock and SSL channel, but now we have secured your password with NTRU security for this vitally important function.  Here’s what your password now looks like with this NTRU encryption:

I won’t tell you my password, but you can rest assured it’s a lot shorter than the one a hacker will now see in the SSL data stream.  There’s no way I could remember more than about 16 characters.  This should provide pretty good security for your password.

We’ve added this level of authentication across all Unseen applications;  Win, Mac, Ubuntu and Android.  We’ll be adding download links from the front page and distributing the desktop clients tonight.  Android is still being tested and will be available hopefully March 15.  That depends on the progress for SIP signaling on the web site…once that’s finished, the Android app will ship.  Vinh and I have been using the Android app and we think everyone will be very happy — it’s got all the secure text chatting and audio and video calling, which is really cool, especially if you’ve got a big battery.  

Finally, we want to invite friendly hackers to test the security at our site.  Please be gentle, we’re still bolting down a few things, but we do appreciate your feedback.  These two security fixes just mentioned were a result of a very good discussion with one of our users, who is a security expert.  Responsible people like this are helping us make Unseen a safe place to communicate.

Thanks go to “The Opera Star” for his help and one other friend of ours.  We will make every effort to immediately fix any security problems pointed out by the members of our community and we’re grateful for the time you’ve spent testing things.  If you find a security problem we need to address that we don’t know about, we’ll reward you with premium accounts and even some bitcoin if .  In the future, once things get a bit more stable, we’ll be making parts of our source code available for review, too, and make parts of it available for developers.  If you have any things you think need to be addressed from a security point of view, please send an email to support at unseen dot is.


Source: http://blog.unseen.is/2014/03/03/ssl-now-more-secure-on-unseen-is-friendly-hackers/


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Lion’s Mane Mushroom

Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, But it benefits growth of Essential Gut Flora, further enhancing your Vitality.



Our Formula includes:

Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity.

Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins.

Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system.

Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome.

Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function.

Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules. Today Be 100% Satisfied Or Receive A Full Money Back Guarantee Order Yours Today By Following This Link.

Report abuse

    Comments

    Your Comments
    Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

    MOST RECENT
    Load more ...

    SignUp

    Login

    Newsletter

    Email this story
    Email this story

    If you really want to ban this commenter, please write down the reason:

    If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.