Important: These forums are for discussions between SkyDemon users. They are not routinely monitored by SkyDemon staff so any urgent issues should be sent directly to our Customer Support.

Login Security


Author
Message
Don Bannister
D
Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)
Group: Forum Members
Posts: 2, Visits: 3
When logging in recently to the SkyDemon Program on my Windows (10) PC, the Anti-Virus software came up with a somewhat surprising message. It said "An attempt to send your password unencrypted was about to occur on data.skydemon.aero". I wouldn't have been aware of this otherwise and, whilst not a total disaster, I would wonder if it might be better to be a bit more secure. I assume it means that the connection was not secured with SSL, but don't know for sure. Any thoughts ?


Tim Dawson
Tim Dawson
SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)
Group: Forum Members
Posts: 7.8K, Visits: 8.5K
Unless you're using a very old version of SkyDemon, all communications with our server are secure. Even the older versions hashed your password before sending, so the message you saw is simply incorrect.
Don Bannister
D
Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)Forum Newbie (9 reputation)
Group: Forum Members
Posts: 2, Visits: 3
Tim Dawson - 7/31/2023 9:13:06 AM
Unless you're using a very old version of SkyDemon, all communications with our server are secure. Even the older versions hashed your password before sending, so the message you saw is simply incorrect.

Thanks Tim.
You were right - I was using a pretty old version. I mostly use SkyDemon on a tablet, where I am used to it telling me when there are updates. This didn't seem to happen with the Windows Desktop version I had.
But the warning message was correct. Although the password was hashed, it and the username were sent in the clear in an http POST, so the anti-virus was pretty much right.
A useful exercise, nevertheless, as I am now up to date with a more secure version, and know that I need to manually check for updates !
Cheers, Don


Edited 8/1/2023 4:32:14 PM by Don Bannister
Tim Dawson
Tim Dawson
SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)SkyDemon Team (625K reputation)
Group: Forum Members
Posts: 7.8K, Visits: 8.5K
It's worth noting that all recent versions of the desktop software also check for updates and prompt for upgrade when they are discovered.
GO

Merge Selected

Merge into selected topic...



Merge into merge target...



Merge into a specific topic ID...




Reading This Topic

Login

Explore
Messages
Mentions
Search