Encryption of affiliate access is missing in most Programs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • faxxaff
    Confirmed User
    • Dec 2002
    • 2134

    #1

    Encryption of affiliate access is missing in most Programs

    I see that most affiliate programs, specially the ones based on NATS have no encryption of the data ... That means ISPs and people who can listed to your internet connection can see your data and how much you make .... Wouldn't it be a good idea for program owners to make their interfaces a bit safer?

    The big third party billers CCBill and Verotel have safe connections, but about 90% of programs do not.
    Asian Babes
  • Why
    MFBA
    • Mar 2003
    • 7230

    #2
    well for one is it really that big of a deal? and two, ssl connections are a lot more work for the server and everything in between.

    dont be so paranoid, im sure your ISP has better things to do then spy on you checking your stats so they can see how much money you make.

    Comment

    • ztik
      Confirmed User
      • Aug 2001
      • 5196

      #3
      Ive never once in all my years online heard of ISP's sniffing packets of random crap. They usually only do it when there is a reason to do it. Its not like there's people sitting there sniffing the billion gazillion packets reading them
      .

      Comment

      • faxxaff
        Confirmed User
        • Dec 2002
        • 2134

        #4
        It's a big threat to privacy. Why do you guys think banks, CCbill, online brokers, etc. encrypt their data?

        There are countries where ISPs are ordered to spy on citizens and I am not just talking about China. Revenue services can sniff your data. If you are on a wireless connection your neighbours or friends can pick up your data stream, etc. ... just a few examples.
        Asian Babes

        Comment

        • TMM_John
          Confirmed User
          • May 2004
          • 6665

          #5
          You can use an SSL certificate with NATS if you'd like. Some programs do.

          Please try to do some research before making blanket statements about things.


          Too Much Media - Makers of the Industry's Leading Payite Management Platform, NATS!

          Comment

          • cashbot
            So Fucking Banned
            • Apr 2007
            • 325

            #6
            It would be great if programs offered an optional SSL login page, especially for when you're surfing from an unsecured (wireless) connection without a VPN or ssh tunnel. Then you could have the option, faster unsecured logins for home, or SSL for when you're out and about.
            Last edited by cashbot; 08-20-2007, 06:15 PM.

            Comment

            • _Rush_
              Confirmed User
              • Dec 2006
              • 742

              #7
              Hey faxxaff!
              No sig.

              Comment

              • woj
                <&(©¿©)&>
                • Jul 2002
                • 47880

                #8
                I agree, and it's not like it's expensive or difficult to setup... :-/
                Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
                Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
                Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

                Comment

                • teg0
                  Confirmed User
                  • Jan 2006
                  • 4204

                  #9
                  Yeah I was always wondering that too. I think its like $17 with godaddy to get an SSL certificate.

                  Comment

                  • Jace
                    FBOP Class Of 2013
                    • Jan 2004
                    • 35562

                    #10
                    an easy solution would be to tell all these new programs coming up every week "no, i am not signing up, you don't protect with SSL, but let me know when you do"

                    this is exactly how I started the rss revolution last year....any time a program posted about their program updates I would say "where is the rss? I can't rfind it anywhere"....and before long rss became standard

                    Comment

                    • faxxaff
                      Confirmed User
                      • Dec 2002
                      • 2134

                      #11
                      Originally posted by PBucksJohn
                      You can use an SSL certificate with NATS if you'd like. Some programs do.
                      Please try to do some research before making blanket statements about things.
                      I am not attacking you, I just say that program owners should care more about the safety of affiliate data. If NATS can do their part to encourage them to do so, I think they should. It is not a blank statement, but a fact that most NATS programs do not use encrypted connections. I am a member of a few programs and I know what I am talking about. It is a step back from CCBills top noth security!

                      Take it as a kind proposal to improve your product if you care.

                      Would you do online banking without a secure https connection?
                      Asian Babes

                      Comment

                      • ServerGenius
                        Confirmed User
                        • Feb 2002
                        • 9377

                        #12
                        Originally posted by Why
                        well for one is it really that big of a deal? and two, ssl connections are a lot more work for the server and everything in between.

                        dont be so paranoid, im sure your ISP has better things to do then spy on you checking your stats so they can see how much money you make.
                        It is coz it means others could access webmaster profiles and change
                        payout info. It's not a huge risk....but it's still a risk...which easily can be
                        avoided.
                        | http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |

                        Comment

                        • DaddyHalbucks
                          A freakin' legend!
                          • Feb 2004
                          • 18975

                          #13
                          SSL certs are so expensive that webmasters can't afford them.

                          It's all because there's no money in porn.

                          ;)
                          Boner Money

                          Comment

                          • TMM_John
                            Confirmed User
                            • May 2004
                            • 6665

                            #14
                            Originally posted by faxxaff
                            I am not attacking you, I just say that program owners should care more about the safety of affiliate data. If NATS can do their part to encourage them to do so, I think they should. It is not a blank statement, but a fact that most NATS programs do not use encrypted connections. I am a member of a few programs and I know what I am talking about. It is a step back from CCBills top noth security!

                            Take it as a kind proposal to improve your product if you care.

                            Would you do online banking without a secure https connection?
                            I never said you were attacking me Sorry if my reply sounded pissy, it wasn't meant in that way.

                            I just want everyone to understand that NATS installs run independently and it is up to the program owner whether or not they use an SSL cert on their affiliate join form. Their running of NATS (or other 3rd party systems) has nothing to do with them using or not using a cert.

                            System like CCBill are not run independently but rather run on CCBill's servers and are hosted and controlled by CCBill. So either no one or everyone on it has a cert for it as it is all centralized.

                            I hope this clarifies it a bit and please don't confuse any reply of disagreement with taking it as an attack. Sorry if you thought I took it that way.


                            Too Much Media - Makers of the Industry's Leading Payite Management Platform, NATS!

                            Comment

                            • drjones
                              Confirmed User
                              • Oct 2005
                              • 908

                              #15
                              Originally posted by ztik
                              Ive never once in all my years online heard of ISP's sniffing packets of random crap. They usually only do it when there is a reason to do it. Its not like there's people sitting there sniffing the billion gazillion packets reading them
                              Its not really about ISP's sitting in their data center spying on you... though it could be a concern. Its about all the identity thieves and crackers out there who scour the internet for this type of info, constantly. There are numerous ways they can get in between the affiliate, and the affiliate backends.

                              Seeing as how many may have personal info, or sensitive company info stored on the backends of all these programs, it really is a little irresponsible not to make SSL available. Its brain dead easy to turn on... even if you use a self signed cert, its better than nothing.

                              Of course, SSL doesnt come close to solving every security problem out there, but it goes a *long* way for the amount of work involved setting it up. Its really as simple as setting up a typical webserver, with the added step of generating a cert.
                              ICQ: 284903372

                              Comment

                              Working...