Salem website security issue. Dev's read ~Important~

Forum for bugs and technical problems.

Salem website security issue. Dev's read ~Important~

Postby xartin » Sun Oct 16, 2016 11:44 pm

Hi i'm xartin nice to meet you all.

I've tried your great game on only a few occasions and enjoy what i've seen of it from watching a friends twitch stream. I'm also one of Daopa's twitch channel mods and in my professional career served as an IT network infrastructure developer for Gentoo Linux some number of years ago.

I was uncertain of your staff were aware and just wanted to contribute something by posting a vulnerability "bug" regarding your website server configuration to help ensure the salem community isnt being data mined or compromised from the current insecure web server configuration.

The bug i'm referring to is your website SSL certificate is both expired, invalid and using a depreciated SHA-1 encryption cypher.

Image

Secure modern website encryption should be at the very least using SHA-256 RSA-2048 bit TLS.v3

Microsoft and every other respected or recognized software vendor is depreciating SHA-1 and ssl v3.

http://arstechnica.com/security/2016/05 ... -4-months/

I just wanted to relay this issue to someone willing interested and able to rectify this with the goal of aiding the online privacy and security of the salem community.

Thanks in advance and greetings from Daopa's twitch moderators :)

https://www.twitch.tv/daopa
xartin
 
Posts: 1
Joined: Sat Jun 20, 2015 12:02 am

Re: Salem website security issue. Dev's read ~Important~

Postby TotalyMeow » Mon Oct 17, 2016 12:34 am

Community Manager for Mortal Moments Inc.

Icon wrote:This isn't Farmville with fighting, its Mortal Kombat with corn.
User avatar
TotalyMeow
 
Posts: 3782
Joined: Thu Jun 05, 2014 8:14 pm


Return to Bugs & Technicalities

Who is online

Users browsing this forum: No registered users and 38 guests