Hacker Newsnew | past | comments | ask | show | jobs | submit | ssl_love's commentslogin

Hey OkCupid – How about some SSL Love?

"For the hundreds of thousands of users searching for that special someone through one of the largest free online dating sites, the love fest may be coming to an end. OkCupid is putting users’ privacy in danger by failing to support secure access to its entire website through HTTPS. Every OkCupid email, chat session, search, clicked link, page viewed, and username is transmitted over the Internet in unencrypted plaintext, where it can be intercepted and read by anyone on the network."

https://www.eff.org/deeplinks/2012/02/hey-okcupid-how-about-...

The Heartbreaking Truth About Online Dating Privacy: https://www.eff.org/press/releases/heartbreaking-truth-about...


Is this really still the case?


Oh, yeah :/ The login page is over SSL, but everything after that is not (!!) This protects your password but not your OkCupid session cookies. It's an improvement over no SSL at all (which was the case for a long time) but still leaves a lot to be desired.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: