Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-20-2007, 11:09 AM   #1
faxxaff
Confirmed User
 
Industry Role:
Join Date: Dec 2002
Location: Marina Hemingway
Posts: 2,134
Encryption of affiliate access is missing in most Programs

I see that most affiliate programs, specially the ones based on NATS have no encryption of the data ... That means ISPs and people who can listed to your internet connection can see your data and how much you make .... Wouldn't it be a good idea for program owners to make their interfaces a bit safer?

The big third party billers CCBill and Verotel have safe connections, but about 90% of programs do not.
__________________
Asian Babes
faxxaff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 11:44 AM   #2
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
well for one is it really that big of a deal? and two, ssl connections are a lot more work for the server and everything in between.

dont be so paranoid, im sure your ISP has better things to do then spy on you checking your stats so they can see how much money you make.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 11:48 AM   #3
ztik
Confirmed User
 
ztik's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Nomad
Posts: 5,196
Ive never once in all my years online heard of ISP's sniffing packets of random crap. They usually only do it when there is a reason to do it. Its not like there's people sitting there sniffing the billion gazillion packets reading them
__________________
.
ztik is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 01:05 PM   #4
faxxaff
Confirmed User
 
Industry Role:
Join Date: Dec 2002
Location: Marina Hemingway
Posts: 2,134
It's a big threat to privacy. Why do you guys think banks, CCbill, online brokers, etc. encrypt their data?

There are countries where ISPs are ordered to spy on citizens and I am not just talking about China. Revenue services can sniff your data. If you are on a wireless connection your neighbours or friends can pick up your data stream, etc. ... just a few examples.
__________________
Asian Babes
faxxaff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 07:05 PM   #5
TMM_John
Confirmed User
 
TMM_John's Avatar
 
Industry Role:
Join Date: May 2004
Posts: 6,659
You can use an SSL certificate with NATS if you'd like. Some programs do.

Please try to do some research before making blanket statements about things.
TMM_John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 07:13 PM   #6
cashbot
So Fucking Banned
 
Join Date: Apr 2007
Posts: 325
It would be great if programs offered an optional SSL login page, especially for when you're surfing from an unsecured (wireless) connection without a VPN or ssh tunnel. Then you could have the option, faster unsecured logins for home, or SSL for when you're out and about.

Last edited by cashbot; 08-20-2007 at 07:15 PM..
cashbot is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 07:17 PM   #7
_Rush_
Confirmed User
 
_Rush_'s Avatar
 
Join Date: Dec 2006
Location: Buenos Aires
Posts: 742
Hey faxxaff!
__________________
No sig.
_Rush_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 07:21 PM   #8
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
I agree, and it's not like it's expensive or difficult to setup... :-/
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 08:15 PM   #9
teg0
Confirmed User
 
teg0's Avatar
 
Join Date: Jan 2006
Location: Gringo in Puerto Rico
Posts: 4,197
Yeah I was always wondering that too. I think its like $17 with godaddy to get an SSL certificate.
__________________
OV Tube - Tube Script Software
teg0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2007, 08:19 PM   #10
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
an easy solution would be to tell all these new programs coming up every week "no, i am not signing up, you don't protect with SSL, but let me know when you do"

this is exactly how I started the rss revolution last year....any time a program posted about their program updates I would say "where is the rss? I can't rfind it anywhere"....and before long rss became standard
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2007, 12:53 AM   #11
faxxaff
Confirmed User
 
Industry Role:
Join Date: Dec 2002
Location: Marina Hemingway
Posts: 2,134
Quote:
Originally Posted by PBucksJohn View Post
You can use an SSL certificate with NATS if you'd like. Some programs do.
Please try to do some research before making blanket statements about things.
I am not attacking you, I just say that program owners should care more about the safety of affiliate data. If NATS can do their part to encourage them to do so, I think they should. It is not a blank statement, but a fact that most NATS programs do not use encrypted connections. I am a member of a few programs and I know what I am talking about. It is a step back from CCBills top noth security!

Take it as a kind proposal to improve your product if you care.

Would you do online banking without a secure https connection?
__________________
Asian Babes
faxxaff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2007, 01:13 AM   #12
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
Quote:
Originally Posted by Why View Post
well for one is it really that big of a deal? and two, ssl connections are a lot more work for the server and everything in between.

dont be so paranoid, im sure your ISP has better things to do then spy on you checking your stats so they can see how much money you make.
It is coz it means others could access webmaster profiles and change
payout info. It's not a huge risk....but it's still a risk...which easily can be
avoided.
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2007, 01:35 AM   #13
DaddyHalbucks
A freakin' legend!
 
DaddyHalbucks's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Las Vegas, Nevada USA
Posts: 18,975
SSL certs are so expensive that webmasters can't afford them.

It's all because there's no money in porn.

;)
__________________
Boner Money
DaddyHalbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2007, 08:42 AM   #14
TMM_John
Confirmed User
 
TMM_John's Avatar
 
Industry Role:
Join Date: May 2004
Posts: 6,659
Quote:
Originally Posted by faxxaff View Post
I am not attacking you, I just say that program owners should care more about the safety of affiliate data. If NATS can do their part to encourage them to do so, I think they should. It is not a blank statement, but a fact that most NATS programs do not use encrypted connections. I am a member of a few programs and I know what I am talking about. It is a step back from CCBills top noth security!

Take it as a kind proposal to improve your product if you care.

Would you do online banking without a secure https connection?
I never said you were attacking me Sorry if my reply sounded pissy, it wasn't meant in that way.

I just want everyone to understand that NATS installs run independently and it is up to the program owner whether or not they use an SSL cert on their affiliate join form. Their running of NATS (or other 3rd party systems) has nothing to do with them using or not using a cert.

System like CCBill are not run independently but rather run on CCBill's servers and are hosted and controlled by CCBill. So either no one or everyone on it has a cert for it as it is all centralized.

I hope this clarifies it a bit and please don't confuse any reply of disagreement with taking it as an attack. Sorry if you thought I took it that way.
TMM_John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2007, 11:03 AM   #15
drjones
Confirmed User
 
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
Quote:
Originally Posted by ztik View Post
Ive never once in all my years online heard of ISP's sniffing packets of random crap. They usually only do it when there is a reason to do it. Its not like there's people sitting there sniffing the billion gazillion packets reading them
Its not really about ISP's sitting in their data center spying on you... though it could be a concern. Its about all the identity thieves and crackers out there who scour the internet for this type of info, constantly. There are numerous ways they can get in between the affiliate, and the affiliate backends.

Seeing as how many may have personal info, or sensitive company info stored on the backends of all these programs, it really is a little irresponsible not to make SSL available. Its brain dead easy to turn on... even if you use a self signed cert, its better than nothing.

Of course, SSL doesnt come close to solving every security problem out there, but it goes a *long* way for the amount of work involved setting it up. Its really as simple as setting up a typical webserver, with the added step of generating a cert.
__________________
ICQ: 284903372
drjones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.