It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
This might be a noobish question, but I'm curious about how my password is sent securely to GOG when I log in.

I noticed some sites establish a secure connection when you want to log in. Others, like GOG, don't seem to do that, at least on the surface of it.

If you are not logged in and you click on 'Account login', on the front page, you can notice that your connection to GOG is a normal, unencrypted connection. How does GOG protect my password?
Post edited December 16, 2011 by paulcmnt
avatar
paulcmnt: This might be a noobish question, but I'm curious about how my password is sent securely to GOG when I log in.

I noticed some sites establish a secure connection when you want to log in. Others, like GOG, don't seem to do that, at least on the surface of it.

If you are not logged in and you click on 'Account login', on the front page, you can notice that your connection to GOG is a normal, unencrypted connection. How does GOG protect my password?
Actually AFAIK the login page is partially encrypted, so your password isn't sent in the clear, and the checkout page is encrypted as well.

Besides this, they salt the passwords so even if the database is compromised they can't actually easily retrieve usable data.

Later edit: Yep, just checked, the handshake and everything pertaining to the login is encrypted
Post edited December 16, 2011 by AndrewC
avatar
AndrewC: Besides this, they salt the passwords so even if the database is compromised they can't actually easily retrieve usable data.
And pepper them. They're delicious!
avatar
AndrewC: Besides this, they salt the passwords so even if the database is compromised they can't actually easily retrieve usable data.
avatar
TheEnigmaticT: And pepper them. They're delicious!
Mmm, sounds yummy! I need that recipe ASAP, gonna make myself some grilled passwords :D
avatar
TheEnigmaticT: And pepper them. They're delicious!
avatar
AndrewC: Mmm, sounds yummy! I need that recipe ASAP, gonna make myself some grilled passwords :D
Don't be fooled, that P in the beginning of the word is just a horrendous ploy.

Do not try them!
avatar
AndrewC: Mmm, sounds yummy! I need that recipe ASAP, gonna make myself some grilled passwords :D
avatar
Profanity: Don't be fooled, that P in the beginning of the word is just a horrendous ploy.

Do not try them!
Neah, I trust TheEnigmaticT; and just in case he's lying, I can always ban his ass on IRC :D It's a MAD scenario we've got going on.
avatar
Profanity: Don't be fooled, that P in the beginning of the word is just a horrendous ploy.

Do not try them!
avatar
AndrewC: Neah, I trust TheEnigmaticT; and just in case he's lying, I can always ban his ass on IRC :D It's a MAD scenario we've got going on.
Well alright, enjoy your asswords.