Acronis Forum Site does not use HTTPS but uses our Acronis Credentials!!!
As the title says: This Acronis Forum Site does not use HTTPS but uses our Acronis Credentials!!! Seriously this is a major security risk and needs to be fixed yesterday.

- Log in to post comments

Gareth Willis wrote:As the title says: This Acronis Forum Site does not use HTTPS but uses our Acronis Credentials!!! Seriously this is a major security risk and needs to be fixed yesterday.
How is this a security risk?
- Log in to post comments

@Howard,
Yes, it is a major and obvious security flaw and I don't understand how a serious company can do it this way and not to fix ASAP.
An innocent user sets his username/password for Acronis and, since main site uses HTTPS, supplies a valuable password which she is using to purchase Acronis or possibly on some other secure sites. Then, after a while, here at Acronis forums she is asked to supply her Acronis site credentials to log in. It's enough not to realize that her credentials are now sent over internet in clear text, to become an easy target for hackers.
@GroverH,
I don't understand how editing a nickname could help, since this site do not use nickname as a username. It only allows to login with your real username/password from main Acronis site.
And even if such a trick worked, it still would be a major security flaw in site design. It makes me wonder if I really want to leave my valuable backups in such problematic hands.
- Log in to post comments

Hello all,
This topic makes a great sense for us and we were working on enabling the HTTPS for login functionality. It will be deployed to production soon.
Thanks
- Log in to post comments

Hello all,
This is resolved for now. Any form that is asking you for the credentials is now posting the data using the HTTPS protocol.
Thanks
- Log in to post comments