{"id":567,"date":"2011-05-15T02:02:03","date_gmt":"2011-05-15T01:02:03","guid":{"rendered":"http:\/\/www.stevenwhiting.com\/blog\/?p=567"},"modified":"2012-06-03T03:50:31","modified_gmt":"2012-06-03T02:50:31","slug":"wonderland-models-security-issue","status":"publish","type":"post","link":"https:\/\/stevenwhiting.com\/blog\/?p=567","title":{"rendered":"Wonderland Models Security Issue"},"content":{"rendered":"<p>http:\/\/www.youtube.com\/watch?v=wSlHEKQAQ04<\/p>\n<p>I&#8217;d avoid shopping at their online store until they fix HTTPS. Neither their registration page uses HTTPS nor does the login box. So user names and passwords are sent over in plain text. Makes you wonder what sort of security they have on the customer database. I bet that&#8217;s not even encrypted.<\/p>\n<p>The issue is if anyone is sniffing the traffic on the network you&#8217;re on, they&#8217;ll be able to get your login details and password for that site. If you use the same password on othersites then they&#8217;d be able to gain access to that as well.<\/p>\n<p>Reported it almost a week ago to them and their website devs. Both have ignored the e-mails. And their contact e-mail in fact fails. I had to use their online form.<\/p>\n<p>UPDATE- They have finally contacted me and said they are working on fixing security across the whole site.<\/p>\n<p>UPDATE 2 -This has now been fixed.\u00a0 I&#8217;ve tested and all now fine so I removed the video.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>http:\/\/www.youtube.com\/watch?v=wSlHEKQAQ04 I&#8217;d avoid shopping at their online store until they fix HTTPS. Neither their registration page uses HTTPS nor does the login box. So user names and passwords are sent over in plain text. Makes you wonder what sort of &hellip; <a href=\"https:\/\/stevenwhiting.com\/blog\/?p=567\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-567","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=567"}],"version-history":[{"count":5,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/567\/revisions"}],"predecessor-version":[{"id":1044,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/567\/revisions\/1044"}],"wp:attachment":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}