Wiki now uses forum logins

You can now sign in to the documentation wiki with your forum user name and password. Anyone with a forum account can add pages, fix errors, and make updates.

For the last couple months wiki registrations have been disabled. Wiki spammers are relentless, recaptcha and bad behavior only slowed the stupidest bots. It’s a lot easier to handle spammers through the forum, especially with our home-spun forum spam hammer MOD. The non-standard configuration should also send most common scripts packing.

Thanks for your edits to the wiki. It’s a community resource and you should feel at home making changes. Soon you can get a free PCB code for contributing to the wiki. More on that soon.

A special thanks to TREV, our volunteer wiki librarian. He keeps the pages categorized, fixes text, and reorganizes pages as needed.

Join the Conversation

3 Comments

      1. Hi Ian, Yes… This is a major problem security problem that goes unaddressed, especially with Blogs and more-so with Forums (where you need to enter a username and passwod).

        When I said SSH, I meant SSL (which is supposedly called TLS now).

        When you are accessing the Web from a public WiFi connection. Your Blog post is open and your Email address (which I prefer to keep real when I post here) can be scraped by third-parties. This is especially dangerous on public WiFi access points that do not require a SSL/TLS login of any type (even if the user and password are “free” and “free” for-example, Google the Firesheep exploit for more on this).

        When we drop to post mode in the Blog or Forum, a SSL/TLS session should start (little padlock icon in the tray). After posting it is OK to drop out of the SSL/TLS session. This should not burden your servers much as the SSL /TLS session is only established when posting in the Blog, or even smaller-yet, when logging in to the Forum.

        To get SSL/TLS working, you need to self generate a certificate (don’t buy one, they’re too expensive). The user will get a message saying the certificate is not verified, but with little effort the user can see you are self generating the certificate and accept it once (better), or forever.

        The other day I was playing with Firesheep in a local hangout with public no password-protected WiFi. I was able to hijack the likes of Blog and social media sessions that friends established on the same network easily. Not good. So now I only login and/or post to Blogs and Forums from home, where my network is extremely secure (wired only).

        Steve Gibson of GRC Research and Host of the Security Now netcast has covered this issue in detail. http://www.grc.com There’s a Community at grc.com that can shed a lot of light on this and what you may do to rectify it.

        Regards, David in Jakarta

Leave a comment

Your email address will not be published. Required fields are marked *

Notify me of followup comments via e-mail. You can also subscribe without commenting.