Alfred wrote:Does a forum login really need to be secure? I use other forums (including phpBB forums like this one) which do have a secure login, but I don't see any security issues as long as forum accounts are not linked to customers' online store accounts.
If you only see financial risks in the possibility of network abuse, you are cool, but identity theft has more consequences than a mere loss of money. All kinds of comparisons and metaphors come to mind, but I do not want to go through all of that, yet again. If technology exists, that helps to exclude some of the more frequent attacks on user-accounts, why not use it. And when it is simple to deploy, why not use it?
To claim that the secure login were “
necessary” required that we knew all the risks, while all we have is just stories told on the media. You can look these up, yourself, then compare. My question is rather why we cannot connect securely to a site, if the possibility exists?