Just a warning to anyone who uses BCM. Seems like a good service, and I signed up this morning. Already have my new address. But being an IT/tech type, a immediately found a HUGE security hole with that service that they need to fix, and I plan on talking to them about it and maybe even helping them with it if they need help and want it.
First of all, they send you all your login info in an unencrypted email, so the first thing you need to do is change your password. Even worse, they send you a link to log in using unsecure, unencrypted http transport. This means that if you're on public wifi and not on a vpn, anyone with an ounce of networking savvy can see your password and login info right out in the open. They can then log in as you, read your mail, and even see your payment info.
I urge anyone who uses this service or signs up for it to make sure to add the "s" to http in the URL when logging in. So if you add that "s" so it's https:// instead of http:// BEFORE you log in, you should be OK. The site does not redirect to https, but at least it has a valid security certificate, even if it never really gets used. But you'll have to remember that if you follow any links, make sure you're going to https and NOT http.
I opened a ticket with the company in the hopes that they will fix this, as it is a huge liability for them and anyone who uses the service.
K
First of all, they send you all your login info in an unencrypted email, so the first thing you need to do is change your password. Even worse, they send you a link to log in using unsecure, unencrypted http transport. This means that if you're on public wifi and not on a vpn, anyone with an ounce of networking savvy can see your password and login info right out in the open. They can then log in as you, read your mail, and even see your payment info.
I urge anyone who uses this service or signs up for it to make sure to add the "s" to http in the URL when logging in. So if you add that "s" so it's https:// instead of http:// BEFORE you log in, you should be OK. The site does not redirect to https, but at least it has a valid security certificate, even if it never really gets used. But you'll have to remember that if you follow any links, make sure you're going to https and NOT http.
I opened a ticket with the company in the hopes that they will fix this, as it is a huge liability for them and anyone who uses the service.
K