Just a small note (!), but it seems the password reset for NAS registration is plaintext. That's literally incredibly bad practice.
It makes me wonder how credentials are sent when I register the NAS itself - is that plaintext also?
If so this is P1 - fix it. Make it encrypted. What on earth...
Registration of NAS and password reset in PLAINTEXT ??
-
elfidge
- Posts: 25
- youtube meble na wymiar Warszawa
- Joined: Tue Oct 15, 2013 2:52 am
-
Vincent.T@AST
- Posts: 78
- Joined: Tue Apr 01, 2014 5:13 pm
Re: Registration of NAS and password reset in PLAINTEXT ??
Hi elfidge,
Thanks for reporting this issue to us. We will use https for the password reset process right away.
As to the NAS registration process, it is using https connection currently.
Thanks for reporting this issue to us. We will use https for the password reset process right away.
As to the NAS registration process, it is using https connection currently.