Menu
News
All News
Dungeons & Dragons
Level Up: Advanced 5th Edition
Pathfinder
Starfinder
Warhammer
2d20 System
Year Zero Engine
Industry News
Reviews
Dragon Reflections
White Dwarf Reflections
Columns
Weekly Digests
Weekly News Digest
Freebies, Sales & Bundles
RPG Print News
RPG Crowdfunding News
Game Content
ENterplanetary DimENsions
Mythological Figures
Opinion
Worlds of Design
Peregrine's Nest
RPG Evolution
Other Columns
From the Freelancing Frontline
Monster ENcyclopedia
WotC/TSR Alumni Look Back
4 Hours w/RSD (Ryan Dancey)
The Road to 3E (Jonathan Tweet)
Greenwood's Realms (Ed Greenwood)
Drawmij's TSR (Jim Ward)
Community
Forums & Topics
Forum List
Latest Posts
Forum list
*Dungeons & Dragons
Level Up: Advanced 5th Edition
D&D Older Editions
*TTRPGs General
*Pathfinder & Starfinder
EN Publishing
*Geek Talk & Media
Search forums
Chat/Discord
Resources
Wiki
Pages
Latest activity
Media
New media
New comments
Search media
Downloads
Latest reviews
Search resources
EN Publishing
Store
EN5ider
Adventures in ZEITGEIST
Awfully Cheerful Engine
What's OLD is NEW
Judge Dredd & The Worlds Of 2000AD
War of the Burning Sky
Level Up: Advanced 5E
Events & Releases
Upcoming Events
Private Events
Featured Events
Socials!
EN Publishing
Twitter
BlueSky
Facebook
Instagram
EN World
BlueSky
YouTube
Facebook
Twitter
Twitch
Podcast
Features
Top 5 RPGs Compiled Charts 2004-Present
Adventure Game Industry Market Research Summary (RPGs) V1.0
Ryan Dancey: Acquiring TSR
Q&A With Gary Gygax
D&D Rules FAQs
TSR, WotC, & Paizo: A Comparative History
D&D Pronunciation Guide
Million Dollar TTRPG Kickstarters
Tabletop RPG Podcast Hall of Fame
Eric Noah's Unofficial D&D 3rd Edition News
D&D in the Mainstream
D&D & RPG History
About Morrus
Log in
Register
What's new
Search
Search
Search titles only
By:
Forums & Topics
Forum List
Latest Posts
Forum list
*Dungeons & Dragons
Level Up: Advanced 5th Edition
D&D Older Editions
*TTRPGs General
*Pathfinder & Starfinder
EN Publishing
*Geek Talk & Media
Search forums
Chat/Discord
Menu
Log in
Register
Install the app
Install
Community
General Tabletop Discussion
*Pathfinder & Starfinder
The biggest issue with the new Character Builder:
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
<blockquote data-quote="Festivus" data-source="post: 5380447" data-attributes="member: 34532"><p>I really just have a couple major concerns about security with the site, simple things they could do to build my confidence. The performance and bugs will be worked otu in time, yes. However, I pointed these out and have yet to hear of any action or plan of action for them:</p><p></p><p>* Wrap sessions in SSL and use encrypted cookies - Right now, you use the same user name and password to set up your credit card information as you do to log into DDI. DDI isn't a secure site, there is no padlock. This is something they *should* be able to fix with relative ease, but have not yet done so (it's been this way since launch... really silly)</p><p></p><p>* Don't divulge critical internal workings of code when an error occurs is another. That should also be easy to fix, it's a setting on the server. I have seen enough crash dumps to be able to tell you where they store the databases on their servers, what kind of database and web server they are using, and a few other juicy details (like the field name for the login name).</p><p></p><p>I am waiting for the letter to arrive in my mailbox when they have a breach... because it's going to happen sooner rather than later with them.</p></blockquote><p></p>
[QUOTE="Festivus, post: 5380447, member: 34532"] I really just have a couple major concerns about security with the site, simple things they could do to build my confidence. The performance and bugs will be worked otu in time, yes. However, I pointed these out and have yet to hear of any action or plan of action for them: * Wrap sessions in SSL and use encrypted cookies - Right now, you use the same user name and password to set up your credit card information as you do to log into DDI. DDI isn't a secure site, there is no padlock. This is something they *should* be able to fix with relative ease, but have not yet done so (it's been this way since launch... really silly) * Don't divulge critical internal workings of code when an error occurs is another. That should also be easy to fix, it's a setting on the server. I have seen enough crash dumps to be able to tell you where they store the databases on their servers, what kind of database and web server they are using, and a few other juicy details (like the field name for the login name). I am waiting for the letter to arrive in my mailbox when they have a breach... because it's going to happen sooner rather than later with them. [/QUOTE]
Insert quotes…
Verification
Post reply
Community
General Tabletop Discussion
*Pathfinder & Starfinder
The biggest issue with the new Character Builder:
Top