NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

schumaku's avatar
schumaku
Guru - Experienced User
May 26, 2019
Status:
New Idea

Login Page Enhancement - Add Content to the https Baisc Auth Page so the Browser shows Secure

A problem all over Netgear consumer BU where https is available and Baisc Authentication is used to query the username and password - browsers show an insecure connection!

Permitting the connection is using https for these domains (as of writing) where Netgear does provide a perfeclty signed certificate for 

DNS-Name=www.routerlogin.net
DNS-Name=routerlogin.net
DNS-Name=www.orbilogin.com
DNS-Name=orbilogin.net
DNS-Name=routerlogin.com
DNS-Name=orbilogin.com
DNS-Name=www.routerlogin.com
DNS-Name=www.orbilogin.net
the users are on the secure side of the things - however, the browsers indicate a non-secure connection during the initial login where the username and password is prompted.

Trouble is that browsers consider a plain HTML Basic Auth - before any content data is exchanged - on a https connection insecure. This applies to modern browsers like Chrome, Edge, Firefox, ... regardless of the connection is run e.g. on TLSv1.2, and all the certificate and crypto exchange is done, and the certificate (with the "shared" private key on many products) is perfectly valid.

 

Netgear must re-think their design philosophy for this process - undoubted a balance between fingerprinting (gee, the certificate does unveil much more). Simply adding some content to the Web page - see the case with the multiple login warning - would fix this issue easily.


Here again, we can't use multiple in-line photos/images - so multiple images are mixed into one attachment. ChristineT 

No CommentsBe the first to comment