Select Page

Ars Technica: Tens of millions of Match.com subscribers risk having their site password exposed each time they sign in because the dating site doesn’t use HTTPS encryption to protect its login page. Amazingly, the login page uses an unprotected connection to transmit the data, allowing anyone with a man-in-the-middle vantage point — say, someone on the same public network as a Match.com user — to pilfer the credentials. Had Match.com followed basic security practices and properly enabled HTTPS on the login page, the entire session would be unintelligible to all but the end user and connecting server.