Jump to content

Jez Caudle

Members
  • Posts

    4
  • Joined

  • Last visited

    Never

Jez Caudle's Achievements

Newbie

Newbie (1/14)

0

Reputation

  1. If you logout then login without the box ticked it will not log you in again automatically next time even when connected to the Livebox. Well it works for me anyway. ---- But I can't try it because I'm in the UK now :-( I'll have to send someone round to do it but they'll charge me €35 per hour for this. I did't have time to ring the help line today - something for tomorrows to-do list. Thanks every one for your help. I only joined the forum to try and get some help but I'll hang around and see if I can help others.
  2. Just got back to the UK and of course it doesn't recognise my IP address so asks me to log in. On the Cookie front, it isn't using cookies. I deleted all my cookies when I tried with Safari and it still worked. It still worked with Firefox and it still worked using IE7 when I fired up a virtual machine. It worked for my wife when she tried with her laptop. I didn't try my iPhone but I'm sure it would have gone straight in. Orange.fr recognises my IP address and the LiveBox that it is bound to and as a "convenience" logs me in without a user name and password. This is such a good idea the banks should adopt it - NOT! I was thinking of altering the routing tables on the LiveBox so that Orange.fr became inaccessible but I didn't have time. I don't need the email - I just don't want my rental clients being able to order mobile phones and other services when they are sat in my flat. Thanks for the tip re:logging out, but I'm back in the UK now so I can't actually follow your advice :-( Time to call the help line and try and not be abusive - as someone who is responsible for IT Security in my daily job that is going to be difficult. Looking forward to seeing the results of AnOther's wife's experiment.
  3. My difficulty is that I can get email via webmail without having to login. As can my wife and anyone else using my LiveBox. Have you tried going to www.orange.fr and seeing if it logs you in without having to enter a password? I'd love to know if it was just me.
  4. I have seen something posted along these lines elsewhere on this forum but I couldn't find a solution. I have just had ADSL installed in my rental flat. I have gone for the service from Orange with the TV channels and phone. Setting up the LiveBox and the TV was really easy - I have configured the dynamic DNS so I can do remote admin etc. I decided to see if I could administer my Orange account and visited Orange.fr To my horror it automatically logged me in and allowed me to read the 8 emails Orange have sent me. I tried visiting the web site using a different browser and it also logged me on automatically. I then asked the wife to try with her laptop and the same thing happened - straight in, no password. I'm leaving in the morning and have clients coming in. If they connect to the LiveBox and then visit Orange.fr they can administer my account, read my emails - do what they like. Does anyone know a way of closing this obvious security hole the size of bus? [Which idiot at Orange thought that this was a good idea? - I'm not expecting an answer to this question.]
×
×
  • Create New...