cancel
Showing results for 
Search instead for 
Did you mean: 

Manage my TiVo from PC insecure???

escargo
On our wavelength

I was just experiementing with "Manage my TiVo" on my laptop but got a warning about the site being insecure and it looks like it's all unencrypted. That can't be right surely????

escargo_0-1643670810942.png

 

9 REPLIES 9

Zak_M
Forum Team (Retired)
Forum Team (Retired)

Good morning @escargo

 

Welcome back to the forums & thank you for taking the time to post. 

 

I am sorry to hear that you are having some issues with this, please could you let me know if you have a VPN set up & if you are using this to try and access this? 

 

Kind regards,

Zak_M

escargo
On our wavelength

Hi,  No I'm not using a VPN or anything. I just had the TVGo app open on my lap top, clicked on "Manage my Box" 

escargo_0-1643933918172.png

and it took me to the insecure webpage: "http://manage-virgintvgo.virginmedia.com/tivo/"

It's not even a https address which seems pretty poor in this day and age.

Name: manage-virgintvgo.virginmedia.com
Address: 213.105.9.17

BenMcr
Very Insightful Person
Very Insightful Person
Although the site is http, all entry into the site does go through https sign in pages.
**********************************
I work for Virgin Media - but all opinions posted here are my own

escargo
On our wavelength

So the traffic itself isn't encrypted across the internet and could be subjected to a cookie replay attack?

😞

escargo
On our wavelength

So talking with support over twitter they've confirmed VirginMedia websites aren't encrypted once authenticated but they are "Working hard" to get this in place "very soon".

Disappointing this isn't already the case but not much us customers can do about it.

Hayley_S
Forum Team (Retired)
Forum Team (Retired)

Hello @escargo,

Thanks for the update.

I am sorry for the inconvenience this has caused.

Many thanks,

Hayley
Forum Team



New around here? To find out more about the Community check out our Getting Started guide


jjaggii
On our wavelength

Now December 2022 and the issue remains. Further, the site throws a "page cant be reached" message. Maybe the functionality to manage your Tivo should be removed from the app.

Hi there @jjaggii 

 

We are so sorry that this issues is continuing but as out community members have stated all entry into the site does go through the https sign in pages. 

 

Thank you again

The sign in might be protected but the rest of the traffic isn't.

 

Which means someone could see the traffic and then use a cookie today to delete all your recordings.

 

Or someone could see what programs you are recording which you may not want eg if they strongly hint at personal information you don't want disclosed.

 

Both of those are unlikely, but still possible. Just turn on encryption everywhere.