on 31-01-2022 23:15
I was just experiementing with "Manage my TiVo" on my laptop but got a warning about the site being insecure and it looks like it's all unencrypted. That can't be right surely????
on 02-02-2022 09:55
Good morning @escargo.
Welcome back to the forums & thank you for taking the time to post.
I am sorry to hear that you are having some issues with this, please could you let me know if you have a VPN set up & if you are using this to try and access this?
Kind regards,
Zak_M
on 04-02-2022 00:23
Hi, No I'm not using a VPN or anything. I just had the TVGo app open on my lap top, clicked on "Manage my Box"
and it took me to the insecure webpage: "http://manage-virgintvgo.virginmedia.com/tivo/"
It's not even a https address which seems pretty poor in this day and age.
Name: manage-virgintvgo.virginmedia.com
Address: 213.105.9.17
on 04-02-2022 09:13
on 04-02-2022 21:30
So the traffic itself isn't encrypted across the internet and could be subjected to a cookie replay attack?
😞
on 05-02-2022 12:01
So talking with support over twitter they've confirmed VirginMedia websites aren't encrypted once authenticated but they are "Working hard" to get this in place "very soon".
Disappointing this isn't already the case but not much us customers can do about it.
on 06-02-2022 12:07
Hello @escargo,
Thanks for the update.
I am sorry for the inconvenience this has caused.
Many thanks,
New around here? To find out more about the Community check out our Getting Started guide
on 15-12-2022 16:55
Now December 2022 and the issue remains. Further, the site throws a "page cant be reached" message. Maybe the functionality to manage your Tivo should be removed from the app.
on 16-12-2022 17:40
Hi there @jjaggii
We are so sorry that this issues is continuing but as out community members have stated all entry into the site does go through the https sign in pages.
Thank you again
on 16-12-2022 18:39
The sign in might be protected but the rest of the traffic isn't.
Which means someone could see the traffic and then use a cookie today to delete all your recordings.
Or someone could see what programs you are recording which you may not want eg if they strongly hint at personal information you don't want disclosed.
Both of those are unlikely, but still possible. Just turn on encryption everywhere.