• Twitter
  • Facebook
  • Blog
  • Blogs
  • FAQ

Go Back   Talk Tennis > Competitive Tennis Talk > Adult League & Tournament Talk
Reload this Page USTA Membership Site Security Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
Old 02-01-2013, 07:21 PM   #1
SwankPeRFection
Professional
 
SwankPeRFection's Avatar
 
Join Date: Apr 2012
Posts: 1,029
Exclamation USTA Membership Site Security Issues

Has anyone else noticed how on the USTA site when you log in and pull up your account summary pages it has a proper SSL encryption for the site, but the minute you click on renew membership or try to buy something it takes you to a checkout page that's no longer SSL encrypted?

WTF USTA?!
SwankPeRFection is offline   Reply With Quote
SwankPeRFection
View Public Profile
Find More Posts by SwankPeRFection
Old 02-01-2013, 08:15 PM   #2
darrinbaker00
Semi-Pro
 
Join Date: May 2005
Location: Berkeley, CA
Posts: 776
Default

You decided to start a thread on a message board instead of asking the USTA about it because.....?
darrinbaker00 is offline   Reply With Quote
darrinbaker00
View Public Profile
Visit darrinbaker00's homepage!
Find More Posts by darrinbaker00
Old 02-01-2013, 08:25 PM   #3
SwankPeRFection
Professional
 
SwankPeRFection's Avatar
 
Join Date: Apr 2012
Posts: 1,029
Default

Quote:
Originally Posted by darrinbaker00 View Post
You decided to start a thread on a message board instead of asking the USTA about it because.....?
Don't quit your day job because making assumptions is not your forte.

Think of this thread as a public service announcement.

Last edited by SwankPeRFection : 02-01-2013 at 08:32 PM.
SwankPeRFection is offline   Reply With Quote
SwankPeRFection
View Public Profile
Find More Posts by SwankPeRFection
Old 02-01-2013, 11:13 PM   #4
beernutz
Hall Of Fame
 
beernutz's Avatar
 
Join Date: Aug 2005
Location: expanding my Ignore List
Posts: 3,334
Default

https://secure.ustashop.com/checkout.php
__________________
I have come to the conclusion that people who respond to forum posts with "tl;dnr" should really be writing "add;dnr".
beernutz is offline   Reply With Quote
beernutz
View Public Profile
Visit beernutz's homepage!
Find More Posts by beernutz
Old 02-02-2013, 08:05 AM   #5
fleabitten
Semi-Pro
 
fleabitten's Avatar
 
Join Date: Mar 2005
Location: surfing through tennisopolis.com
Posts: 692
Default

Quote:
Originally Posted by SwankPeRFection View Post
Think of this thread as a public service announcement.
Well said, and plus, asking the USTA to fix their website is like yelling underwater, nobody hears you. The USTA site is so clumsy and horrible as far as navigation goes, this just adds to it.
__________________
Constantly on the lookout for new challenges!
Tennis Partners | Tennis Players | http://www.tennisopolis.com
fleabitten is offline   Reply With Quote
fleabitten
View Public Profile
Visit fleabitten's homepage!
Find More Posts by fleabitten
Old 02-02-2013, 08:50 AM   #6
SwankPeRFection
Professional
 
SwankPeRFection's Avatar
 
Join Date: Apr 2012
Posts: 1,029
Default

Quote:
Originally Posted by beernutz View Post
https://secure.ustashop.com/checkout.php
What's your point?


Go here once you're logged in... https://membership.usta.com/checkout/checkout.jsp#init and you'll see how the browser bar at the last second once it's done loading switches to a non-SSL site. (i.e. the lock isn't there anymore to indicate the connection to the webpage is still encrypted.
SwankPeRFection is offline   Reply With Quote
SwankPeRFection
View Public Profile
Find More Posts by SwankPeRFection
Old 02-02-2013, 11:57 AM   #7
beernutz
Hall Of Fame
 
beernutz's Avatar
 
Join Date: Aug 2005
Location: expanding my Ignore List
Posts: 3,334
Default

My point is that the important parts of that page like your credit card information are encrypted. Only some google remarketing components are unencrypted which is why your browser is giving you a warning. If you look at the page properties you'll likely see something like this:

__________________
I have come to the conclusion that people who respond to forum posts with "tl;dnr" should really be writing "add;dnr".
beernutz is offline   Reply With Quote
beernutz
View Public Profile
Visit beernutz's homepage!
Find More Posts by beernutz
Old 02-02-2013, 01:25 PM   #8
SwankPeRFection
Professional
 
SwankPeRFection's Avatar
 
Join Date: Apr 2012
Posts: 1,029
Default

Doesn't matter. If the normal account info page has full encryption for ALL frames and content, then the renewal and checkout page should be the same way. Anything else and it leaves the page vulnerable to redirects, etc. That's bad page writing. There's no reason why there should be anything else on that page other than your own checkout info. What moron writes other crap into a page that's meant to be secure!? They just have idiots write code for them, both for their webpage and for their mobile apps, which are utter crap and need to be seriously rewritten. I'm just tired of their crap IT standards!!!
SwankPeRFection is offline   Reply With Quote
SwankPeRFection
View Public Profile
Find More Posts by SwankPeRFection
Old 02-02-2013, 06:34 PM   #9
beernutz
Hall Of Fame
 
beernutz's Avatar
 
Join Date: Aug 2005
Location: expanding my Ignore List
Posts: 3,334
Default

Quote:
Originally Posted by SwankPeRFection View Post
Doesn't matter. If the normal account info page has full encryption for ALL frames and content, then the renewal and checkout page should be the same way. Anything else and it leaves the page vulnerable to redirects, etc. That's bad page writing. There's no reason why there should be anything else on that page other than your own checkout info. What moron writes other crap into a page that's meant to be secure!? They just have idiots write code for them, both for their webpage and for their mobile apps, which are utter crap and need to be seriously rewritten. I'm just tired of their crap IT standards!!!
Lol. You have a lot of professional web coding experience?
__________________
I have come to the conclusion that people who respond to forum posts with "tl;dnr" should really be writing "add;dnr".
beernutz is offline   Reply With Quote
beernutz
View Public Profile
Visit beernutz's homepage!
Find More Posts by beernutz
Old 02-02-2013, 06:41 PM   #10
darrinbaker00
Semi-Pro
 
Join Date: May 2005
Location: Berkeley, CA
Posts: 776
Default

Quote:
Originally Posted by SwankPeRFection View Post
Doesn't matter. If the normal account info page has full encryption for ALL frames and content, then the renewal and checkout page should be the same way. Anything else and it leaves the page vulnerable to redirects, etc. That's bad page writing. There's no reason why there should be anything else on that page other than your own checkout info. What moron writes other crap into a page that's meant to be secure!? They just have idiots write code for them, both for their webpage and for their mobile apps, which are utter crap and need to be seriously rewritten. I'm just tired of their crap IT standards!!!
In that case, why don't you submit your resume to the USTA? They could obviously use someone with your expertise.
darrinbaker00 is offline   Reply With Quote
darrinbaker00
View Public Profile
Visit darrinbaker00's homepage!
Find More Posts by darrinbaker00
Old 02-02-2013, 07:06 PM   #11
mikeler
G.O.A.T.
 
mikeler's Avatar
 
Join Date: Sep 2008
Location: Central Florida
Posts: 14,833
Default

The OP is right. Once you go into SSL mode, it is generally not advisable to come out of it.
mikeler is offline   Reply With Quote
mikeler
View Public Profile
Find More Posts by mikeler
Old 02-03-2013, 07:39 AM   #12
SwankPeRFection
Professional
 
SwankPeRFection's Avatar
 
Join Date: Apr 2012
Posts: 1,029
Default

(After further testing.) Seems the mobile site can maintain the SSL encryption throughout the entire checkout/payment session, just the full website cannot.
SwankPeRFection is offline   Reply With Quote
SwankPeRFection
View Public Profile
Find More Posts by SwankPeRFection
Old 02-04-2013, 05:59 AM   #13
Adles
New User
 
Join Date: Jan 2013
Location: NH
Posts: 37
Default

I got a "Malware Alert" from my browser (Chrome) today on the USTA site, saying that there was known malware from cmi.netseer.com on the mixed doubles team page I was trying to look at.

Perhaps I should stay away from mixed doubles?

Has anyone else gotten this message? A big red screen from Google Chrome, saying to stay away.
Adles is offline   Reply With Quote
Adles
View Public Profile
Find More Posts by Adles
Reply

« Previous Thread | Next Thread »


Go Back   Talk Tennis > Competitive Tennis Talk > Adult League & Tournament Talk
Reload this Page USTA Membership Site Security Issues

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 04:51 PM.

Talk Tennis :: Powered By Tennis Warehouse - Archive - Top

Powered by vBulletin® Version 3.6.9
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
© 2006 - Tennis Warehouse