Can't I just sniff what my browser sends to the server?
I'm suspicious.
This is a real problem though.
PS: You might want to reconsider that name. Meldium, to me at least, just looks like someone typoed when trying to type Medium.
Can't I just sniff what my browser sends to the server?
I'm suspicious.
This is a real problem though.
PS: You might want to reconsider that name. Meldium, to me at least, just looks like someone typoed when trying to type Medium.
Regardless of your answer I think these questions make it clear that you should definitely consider adding some more detailed explanations to your website about how exactly your product works. Especially for a security related product this is pretty important.
I say this as someone who is very interested in paying someone to solve this problem for me.
It's probably a reasonable trade for a lot of services -- I'd probably use it for an analytics dashboard, etc., but probably not for admin interfaces to do stuff to customer data (which you presumably could set up with individual user accounts and group/role management, anyway). This seems to be aimed at the ~bunch of low security passwords which are either the same across your whole business, or stored in a google docs spreadsheet now, not the most important credentials for your users.
I don't mean this to criticize you, one of the first scripts I ever sold was a better UI to a service that basically used Cross Site Request Forgery to do the work.
The solution I'm going with now is a native client that creates the cookies locally which the browser extension then accesses. Mine's also not immediately marketed towards teams but rather individuals.
Best of luck.
http://cl.ly/image/3f3x3R0N0y2W
If I had actually logged in you would see my password in the space that currently says NotActuallyMyPassword.
I don't see how Meldium could prevent that.
It is also possible to run the proxy server on the end user machine and use a mechanism called SSL tunneling to securely replace the password. Its hard to explain it here but it can be done. The benefit of running the proxy on the end user machine is that you don't have to route your traffic through a remote proxy.
I have a system which has this thing working - will open-source it under github soon.
You might be able to view the password using something like https://addons.mozilla.org/en-us/firefox/addon/tamper-data/ provided that runs after their extension.