Ummm.... With basic authentication, my server is open to the world without a password???

Joined
Aug 26, 2020
Messages
3
Reaction score
0
Location
USA
So I have my server setup on https via a URL so I can view from anywhere. I used to use the "secure session keys and login" option, however I recently unchecked that so I could pass triggers w/ passwords via URL (), which uses basic authentication.
Come to find out, my server has been accessible to the world from myurl.com without any type of authentication! Even tested accessing it from a tor browser outside my home network to confirm!
Why is this, that seems to defeat the whole purpose of authentication!
v 5.3.2.2
 

mat200

IPCT Contributor
Joined
Jan 17, 2017
Messages
14,030
Reaction score
23,361
Welcome LavaTiger99....

hint: See the VPN notes...
 

biggen

Known around here
Joined
May 6, 2018
Messages
2,606
Reaction score
2,915
So you port forward directly to your BI machine? That's bad. When you pass triggers like that is it passing your username and password in the clear as well?

You need a VPN server. You connect to that from outside your network first and then access BI.
 
Top