Posted 15 Aug 2016 by NeuralMiner
We're more concerned with the login credentials of users (as in to login to your account). For instance, any user that uses BAM will have the same ID/PW for every project they're a part of. So if an attacker is able to get their credentials from one project, they'd be able to log in to all the projects the user is a part of.
Posted 1 Aug 2016 by NeuralMiner

I'm a member of the Gridcoin community, and we're currently looking into providing better security for our crunchers.
It looks like this project isn't currently using an SSL certificate. Are there any plans to remedy this in the near future?

There's a chance that not having an SSL cert may lead to this project being removed from the project whitelist, which means it will no longer be crunched by the Gridcoin team.

The discussion regarding the whitelist can be found here:

