DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

Collapse
 
guneyozsan profile image
Guney Ozsan • Edited

Turk Telekom's homepage for customer accounts defaults to http. It becomes https only on login page. Plus, links to the same thing from their main website still leads to their abandoned old site with an expired certificate 5-6 months ago.

I reported this on Twitter, got contacted by 3 different people on the phone from various tiers, and only response I could get was everything is ok and I should try on a different browser.

1 month fast forward, the pages are still untouched for you to try on a different browser:
Non-https customer home page:
ttmobil.com.tr
Links to abandoned customer site (just pick any option):
bireysel.turktelekom.com.tr/mobil/...