113 registered users have written 52 reviews of 222 spots! and 5 answers to 3 questions by Nairobians, old and new!
If you're a business owner, click here for more information, or email us at sales@newhanoian.com.
If you'd like information about placing your banner ad on this site, send us an email at sales@newhanoian.com.
As you’ve probably noticed we’ve changed our URL to http://tnhvietnam.xemzi.com. We’ve also added a regional sub-site for Central Vietnam. At the same time we’ve changed our front page layout so that you can get a better overview of what’s happening on the site.
Apart from the cosmetic changes we’ve rewritten a large part of the site code that handles URLs, so if you see any problems with missing pages (or any other technical problems related to these changes) please let us know at tech@tnhvietnam.com
Last night I was made aware of a glaring problem with TNH site security by a helpful site member, Drew Butler (thanks Drew!).
It turns out in a code update I made around New Year I had left in some testing code that bypassed password security, meaning that you could login as any user using any password.
I fixed the problem last night and logged out all users as a precaution.
There were two basic classes of exploit associated with this issue:
1) Write – post as another user. I haven’t seen any instances of this, but please let us know if you think it may have happened
2) Read – a malicious user could access another’s account to read their private messages.
Additionally, a malicious user could change their victim’s password. This appears to have happened on at least one occasion. If this has happened to you please let us know, and reset your password through the password reset function.
This is obviously very embarrassing to me, and I apologize for any inconvenience that may have been caused. The irony that this occurred when I made a change to login to make your passwords more secure is not lost on me.
If you have any concerns about this or want more information, please post here or send mail to info@tnhvietnam.com
We’ve recently made some changes to what happens behind the scenes when you login to TNH. You might have noticed you’ve been logged out and had to re-login after the Christmas break. When you re-logged-in your password was re-stored in a much more secure manner (using bcrypt for the techies among you).
We’ve had some reports of error messages on login or logout. Some of them might have caused alarm, saying your session had been hijacked. This is likely our fault, but we’d like to hear about it at tech@tnhvietnam.com when you run into problems.
Please also continue to send us reports of any problems you encounter, being sure to tell us what browser you are using.
Thanks,
TNH