SSL Certificate - Site not secure

What's Hot
SunDevilSunDevil Frets: 511
I've not been on here in quite a while

Why? ..on Safari, I get a message that this site isn't secure - ie it's SSL certificate is out of date

I did message Lee about this, but it was a day after he and Tony's announcement and I have no idea who might be dealing with this in his absence.

Having spoken to people I work with who know about this stuff, the site is likely to be targeted because of the expired and is prone to 'man in the middle attacks'

So this is me logging in to flag the issue before logging out again
The answer was never 42 - it's 1/137 (..ish)
0reaction image LOL 0reaction image Wow! 0reaction image Wisdom

Comments

  • RolandRoland Frets: 8689
    @digitalscream has addressed this question in the past. The key points are that we run the forum using freeware. If we had a large sum of money, and lots of man hours, then we could do something about it. We don’t, and we don’t, so we won’t. As long as members are sensible about what they say in PMs, and use email for things like bank details, then there isn’t a great deal of risk.
    Tree recycler, and guitarist with  https://www.undercoversband.com/.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • darthed1981darthed1981 Frets: 11743
    It's weird you get the error of the SSL certificate being out of date because, as Roland has pointed out, TFB does not use HTTPS...

    I tried using HTTPS to connect and it failed, so why does Safari think TFB supports it...?
    You are the dreamer, and the dream...
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • SnagsSnags Frets: 5359
    It's weird you get the error of the SSL certificate being out of date because, as Roland has pointed out, TFB does not use HTTPS...

    I tried using HTTPS to connect and it failed, so why does Safari think TFB supports it...?
    The issue is that browsers (Chrome in particular) are starting to explicitly label non-SSL sites as "insecure", in addition to showing HTTPS as secure. Rather than being passive about HTTP they're active trying to push encryption on everything.

    Depending on how tFB is hosted it could be put on SSL for free, in terms of the certificate, via Let's Encrypt. But someone still has to do all the work, and I seem to remember a post in the past indicating that not all of the site's functions worked when run over SSL.

    There are arguments either way, but I'd have thought that in the main it's more an ivory tower issue than real world one for here. Certainly if the choice is no SSL or no tFB.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • sixstringsuppliessixstringsupplies Frets: 429
    edited July 2018 tFB Trader
    It’s part of google’s mission to create a “fully secure web”

    As from 1st July 2018, google chrome will show a “not secure” warning to websites that are not https (ie they are http).

    it is essential for e-commerce businesses. i migrated my website from http to https end of June and it was a total ballache.

    it is a little harsh on “informational” sites such as news, blogs and forums for example, where no money changes hands and no data is shared. 

    as @Roland  says, no risk at all.

    the reality is that this website is no less secure than it was on 30th June, it’s just google’s policy has changed on how they present websites to internet users. 

    the only negative outcome is that google will *eventually* punish websites that are not secure which will probably start to happen in the next 12 months. 
    For Modders, Makers, Players

    https://sixstringsupplies.co.uk/

    Our YouTube Channel for handy "How-To" Wiring Tutorials
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • darthed1981darthed1981 Frets: 11743
    Snags said:
    There are arguments either way, but I'd have thought that in the main it's more an ivory tower issue than real world one for here. Certainly if the choice is no SSL or no tFB.

    If I recall Lee made a post that basically said the modifications made to the BBS system that TFB uses would not work with SSL as it stands, and therefore would require time consuming modifications that he simply doesn't have time to make any time soon.

    As you say, if the choice is stop moaning about SSL (not directed at the OP, this is not a new topic) or turn off TFB, I'll be fine with good old HTTP.
    You are the dreamer, and the dream...
    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom
  • gavin_axecastergavin_axecaster Frets: 526
    tFB Trader
    Making the switch to https from http also buggers up your search ranking for a while. I switched my entire site over (all pages with sensitive info were already https) about 2 months ago and I'm still not back to my former search ranking.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • digitalscreamdigitalscream Frets: 26560
    There are two possible plans for this - one is a fairly epic bit of work that I'm about half way through (but is on hold because I've got too much on for the next couple of months), and the other is an obscenely epic bit of work which might set this place up for the future.

    I'm currently weighing up the options (there is a third, but it's a bit distasteful).
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • FretwiredFretwired Frets: 24601
    There are two possible plans for this - one is a fairly epic bit of work that I'm about half way through (but is on hold because I've got too much on for the next couple of months), and the other is an obscenely epic bit of work which might set this place up for the future.

    I'm currently weighing up the options (there is a third, but it's a bit distasteful).
    There's probably a fourth. I've seen quite a few sites have built new forums and archived the old one. I think Line 6 are on iteration 4 ... the older ones are archived for a while and deleted.

    Remember, it's easier to criticise than create!
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • digitalscreamdigitalscream Frets: 26560
    Fretwired said:
    There are two possible plans for this - one is a fairly epic bit of work that I'm about half way through (but is on hold because I've got too much on for the next couple of months), and the other is an obscenely epic bit of work which might set this place up for the future.

    I'm currently weighing up the options (there is a third, but it's a bit distasteful).
    There's probably a fourth. I've seen quite a few sites have built new forums and archived the old one. I think Line 6 are on iteration 4 ... the older ones are archived for a while and deleted.
    I'm only talking about realistic options; in my opinion, archiving content on a site when the whole point of it is that content is live is a cop-out. Accordingly, that's not something I'm considering.
    <space for hire>
    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom
  • valevale Frets: 1052
    edited July 2018
    It’s part of google’s mission to create a “fully secure web”
    google's 'mission' is to own the internet.

    try to access any of the main sites these days without allowing google cookies etc and you get third rate lepers access and functionality. ebay, youtube, gumtree, etc.

    allow google cookies and suddenly the internet opens up to you, on condition...

    google's concept of internet liberty is to electronic tag everyone and lock them in a mall.

    google is evil.
    hofner hussie & hayman harpie. what she said...
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • crunchmancrunchman Frets: 11446
    I've been using DuckDuckGo as my search engine the last couple of months.  Seems to work ok for general use.  If we all start doing that, then we will reduce Google's reach.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • darthed1981darthed1981 Frets: 11743
    crunchman said:
    I've been using DuckDuckGo as my search engine the last couple of months.  Seems to work ok for general use.  If we all start doing that, then we will reduce Google's reach.
    All us fretboarders? Might want a couple of billion more volunteers.. 
    You are the dreamer, and the dream...
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
Sign In or Register to comment.