|
|
|
|
|
|
The Unsettler
|
Quote:
Let's Encrypt is a one button click install and configure in Plesk these days. I think it may be in cPanel as well. And it auto renews now so short cert life not that big a deal anymore.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" Last edited by stomachmonkey; 04-03-2019 at 06:47 AM.. |
||
|
|
|
|
The Unsettler
|
Quote:
It'd probably be painfully slow and then there is the "...but you said it was not that big a threat and I got hacked..." crowd. Personally I hate it.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
|
|
|
|
The Unsettler
|
Did you ask the Pelican Brain Trust first?
If you did I missed it so my apologies there. You can always go Let's Encrypt when your current cert expires.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
|
|
|
|
Brew Master
|
Nope! Shoulda known better too! If it can be answered, it'll be answered here.
__________________
Nick |
||
|
|
|
|
Counterclockwise?
|
When I switched my company's domain over to GoDaddy last year they really pushed me for a "secure" site.
They made it sound like I better spend the extra or ....you know. It's a content only website.
__________________
Rod 1986 Carrera 2001 996TT A bunch of stuff with spark plugs |
||
|
|
|
|
Banned
Join Date: May 2014
Posts: 15,053
|
|||
|
|
|
|
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 7,008
|
It needs to be fixed period.
The page in the concern category is the login page; meaning your username and password are sent in clear text over the internet. Please fix Pelican
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
|
|
|
|
Registered
Join Date: Jun 2003
Location: Calgary Alberta, CANADA
Posts: 2,113
|
If you offer a forum with free speech there are responsibilities...
The feds will want to be able to access all your messages and what you send (even if using a 2nd account). So, this is not a technical thing... its a "I leave you alone but cooperate" kind of deal..
__________________
We're all in the gutter,but some of us are looking at the stars. -Oscar Wilde |
||
|
|
|
|
Information Overloader
Join Date: Mar 2003
Location: NW Lower Michigan
Posts: 29,486
|
I read this entire thread. It reminds me of statistics. I sat through an entire term of statistics in college and didn’t understand any of it.
|
||
|
|
|
|
The Unsettler
|
Quote:
Which by the way, happy to see you don't. Yes, I checked.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
|
|
|
|
Mighty Meatlocker Turbo
Join Date: Apr 2016
Location: North TexASS
Posts: 18,538
|
Quote:
|
||
|
|
|
|
?
Join Date: Apr 2002
Posts: 30,621
|
Can't have yer "tits" transmitted over the Internet so the geeks can't see 'em....WAH
!What if it literally cost 7 figures to encrypt those pics? I used to live this stuff too...on a rather large scale .T-Rex |
||
|
|
|
|
?
Join Date: Apr 2002
Posts: 30,621
|
Quote:
I have to mow my own lawn though
Last edited by KFC911; 04-04-2019 at 03:01 AM.. |
||
|
|
|
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 7,008
|
Sorry they do have one, it just not implemented correctly ( I would suspect to let the adds in)
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
|
|
|
|
Still here
|
|||
|
|
|
|
You do not have permissi
Join Date: Aug 2001
Location: midwest
Posts: 40,041
|
The "already pinged" list of spam seems to have disappeared.
As noted, "secure" should only required for some functions. Maybe it's easier to code the whole site that way? Https removes any anonymity for visitors not using proxies. As does the new Pelican PARF loggin requirement and Google javascript required for private messages. More tracking. |
||
|
|
|
|
Registered
Join Date: Jun 2003
Location: Calgary Alberta, CANADA
Posts: 2,113
|
its a cross reference thing.. if the site is secure its harder to connect to unsecure sources of advertisements.. Also allows for xsite scripting injection, so more adevertisements and things like cookies can be injected and later harvested by other sites..
This is a technical choice. Profits over everything else. Lets not forget we are the product here
__________________
We're all in the gutter,but some of us are looking at the stars. -Oscar Wilde |
||
|
|
|
|
Registered
|
The forum should also use https as the certificate not only serves to encrypt the connection between the browser and the server, it also validates that you are connecting to the legitimate pelican forum server. In its current configuration it would be rather trivial to bring up another server and mascarade as forums.pelicanparts.com, conduct a DNS poisoning attack to redirect everyone to the imposter server and capture everyone's logins. The fact this is not their e-commerce site should not preclude them from protecting the forum servers. Attackers may be able to find their way into more sensitive areas of their operation. Remember the Target credit card breach? The attackers exploited a weakness in the HVAC systems and found their way to the credit card machines.
The go daddy cert issued to pelican parts e-commerce site can only be used on www.pelicanparts.com and pelicanparts.com. Pelican parts would need to either get another cert for forums.pelicanparts.com or update their current cert to a SAN cert that could be used for Loading, pelicanparts.com and forums.pelicanparts.com. I would opt for a separate cert so if one is compromised (say the forum cert) it doesn't affect the other (cert used for e-commerce site). Looking at the go daddy pricing for certs, a single domain is only $63.99 per year, a san cert is $159.99 per year and a wildcard cert which can be used on *.pelicanparts.com $295 per year. Cheap insurance IMHO. |
||
|
|
|
|
The Unsettler
|
Quote:
Far far far more likely the person hacked used an obvious easy to guess password than it was sniffed. I use a random pass generator along with a pass manager and two factor on every site that I can. I have accounts that I don’t even know the password for. We can rely on others for our security or take matters into our own hands. Obviously, I’m an advocate for the later.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
|
|
|
|
Burn the fire.
|
Just install the browser plugin "HTTPS Everywhere". Problem solved.
__________________
[x] Working | [_] Broken: 2017 Victory Octane [x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi "Drive it like you stole it." |
||
|
|
|