Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by id10t View Post
Free, works, and works well. Also works for doing SMTP w/ SSL/TLS and wrapping both POP3 and IMAP in SSL.

"Only" down side is short certificate life but if you have the skills to be messing around setting up web/mail servers and needing SSL you should be able to set up a cron job to keep your certificate valid.
Most people who don't have that skill are using a hosting panel like Plesk, cPanel.

Let's Encrypt is a one button click install and configure in Plesk these days.

I think it may be in cPanel as well.

And it auto renews now so short cert life not that big a deal anymore.

__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"

Last edited by stomachmonkey; 04-03-2019 at 06:47 AM..
Old 04-03-2019, 06:42 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #21 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by cstreit View Post
This is whats so frustrating about Google's decision and that of the browser companies following suit.

It scares the uninformed user. THere is simply no need to encrypt static boring content, but the "warning" implies that there is something nefarious going on.
Don't disagree but think about what would need to happen for the browser to make a determination on the risk of each bit of content running under a non secure directory.

It'd probably be painfully slow and then there is the "...but you said it was not that big a threat and I got hacked..." crowd.

Personally I hate it.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 04-03-2019, 06:45 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #22 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by cabmando View Post
Where were you a month ago!?
Did you ask the Pelican Brain Trust first?

If you did I missed it so my apologies there.

You can always go Let's Encrypt when your current cert expires.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 04-03-2019, 06:46 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #23 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,210
Garage
Quote:
Originally Posted by stomachmonkey View Post
Did you ask the Pelican Brain Trust first?

If you did I missed it so my apologies there.

You can always go Let's Encrypt when your current cert expires.
Nope! Shoulda known better too! If it can be answered, it'll be answered here.
__________________
Nick
Old 04-03-2019, 06:49 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #24 (permalink)
Counterclockwise?
 
Join Date: Oct 2005
Location: Keswick, Ontario
Posts: 6,471
Garage
When I switched my company's domain over to GoDaddy last year they really pushed me for a "secure" site.
They made it sound like I better spend the extra or ....you know.
It's a content only website.
__________________
Rod
1986 Carrera
2001 996TT
A bunch of stuff with spark plugs
Old 04-03-2019, 07:54 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #25 (permalink)
Banned
 
Join Date: May 2014
Posts: 15,053
Quote:
Originally Posted by speeder View Post
I've never noticed this before, in the address bar it says, "Not Secure--forums.pelicanparts.com

What the what?
It started showing up with the latest IPhone update.
Old 04-03-2019, 08:47 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #26 (permalink)
 
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 7,008
It needs to be fixed period.

The page in the concern category is the login page; meaning your username and password are sent in clear text over the internet.

Please fix Pelican
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 04-03-2019, 12:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #27 (permalink)
Registered
 
Oracle's Avatar
 
Join Date: Jun 2003
Location: Calgary Alberta, CANADA
Posts: 2,113
If you offer a forum with free speech there are responsibilities...
The feds will want to be able to access all your messages and what you send (even if using a 2nd account).

So, this is not a technical thing... its a "I leave you alone but cooperate" kind of deal..
__________________
We're all in the gutter,but some of us are looking at the stars.
-Oscar Wilde
Old 04-03-2019, 12:32 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #28 (permalink)
Information Overloader
 
Join Date: Mar 2003
Location: NW Lower Michigan
Posts: 29,486
I read this entire thread. It reminds me of statistics. I sat through an entire term of statistics in college and didn’t understand any of it.
Old 04-03-2019, 07:37 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #29 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by stealthn View Post
It needs to be fixed period.

The page in the concern category is the login page; meaning your username and password are sent in clear text over the internet.

Please fix Pelican
Meh, as long as one is not using the same user/pass as they use for say, their bank....

Which by the way, happy to see you don't.

Yes, I checked.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 04-03-2019, 08:23 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #30 (permalink)
Mighty Meatlocker Turbo
 
Rawknees'Turbo's Avatar
 
Join Date: Apr 2016
Location: North TexASS
Posts: 18,538
Quote:
Originally Posted by Oracle View Post
If you offer a forum with free speech there are responsibilities...
The feds will want to be able to access all your messages and what you send (even if using a 2nd account).

So, this is not a technical thing... its a "I leave you alone but cooperate" kind of deal..
The Pelican forums are definitely not "free speech", but are a censor at whim and will platform (not sure if you were saying it is a free speech forum, however).
Old 04-03-2019, 08:29 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #31 (permalink)
?
 
Join Date: Apr 2002
Posts: 30,621
Can't have yer "tits" transmitted over the Internet so the geeks can't see 'em....WAH !

What if it literally cost 7 figures to encrypt those pics?

I used to live this stuff too...on a rather large scale .

T-Rex
Old 04-04-2019, 02:53 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #32 (permalink)
?
 
Join Date: Apr 2002
Posts: 30,621
Quote:
Originally Posted by Crowbob View Post
I read this entire thread. It reminds me of statistics. I sat through an entire term of statistics in college and didn’t understand any of it.
Computer Science, Advanced Communications, and Quantitatitive Analysis are easy peasy if yer gifted in those arenas...

I have to mow my own lawn though

Last edited by KFC911; 04-04-2019 at 03:01 AM..
Old 04-04-2019, 02:58 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #33 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 7,008
Sorry they do have one, it just not implemented correctly ( I would suspect to let the adds in)

__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 11-26-2019, 02:05 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #34 (permalink)
Still here
 
pmax's Avatar
 
Join Date: May 2014
Location: SF Bay Area
Posts: 18,099
Garage
Quote:
Originally Posted by stomachmonkey View Post
Meh, as long as one is not using the same user/pass as they use for say, their bank....

Which by the way, happy to see you don't.

Yes, I checked.
There have been cases where someone's ID was stolen and used in a for sale scam here.
Old 11-26-2019, 03:30 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #35 (permalink)
You do not have permissi
 
john70t's Avatar
 
Join Date: Aug 2001
Location: midwest
Posts: 40,041
The "already pinged" list of spam seems to have disappeared.

As noted, "secure" should only required for some functions.
Maybe it's easier to code the whole site that way?

Https removes any anonymity for visitors not using proxies.
As does the new Pelican PARF loggin requirement and Google javascript required for private messages.
More tracking.
Old 11-26-2019, 04:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #36 (permalink)
Registered
 
Oracle's Avatar
 
Join Date: Jun 2003
Location: Calgary Alberta, CANADA
Posts: 2,113
its a cross reference thing.. if the site is secure its harder to connect to unsecure sources of advertisements.. Also allows for xsite scripting injection, so more adevertisements and things like cookies can be injected and later harvested by other sites..

This is a technical choice.

Profits over everything else. Lets not forget we are the product here
__________________
We're all in the gutter,but some of us are looking at the stars.
-Oscar Wilde
Old 11-26-2019, 05:02 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #37 (permalink)
Registered
 
930addict's Avatar
 
Join Date: Jan 2005
Posts: 902
Garage
The forum should also use https as the certificate not only serves to encrypt the connection between the browser and the server, it also validates that you are connecting to the legitimate pelican forum server. In its current configuration it would be rather trivial to bring up another server and mascarade as forums.pelicanparts.com, conduct a DNS poisoning attack to redirect everyone to the imposter server and capture everyone's logins. The fact this is not their e-commerce site should not preclude them from protecting the forum servers. Attackers may be able to find their way into more sensitive areas of their operation. Remember the Target credit card breach? The attackers exploited a weakness in the HVAC systems and found their way to the credit card machines.

The go daddy cert issued to pelican parts e-commerce site can only be used on www.pelicanparts.com and pelicanparts.com. Pelican parts would need to either get another cert for forums.pelicanparts.com or update their current cert to a SAN cert that could be used for Loading, pelicanparts.com and forums.pelicanparts.com. I would opt for a separate cert so if one is compromised (say the forum cert) it doesn't affect the other (cert used for e-commerce site).

Looking at the go daddy pricing for certs, a single domain is only $63.99 per year, a san cert is $159.99 per year and a wildcard cert which can be used on *.pelicanparts.com $295 per year. Cheap insurance IMHO.
Old 11-26-2019, 08:25 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #38 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by pmax View Post
There have been cases where someone's ID was stolen and used in a for sale scam here.
Again, meh.

Far far far more likely the person hacked used an obvious easy to guess password than it was sniffed.

I use a random pass generator along with a pass manager and two factor on every site that I can. I have accounts that I don’t even know the password for.

We can rely on others for our security or take matters into our own hands.

Obviously, I’m an advocate for the later.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 11-26-2019, 09:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #39 (permalink)
Burn the fire.
 
Brando's Avatar
 
Join Date: May 2003
Location: Land of Liberty, NH
Posts: 6,501
Garage
Just install the browser plugin "HTTPS Everywhere". Problem solved.

__________________
[x] Working | [_] Broken: 2017 Victory Octane
[x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi

"Drive it like you stole it."
Old 11-27-2019, 03:26 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #40 (permalink)
Reply


 


All times are GMT -8. The time now is 08:06 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.