![]() |
Why is this site, "not secure"??
I've never noticed this before, in the address bar it says, "Not Secure--forums.pelicanparts.com
What the what? :confused: |
I’ve asked that as well. I remember Erik at PP told us but don’t recall the answer.
Maybe it’s because it’s not worth paying for the security certificate or similar? |
It is delivered via plain HTTP and not SSL/TLS wrapped HTTP (aka HTTPS, the "green icon/lock")
So the only thing insecure about it is the traffic across the wire isn't encrypted between your browser and the forum servers. You are just starting to see it now because the browser companies have finally started trying to get non-technical people to understand what they are doing, how they are doing it, and possibly who they are doing it with. Since all you are sending/receiving is ending up in public anyway, no issues. You'll note if you log out and log back in that your login is processed via HTTPS. No issues here, just change in browser behavior. |
Russians. ;)
|
When I click the warning, it says "parts of this page are not secure (like images)"
|
id10t, nice explanation!
|
Because it does not need to be.
Encryption slows things down and there is no sensitive data being passed here beyond what we already voluntarily reveal ourselves. |
Quote:
|
When this was brought up last year (and the year before that) some elements of the site are still served up on HTTP instead of HTTPS. The forums are behind the rest of the site because a lot of content (images and scripts) are still referencing HTTP.
|
Quote:
http://forums.pelicanparts.com/support/smileys/blah.gifhttp://forums.pelicanparts.com/support/smileys/blah.gif |
Quote:
|
Da Russians..
No SSL certificate for the page. No e-commerce done, no real need for a SSL... but google and others have been driving this nonsense and if you don't have the SSL, you get the scary red triangle. I had to purchase the SSL because browsers weren't allowing customers to get to my website or the customer was too worried about "not secure". I don't take any payments through my website... but have to have the stupid SSL if I don't want customers being freaked out and thinking I'm a scammer. |
For those of you who think you may need SSL look at Let’s Encrypt, https://letsencrypt.org
Free and works. |
Quote:
"Only" down side is short certificate life but if you have the skills to be messing around setting up web/mail servers and needing SSL you should be able to set up a cron job to keep your certificate valid. |
Quote:
|
Quote:
|
Even though the content is delivered as https (secure), images are displayed insecurely so the site is flagged.
If even one element of a page is unencrypted, browsers flag it as "not secure". Not a big deal for a forum. HUGE deal for ecom sites. Its misleading by the browser companies to make such a big issue of this IMO, but Google led the way with "secure everything" by de-ranking sites that weren't all secure. We saw that wind coming a few years ago and just delivered all content that way. |
Quote:
|
Quote:
|
Quote:
It scares the uninformed user. THere is simply no need to encrypt static boring content, but the "warning" implies that there is something nefarious going on. |
| All times are GMT -8. The time now is 06:18 AM. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website