Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Banned
 
speeder's Avatar
 
Join Date: Jul 2001
Location: los angeles, CA.
Posts: 41,306
Why is this site, "not secure"??

I've never noticed this before, in the address bar it says, "Not Secure--forums.pelicanparts.com

What the what?

Old 04-02-2019, 05:38 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
A930Rocket's Avatar
 
Join Date: Oct 2003
Location: Mount Pleasant, South Carolina
Posts: 14,298
I’ve asked that as well. I remember Erik at PP told us but don’t recall the answer.

Maybe it’s because it’s not worth paying for the security certificate or similar?
Old 04-02-2019, 05:41 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,364
It is delivered via plain HTTP and not SSL/TLS wrapped HTTP (aka HTTPS, the "green icon/lock")

So the only thing insecure about it is the traffic across the wire isn't encrypted between your browser and the forum servers.

You are just starting to see it now because the browser companies have finally started trying to get non-technical people to understand what they are doing, how they are doing it, and possibly who they are doing it with.

Since all you are sending/receiving is ending up in public anyway, no issues. You'll note if you log out and log back in that your login is processed via HTTPS. No issues here, just change in browser behavior.
Old 04-02-2019, 05:42 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
URY914's Avatar
 
Join Date: Aug 2001
Location: Jacksonville FL
Posts: 50,449
Garage
Russians.
__________________
Jacksonville. Florida

https://www.flickr.com/photos/ury914/
Old 04-02-2019, 05:45 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,335
When I click the warning, it says "parts of this page are not secure (like images)"
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 04-02-2019, 05:53 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
piscator's Avatar
 
Join Date: Jun 2009
Location: New England
Posts: 850
id10t, nice explanation!
__________________
Robert

-----------------------------------------
"A man must consider what a rich realm he abdicates when he becomes a conformist." ~ Ralph Waldo Emerson ~ (thanks to Pat Keefe)
Old 04-02-2019, 06:17 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Because it does not need to be.

Encryption slows things down and there is no sensitive data being passed here beyond what we already voluntarily reveal ourselves.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 04-02-2019, 06:17 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
Bill Douglas's Avatar
 
Join Date: Jun 2000
Location: bottom left corner of the world
Posts: 22,808
Quote:
Originally Posted by URY914 View Post
Russians.
Chinese
Old 04-02-2019, 06:19 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Burn the fire.
 
Brando's Avatar
 
Join Date: May 2003
Location: Land of Liberty, NH
Posts: 6,501
Garage
When this was brought up last year (and the year before that) some elements of the site are still served up on HTTP instead of HTTPS. The forums are behind the rest of the site because a lot of content (images and scripts) are still referencing HTTP.
__________________
[x] Working | [_] Broken: 2017 Victory Octane
[x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi

"Drive it like you stole it."
Old 04-02-2019, 06:44 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Banned but not out, yet..
 
RSBob's Avatar
 
Join Date: Jan 2003
Location: "Apple Maggot Quarantine Area', WA.
Posts: 6,422
Garage
Quote:
Originally Posted by Bill Douglas View Post
Chinese
Iranians

__________________
An air cooled refrigerator. ‘Mein Teil’
Old 04-02-2019, 07:49 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
?
 
Join Date: Apr 2002
Posts: 30,602
Quote:
Originally Posted by stomachmonkey View Post
Because it does not need to be.

....
^^^ This....and encryption/decryption is NOT free in terms of overhead costs and performance.
Old 04-03-2019, 01:07 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,199
Garage
Da Russians..

No SSL certificate for the page. No e-commerce done, no real need for a SSL... but google and others have been driving this nonsense and if you don't have the SSL, you get the scary red triangle. I had to purchase the SSL because browsers weren't allowing customers to get to my website or the customer was too worried about "not secure". I don't take any payments through my website... but have to have the stupid SSL if I don't want customers being freaked out and thinking I'm a scammer.
__________________
Nick

Last edited by cabmandone; 04-03-2019 at 02:19 AM..
Old 04-03-2019, 02:16 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
For those of you who think you may need SSL look at Let’s Encrypt, https://letsencrypt.org

Free and works.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 04-03-2019, 03:45 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,364
Quote:
Originally Posted by stomachmonkey View Post
For those of you who think you may need SSL look at Let’s Encrypt, https://letsencrypt.org

Free and works.
Free, works, and works well. Also works for doing SMTP w/ SSL/TLS and wrapping both POP3 and IMAP in SSL.

"Only" down side is short certificate life but if you have the skills to be messing around setting up web/mail servers and needing SSL you should be able to set up a cron job to keep your certificate valid.
Old 04-03-2019, 03:55 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Registered
 
Join Date: Feb 2000
Location: Dallas, TX
Posts: 4,612
Quote:
Originally Posted by URY914 View Post
Russians.
Everyone knows it is a fat kid in his mom's basement.
__________________
Neil
'73 911S targa
Old 04-03-2019, 04:22 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Brew Master
 
cabmandone's Avatar
 
Join Date: Jul 2013
Location: Delphos OH
Posts: 32,199
Garage
Quote:
Originally Posted by stomachmonkey View Post
For those of you who think you may need SSL look at Let’s Encrypt, https://letsencrypt.org

Free and works.
Where were you a month ago!?
__________________
Nick
Old 04-03-2019, 04:32 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Super Moderator
 
cstreit's Avatar
 
Join Date: Feb 2000
Location: Naperville, IL USA
Posts: 14,971
Garage
Even though the content is delivered as https (secure), images are displayed insecurely so the site is flagged.

If even one element of a page is unencrypted, browsers flag it as "not secure".

Not a big deal for a forum. HUGE deal for ecom sites. Its misleading by the browser companies to make such a big issue of this IMO, but Google led the way with "secure everything" by de-ranking sites that weren't all secure.

We saw that wind coming a few years ago and just delivered all content that way.
__________________
Chris
----------------------------------------------

1996 993 RS Replica
2023 KTM 890 Adventure R
1971 Norton 750 Commando
Alcon Brake Kits
Old 04-03-2019, 04:53 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,364
Quote:
Originally Posted by cstreit View Post
Even though the content is delivered as https (secure), images are displayed insecurely so the site is flagged.

If even one element of a page is unencrypted, browsers flag it as "not secure".

Not a big deal for a forum. HUGE deal for ecom sites. Its misleading by the browser companies to make such a big issue of this IMO, but Google led the way with "secure everything" by de-ranking sites that weren't all secure.

We saw that wind coming a few years ago and just delivered all content that way.
Yup, and the issue you see with the mixed content is from here where people have posted images on other web servers, etc.
Old 04-03-2019, 05:12 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 85,262
Garage
Quote:
Originally Posted by stomachmonkey View Post
Because it does not need to be.

Encryption slows things down and there is no sensitive data being passed here beyond what we already voluntarily reveal ourselves.
This. Totally public content, no need to encrypt. If you go to the parts catalog, and place an order, you will see the site turn into a secure site. That is when security is vital.
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 04-03-2019, 05:21 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Super Moderator
 
cstreit's Avatar
 
Join Date: Feb 2000
Location: Naperville, IL USA
Posts: 14,971
Garage
Quote:
Originally Posted by GH85Carrera View Post
This. Totally public content, no need to encrypt. If you go to the parts catalog, and place an order, you will see the site turn into a secure site. That is when security is vital.
This is whats so frustrating about Google's decision and that of the browser companies following suit.

It scares the uninformed user. THere is simply no need to encrypt static boring content, but the "warning" implies that there is something nefarious going on.

__________________
Chris
----------------------------------------------

1996 993 RS Replica
2023 KTM 890 Adventure R
1971 Norton 750 Commando
Alcon Brake Kits
Old 04-03-2019, 05:38 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 05:21 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.