mersenneforum.org  

Go Back   mersenneforum.org > Great Internet Mersenne Prime Search > PrimeNet > GPU to 72

Reply
Thread Tools
Old 2012-10-22, 02:19   #1552
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

262716 Posts
Default

Quote:
Originally Posted by swl551 View Post
Why leave port 80 taking traffic when you have an SSL site??
Please give us an example of a site that doesn't leave port 80 open which offers a certified port 443?

Bonus question: please provide us with an example of a site you provide which only offers port 443.
chalsall is offline   Reply With Quote
Old 2012-10-22, 04:10   #1553
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

100110001001112 Posts
Default

Quote:
Originally Posted by chalsall View Post
Bonus question: please provide us with an example of a site you provide which only offers port 443.
Still waiting grasshopper...

Take your time.
chalsall is offline   Reply With Quote
Old 2012-10-22, 04:16   #1554
axn
 
axn's Avatar
 
Jun 2003

13DA16 Posts
Default

Quote:
Originally Posted by chalsall View Post
Please give us an example of a site that doesn't leave port 80 open which offers a certified port 443?
Banking sites? Sure, there might be a landing page on port 80, but after logging in, it is SSL all the way, baby
axn is online now   Reply With Quote
Old 2012-10-22, 08:18   #1555
Bdot
 
Bdot's Avatar
 
Nov 2010
Germany

3·199 Posts
Default

Quote:
Originally Posted by chalsall View Post
Since https://www.gpu72.com/ has worked for months, you might reasonably assume I know that.
I did not notice that before and will happily switch to SSL now ...

I really don't know: will automatic switching (forwarding) to SSL break anything? If so, then maybe an "SSL version" link or something like that could point interested users to this possibility.
Bdot is offline   Reply With Quote
Old 2012-10-22, 11:55   #1556
swl551
 
swl551's Avatar
 
Aug 2012
New Hampshire

23·101 Posts
Default sites with no port 80 open.

Quote:
Originally Posted by chalsall View Post
Still waiting grasshopper...

Take your time.
Master,

While I won't divulge the sites I run on a public forum I'd be happy to show you my CISCO ASA rules showing outside to inside traffic being restricted to just 443 for my WEB servers.

You can also have a firewall redirect a port 80 call to 443.
IIS has the same feature if you prefer to handle it at the web server level. (I put money on apache having a redirect option)

Additionally on your server your port 80 based site can have a page redirect to your 443 site or your port 80 site's page can say "sorry not allowed please visit... %some url% with an href.

In the case of the product infrastructures I manage, port 80 is not allowed to be open. We'd pass our security scan audit if were.

There are a lot of ways to ensure people use only your 443 site.

-Grasshopper---
swl551 is offline   Reply With Quote
Old 2012-10-22, 12:03   #1557
swl551
 
swl551's Avatar
 
Aug 2012
New Hampshire

23×101 Posts
Default

Quote:
Originally Posted by swl551 View Post
I put money on apache having a redirect option
http://wiki.apache.org/httpd/RedirectSSL
swl551 is offline   Reply With Quote
Old 2012-10-22, 13:14   #1558
swl551
 
swl551's Avatar
 
Aug 2012
New Hampshire

32816 Posts
Default I want my bonus!

Quote:
Originally Posted by chalsall View Post
Please give us an example of a site that doesn't leave port 80 open which offers a certified port 443?

Bonus question: please provide us with an example of a site you provide which only offers port 443.
Let's just say that web site security is one of the things that I get paid to ensure...
Attached Thumbnails
Click image for larger version

Name:	Capture.JPG
Views:	121
Size:	143.6 KB
ID:	8770  
swl551 is offline   Reply With Quote
Old 2012-10-22, 16:27   #1559
garo
 
garo's Avatar
 
Aug 2002
Termonfeckin, IE

53148 Posts
Default

Quote:
Originally Posted by LaurV View Post
indeed, firefox is good in remembering all my passwords, better then me. And because I access different sites at work and home, sometime I need to synchronize those passwords, and I use a screen capture (png) from that firefox menu, which I am sending from home to work or viceversa, in a compressed/encrypted form (zip or rar with password)
Try xmarks or LastPass. Latter is paid but the former (part of the same company now) has been providing me with password/bookmark/open tab synchronization since 2008.
garo is offline   Reply With Quote
Old 2012-10-23, 18:56   #1560
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

9,767 Posts
Default

Quote:
Originally Posted by swl551 View Post
Let's just say that web site security is one of the things that I get paid to ensure...
Really?

But you don't appear to understand how web site security works.

Using only port 443 does not guarantee that a site is secure.
chalsall is offline   Reply With Quote
Old 2012-10-23, 23:49   #1561
swl551
 
swl551's Avatar
 
Aug 2012
New Hampshire

23×101 Posts
Default Right. Only you know everything.

Quote:
Originally Posted by chalsall View Post
Really?

But you don't appear to understand how web site security works.

Using only port 443 does not guarantee that a site is secure.
You want to pick at nitty b.s. knowing full well it was assumed 443 was used as the default port for an SSL certificate. I'm tired of your better than EVERYONE else attitude and your hair brained ideas on how things should work. You think you know it all.. You don't I could school you for days, but I'd fire you first for being too rude!

How about I not answer any of your threads anymore and YOU don't answer mine.

What's really sad is someone gave you permissions to run these forums. I guess they didn't realize you were going to be an ego maniac.

Last fiddled with by swl551 on 2012-10-24 at 00:06
swl551 is offline   Reply With Quote
Old 2012-10-24, 00:19   #1562
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

9,767 Posts
Default

Quote:
Originally Posted by swl551 View Post
You want to pick at nitty b.s. knowing full well it was assumed 443 was used as the default port for an SSL certificate. I'm tired of your better than EVERYONE else attitude and your hair brained ideas on how things should work. You think you know it all.. You don't I could school you for days, but I'd fire you first for being too rude!

How about I not answer any of your threads anymore and YOU don't answer mine.

What's really sad is someone gave you permissions to run these forums. I guess they didn't realize you were going to be an ego maniac.
What you said was wrong.

Using port 443 (HTTPS) does not guarantee security.

I'm sorry if you don't like that.
chalsall is offline   Reply With Quote
Reply



Similar Threads
Thread Thread Starter Forum Replies Last Post
Status Primeinator Operation Billion Digits 5 2011-12-06 02:35
62 bit status 1997rj7 Lone Mersenne Hunters 27 2008-09-29 13:52
OBD Status Uncwilly Operation Billion Digits 22 2005-10-25 14:05
1-2M LLR status paulunderwood 3*2^n-1 Search 2 2005-03-13 17:03
Status of 26.0M - 26.5M 1997rj7 Lone Mersenne Hunters 25 2004-06-18 16:46

All times are UTC. The time now is 10:11.


Mon Aug 2 10:11:55 UTC 2021 up 10 days, 4:40, 0 users, load averages: 0.87, 1.17, 1.24

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.

This forum has received and complied with 0 (zero) government requests for information.

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.
A copy of the license is included in the FAQ.