mersenneforum.org  

Go Back   mersenneforum.org > Other Stuff > Forum Feedback

Reply
 
Thread Tools
Old 2018-02-10, 21:10   #34
Nick
 
Nick's Avatar
 
Dec 2012
The Netherlands

2×23×37 Posts
Default

Quote:
Originally Posted by heliosh View Post
many people share the same login information (password) for different services.
That would be a very risky thing to do!
Quote:
Originally Posted by heliosh View Post
And since these information are transmitted plain-text, it can be a problem.
What makes you think this forum sends your password in plain text?
Have you looked?
Nick is online now   Reply With Quote
Old 2018-02-10, 21:16   #35
S485122
 
S485122's Avatar
 
Sep 2006
Brussels, Belgium

32268 Posts
Default

Quote:
Originally Posted by yoyo View Post
Any answer from the admins if HTTPS will be enabled or why not?
The forum is run by volunteers, https is more work...

Quote:
Originally Posted by heliosh View Post
...
It may not be a problem for forum content, but many people share the same login information (password) for different services. And since these information are transmitted plain-text, it can be a problem.
You mean that the forum administrators are responsible for the possible lack of security of some forums users ?

Jacob
S485122 is offline   Reply With Quote
Old 2018-02-10, 21:24   #36
yoyo
 
yoyo's Avatar
 
Oct 2006
Berlin, Germany

617 Posts
Default

I also run as volunteer some websites and know what https means from admin point of view.

I would like to get an answer from the admins.

If you have root access to the host it is easy to setup https based on letsencrypt.

yoyo

Last fiddled with by yoyo on 2018-02-10 at 21:24
yoyo is offline   Reply With Quote
Old 2018-02-10, 22:38   #37
heliosh
 
Oct 2017
++41

53 Posts
Default

Quote:
Originally Posted by Nick View Post
What makes you think this forum sends your password in plain text?
Well, the md5sum.

Quote:
Originally Posted by S485122 View Post
The forum is run by volunteers, https is more work...
Thanks to letsencrypt it took me less than 10 minutes to set up https for my webserver. That's very little effort.

Quote:
You mean that the forum administrators are responsible for the possible lack of security of some forums users ?
I haven't said that.
heliosh is offline   Reply With Quote
Old 2018-02-12, 22:05   #38
ewmayer
2ω=0
 
ewmayer's Avatar
 
Sep 2002
República de California

103·113 Posts
Default

My main concern re. https is this: I use an older version of FF due to the crapification of various key browser aspects, e.g. removal of easy user control over image loading post v22. I'm finding an increasing % os webpages unviewable due to crypto incompatibility, mostly I believe due to my version of FF only supporting TLS 1.0. So https ok in principle, but if we switch to it can we please make an effort to balance security and support for older browsers and OSes?
ewmayer is offline   Reply With Quote
Old 2018-02-12, 22:48   #39
CRGreathouse
 
CRGreathouse's Avatar
 
Aug 2006

3×1,993 Posts
Default

Quote:
Originally Posted by ewmayer View Post
I'm finding an increasing % os webpages unviewable due to crypto incompatibility, mostly I believe due to my version of FF only supporting TLS 1.0.
It's going to be everyone under PCI by June 30:
https://blog.pcisecuritystandards.or...-ssl-early-tls

Regardless of what mersenneforum does, you should seriously think about upgrading. It looks like FF 23 (2013) supported TLS 1.1, though you'll have to enable it.
CRGreathouse is offline   Reply With Quote
Old 2018-02-12, 23:57   #40
heliosh
 
Oct 2017
++41

53 Posts
Default

@ewmayer
You should be upgrading Firefox in any case, since older versions have many known security issues. Maybe you want to stick to the ESR version, which is an older release but still gets security updates.
heliosh is offline   Reply With Quote
Old 2018-02-13, 06:36   #41
S485122
 
S485122's Avatar
 
Sep 2006
Brussels, Belgium

2·3·281 Posts
Default

Just switch over to PaleMoon a FF 24 ESR fork that gets security upgrades.
Pale Moon on Wikipedia
www.palemoon.org

Jacob
S485122 is offline   Reply With Quote
Old 2018-02-13, 07:53   #42
yoyo
 
yoyo's Avatar
 
Oct 2006
Berlin, Germany

617 Posts
Default

It is is possible to support https and http in parallel.
yoyo is offline   Reply With Quote
Old 2018-02-13, 08:17   #43
retina
Undefined
 
retina's Avatar
 
"The unspeakable one"
Jun 2006
My evil lair

183416 Posts
Default

Quote:
Originally Posted by yoyo View Post
It is is possible to support https and http in parallel.
Yes. They are on different ports, so no problem.
retina is online now   Reply With Quote
Old 2018-02-14, 20:52   #44
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

37·263 Posts
Default

Quote:
Originally Posted by S485122 View Post
The forum is run by volunteers, https is more work...
Just to bump this thread...

Mersenne.org, Mersenne.ca and GPU72 are also run by volunteers. Yes, HTTPS takes a /little/ more work, but not really all that much. And nowadays it doesn't cost any more even on shared hosting, unless the hosting provider is still in the dark ages.

Lastly, except for Mersenne.ca, all (including, obviously, this forum) use access credentials which should be transmitted over a secure channel.
chalsall is offline   Reply With Quote
Reply



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why is https://www.mersenne.org so damn buggy? jxsl13 Information & Answers 2 2017-02-22 03:06
https and www etc etc Uncwilly Forum Feedback 1 2012-03-12 20:46
https access to www.mersenne.org failed LLL PrimeNet 17 2008-12-26 20:34

All times are UTC. The time now is 12:56.


Sat Jul 17 12:56:45 UTC 2021 up 50 days, 10:44, 1 user, load averages: 2.12, 1.90, 1.61

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.

This forum has received and complied with 0 (zero) government requests for information.

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.
A copy of the license is included in the FAQ.