mersenneforum.org  

Go Back   mersenneforum.org > Other Stuff > Forum Feedback

Reply
 
Thread Tools
Old 2018-09-03, 20:59   #78
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

37×263 Posts
Default MersenneForum.org needs to get off its ass with regard to TLS...

Hey all.

I'm not quite sure why this happened, but I had to re-authenticate here at MersenneForum.org.

Extremely weirdly, MF doesn't use TLS; it uses Plain Text. So I had to give credentials not encrypted (of course they were "throw-away").

Mike: I respect that you're not terribly strong with the nuances of cyber-security. But you're leaving people exposed because you don't ask for assistance.

MF should be served over a secure channel. Not doing so is a profound embarrassment.

Last fiddled with by chalsall on 2018-09-03 at 21:00 Reason: Something so subtle you wouldn't understand....
chalsall is offline   Reply With Quote
Old 2018-09-03, 21:36   #79
retina
Undefined
 
retina's Avatar
 
"The unspeakable one"
Jun 2006
My evil lair

11000001101002 Posts
Default

IIUC it would cost more each month to enable TLS support in the server.
retina is online now   Reply With Quote
Old 2018-09-03, 22:23   #80
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

37×263 Posts
Default

Quote:
Originally Posted by retina View Post
IIUC it would cost more each month to enable TLS support in the server.
Many expletives deleted!

Mike takes donations to run the Mersenne Forum.

It doesn't take that much to run a TLS site. Every other site associated with the GIMPS project is now running over a secure channel.

Many expletives deleted!

Last fiddled with by chalsall on 2018-09-03 at 22:29 Reason: s/an T/a T/; # if you don't edit in regex, you're not pedantic enough.
chalsall is offline   Reply With Quote
Old 2018-09-03, 23:54   #81
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

37×263 Posts
Default

OK. Like it or hate it, anything web based not served over https connections which takes passwords is now considered untrustworthy.

Mike (our sysadmin): a sincere question: why are you resisting this?

Is it because you don't know how, or because it costs money?

Either way we (the communal we) can help.
chalsall is offline   Reply With Quote
Old 2018-09-04, 03:39   #82
Uncwilly
6809 > 6502
 
Uncwilly's Avatar
 
"""""""""""""""""""
Aug 2003
101×103 Posts

9,787 Posts
Default

Posts 78 through this one were merged from another thread. The subject matter is the same.
Uncwilly is offline   Reply With Quote
Old 2018-09-04, 03:41   #83
Uncwilly
6809 > 6502
 
Uncwilly's Avatar
 
"""""""""""""""""""
Aug 2003
101×103 Posts

978710 Posts
Default

I think that it might be the time to make the move to HTTPS. If we do it now, then if the wiki comes back it can be HTTPS as well. I will gladly add 2 Euros to my monthly dues.
Uncwilly is offline   Reply With Quote
Old 2018-09-04, 10:39   #84
VictordeHolland
 
VictordeHolland's Avatar
 
"Victor de Hollander"
Aug 2011
the Netherlands

23×3×72 Posts
Default

Quote:
Originally Posted by Uncwilly View Post
I will gladly add 2 Euros to my monthly dues.
Same here
VictordeHolland is offline   Reply With Quote
Old 2018-09-04, 13:58   #85
Uncwilly
6809 > 6502
 
Uncwilly's Avatar
 
"""""""""""""""""""
Aug 2003
101×103 Posts

9,787 Posts
Default

Quote:
Originally Posted by chalsall View Post
I'm not quite sure why this happened, but I had to re-authenticate here at MersenneForum.org.

Extremely weirdly, MF doesn't use TLS; it uses Plain Text. So I had to give credentials not encrypted (of course they were "throw-away").
Looks like you got your wish.

Last fiddled with by Uncwilly on 2018-09-04 at 13:58
Uncwilly is offline   Reply With Quote
Old 2018-09-04, 14:12   #86
Xyzzy
 
Xyzzy's Avatar
 
"Mike"
Aug 2002

100000001000002 Posts
Default

The SSL certificate was free.

Setting everything up was a big gamble.

Despite our best efforts to brick the forum, it all worked out in the end.

https://www.gnu.org/fun/jokes/error-haiku.html

Attached Thumbnails
Click image for larger version

Name:	SSL.PNG
Views:	78
Size:	38.2 KB
ID:	19030  
Xyzzy is offline   Reply With Quote
Old 2018-09-04, 14:46   #87
ET_
Banned
 
ET_'s Avatar
 
"Luigi"
Aug 2002
Team Italia

32·5·107 Posts
Default

Quote:
Originally Posted by Xyzzy View Post
The SSL certificate was free.

Setting everything up was a big gamble.

Despite our best efforts to brick the forum, it all worked out in the end.

https://www.gnu.org/fun/jokes/error-haiku.html

You forgot to re-enable the donation link...
ET_ is offline   Reply With Quote
Old 2018-09-04, 17:07   #88
VictordeHolland
 
VictordeHolland's Avatar
 
"Victor de Hollander"
Aug 2011
the Netherlands

23×3×72 Posts
Default

Nice Job!
VictordeHolland is offline   Reply With Quote
Reply



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why is https://www.mersenne.org so damn buggy? jxsl13 Information & Answers 2 2017-02-22 03:06
https and www etc etc Uncwilly Forum Feedback 1 2012-03-12 20:46
https access to www.mersenne.org failed LLL PrimeNet 17 2008-12-26 20:34

All times are UTC. The time now is 12:47.


Sat Jul 17 12:47:18 UTC 2021 up 50 days, 10:34, 1 user, load averages: 1.51, 1.46, 1.37

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.

This forum has received and complied with 0 (zero) government requests for information.

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.
A copy of the license is included in the FAQ.