forums
new posts
donate
events
location db
db map
search
members
faq
terms of service
privacy policy
register
login




UER Forum > UE Website Updates > How's that SSL coming, Av? (Viewed 941 times)
Crypton 


Location: Pacific Northwest
Gender: Male
Total Likes: 128 likes


NullReferenceExc eption

 |  |  | 
How's that SSL coming, Av?
< on 3/21/2017 5:03 PM >
Reply with Quote
Posted on Forum: UER Forum
As many of you have noticed, UER is served over plain-old, unencrypted HTTP. Over the past few years there has been a trend to push SSL to many popular sites (and most can admit this is a popular site).

Unfortunately, UER still seems behind the times, especially considering that Let's Encrypt provides free certificates to enable this capability not to mention plethora of community scripts for most major web servers (e.g. IIS on which this site is hosted).

Furthermore, many browsers now display a warning for non-SSL logins (as in the case of UER).

And to end on a hilarious note, just this week: https://arstechnic...gin-page-insecure/


"Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International, is not wanted and was put there without our permission," a person with the user name dgeorge wrote here (the link was made private shortly after this post went live). "Please remove it immediately. We have our own security system, and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business."



[last edit 3/21/2017 5:04 PM by Crypton - edited 1 times]

https://www.flickr...hotos/kernel32dll/
Deuterium 


Location: PNW
Gender: Male
Total Likes: 178 likes




 |  | 
Re: How's that SSL coming, Av?
< Reply # 1 on 3/26/2017 12:52 AM >
Reply with Quote
Posted on Forum: UER Forum
But until then, hopefully nobody here is stupid enough to use a password for this site that is shared with anything of importance. Is it possible that a bunch of several year old accounts with no posts that are suddenly applying for FM are farmed accounts?




Mickael 

Moderator


Location: Canada
Gender: Male
Total Likes: 83 likes




 |  | 
Re: How's that SSL coming, Av?
< Reply # 2 on 3/26/2017 1:35 AM >
Reply with Quote
Posted on Forum: UER Forum
UER has been running SSL for a while and is accessible at https://www.uer.ca

But I do agree that all HTTP trafic should be redirected to HTTPS by default.

Meanwhile, you can use HTTPS Everywhere and create a rule for UER, so you never have to browse the unsecured site by accident.



[last edit 3/26/2017 1:40 AM by Mickael - edited 1 times]

Need forum-related help / Besoin d'aide reliée au forum ? Contact a moderator
Crypton 


Location: Pacific Northwest
Gender: Male
Total Likes: 128 likes


NullReferenceExc eption

 |  |  | 
Re: How's that SSL coming, Av?
< Reply # 3 on 3/29/2017 7:42 PM >
Reply with Quote
Posted on Forum: UER Forum
Posted by Mickael
UER has been running SSL for a while and is accessible at https://www.uer.ca

But I do agree that all HTTP trafic should be redirected to HTTPS by default.

Meanwhile, you can use HTTPS Everywhere and create a rule for UER, so you never have to browse the unsecured site by accident.


Worth it. I do have HTTPS Everywhere setup. Microsoft also provides an offical plugin for IIS to automatically redirect all requests to https.




https://www.flickr...hotos/kernel32dll/
Avatar-X 

Alpha Husky


Location: Toronto, Ontario, Canada
Gender: Male
Total Likes: 477 likes


yay!

 |  |  | AvBrand
Re: How's that SSL coming, Av?
< Reply # 4 on 6/5/2017 9:23 AM >
Reply with Quote
Posted on Forum: UER Forum
UER has had SSL available with a self-signed cert for years, and with a proper cert for a year and a half now.

People can use SSL if they choose to.

I don't use Let's Encrypt because it requires the certificate to be renewed every 3 months and I just don't have that kind of time. It also doesn't work with my firewall.

-av



[last edit 6/5/2017 9:25 AM by Avatar-X - edited 1 times]

huskies - such fluff.
UER Forum > UE Website Updates > How's that SSL coming, Av? (Viewed 941 times)


Add a poll to this thread



This thread is in a public category, and can't be made private.



All content and images copyright 2002-2017 UER.CA and respective creators. Graphical Design by Crossfire.
To contact webmaster, or click to email with problems or other questions about this site: UER CONTACT
View Terms of Service | View Privacy Policy | Server colocation provided by Beanfield
This page was generated for you in 93 milliseconds. Since June 23, 2002, a total of 525079488 pages have been generated.