Infiltration
THEORY
Ethics
Observations
 
PRACTICE
Abandoned Sites
Boats
Churches
Drains/Catacombs
Hotels/Hospitals
Transit Tunnels
Utility Tunnels
Various
 
RESOURCES
Exploration Timeline
Infilnews
Infilspeak Dictionary
Usufruct Blog
Worldwide Links
Infiltration Forums home | search | login | register

Reply
Infiltration Forums > UE Website Updates > How's that SSL coming, Av?(Viewed 7063 times)
Crypton   |  | 
How's that SSL coming, Av?
< on 3/21/2017 5:03 PM >
Posted on Forum: UER ForumQuote
As many of you have noticed, UER is served over plain-old, unencrypted HTTP. Over the past few years there has been a trend to push SSL to many popular sites (and most can admit this is a popular site).

Unfortunately, UER still seems behind the times, especially considering that Let's Encrypt provides free certificates to enable this capability not to mention plethora of community scripts for most major web servers (e.g. IIS on which this site is hosted).

Furthermore, many browsers now display a warning for non-SSL logins (as in the case of UER).

And to end on a hilarious note, just this week: https://arstechnic...gin-page-insecure/


"Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International, is not wanted and was put there without our permission," a person with the user name dgeorge wrote here (the link was made private shortly after this post went live). "Please remove it immediately. We have our own security system, and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business."



[last edit 3/21/2017 5:04 PM by Crypton - edited 1 times]

Deuterium location:
PNW
 
 |  | 
Re: How's that SSL coming, Av?
<Reply # 1 on 3/26/2017 12:52 AM >
Posted on Forum: UER ForumQuote
But until then, hopefully nobody here is stupid enough to use a password for this site that is shared with anything of importance. Is it possible that a bunch of several year old accounts with no posts that are suddenly applying for FM are farmed accounts?



Mickael
Moderator
 
location:
Canada
 
 |  | 
Re: How's that SSL coming, Av?
<Reply # 2 on 3/26/2017 1:35 AM >
Posted on Forum: UER ForumQuote
UER has been running SSL for a while and is accessible at https://www.uer.ca

But I do agree that all HTTP trafic should be redirected to HTTPS by default.

Meanwhile, you can use HTTPS Everywhere and create a rule for UER, so you never have to browse the unsecured site by accident.


[last edit 3/26/2017 1:40 AM by Mickael - edited 1 times]

Need forum-related help / Besoin d'aide reliée au forum ? Contact a moderator
Crypton   |  | 
Re: How's that SSL coming, Av?
<Reply # 3 on 3/29/2017 7:42 PM >
Posted on Forum: UER ForumQuote
Posted by Mickael
UER has been running SSL for a while and is accessible at https://www.uer.ca

But I do agree that all HTTP trafic should be redirected to HTTPS by default.

Meanwhile, you can use HTTPS Everywhere and create a rule for UER, so you never have to browse the unsecured site by accident.


Worth it. I do have HTTPS Everywhere setup. Microsoft also provides an offical plugin for IIS to automatically redirect all requests to https.



Avatar-X
Alpha Husky
 
location:
West Coast
 
 |  |  | AvBrand
Re: How's that SSL coming, Av?
<Reply # 4 on 6/5/2017 9:23 AM >
Posted on Forum: UER ForumQuote
UER has had SSL available with a self-signed cert for years, and with a proper cert for a year and a half now.

People can use SSL if they choose to.

I don't use Let's Encrypt because it requires the certificate to be renewed every 3 months and I just don't have that kind of time. It also doesn't work with my firewall.

-av


[last edit 6/5/2017 9:25 AM by Avatar-X - edited 1 times]

huskies - such fluff.
Infiltration Forums > UE Website Updates > How's that SSL coming, Av?(Viewed 7063 times)
Reply

Add a poll to this thread



This thread is in a public category, and can't be made private.

Powered by AvBoard AvBoard version 1.5 alpha
Page Generated In: 31 ms