New OOTS products from CafePress
New OOTS t-shirts, ornaments, mugs, bags, and more
Results 1 to 5 of 5
  1. - Top - End - #1
    Bugbear in the Playground
     
    MonkGuy

    Join Date
    Jul 2005
    Location
    SW England
    Gender
    Male

    Default Insecure connection?

    I've just done a reset to factory settings on my laptop, and now when I try to log in to GITP, I get a "This connection is not secure" warning.

    Is there something up with the site, or have I not reconfigured my laptop properly?

  2. - Top - End - #2
    Troll in the Playground
     
    Flumph

    Join Date
    Nov 2006
    Location
    England. Ish.
    Gender
    Male

    Default Re: Insecure connection?

    Some browsers are now "enforcing" https connections rather than http for security purposes. You should be able to upate the browser settings to allow http (and the message usually gives some hint on how to do this).

    What probably happened was that your factory reset also took out that settings update.
    Warning: This posting may contain wit, wisdom, pathos, irony, satire, sarcasm and puns. And traces of nut.

    "The main skill of a good ruler seems to be not preventing the conflagrations but rather keeping them contained enough they rate more as campfires." Rogar Demonblud

    "Hold on just a d*** second. UK has spam callers that try to get you to buy conservatories?!? Even y'alls spammers are higher class than ours!" Peelee

  3. - Top - End - #3
    Bugbear in the Playground
     
    Alent's Avatar

    Join Date
    Sep 2013

    Default Re: Insecure connection?

    On this note, is there any plan to get a security cert for the site? The playground is one of the few places I visit that doesn't offer https:// these days, and while normally I don't think anything of it, I've been on the road and hesitant to log in to the forum from some of the open hotspots I've had to use. (Hurray for VPNs.)
    My Homebrew
    A Return to Exile, a homebrew campaign setting.
    Under Construction: Skills revamp for the Campaign Setting. I need to make a new index thread.



  4. - Top - End - #4
    Pixie in the Playground
    Join Date
    Jul 2009

    Default Re: Insecure connection?

    So apparently www.giantitp.com does support https (which is good) but uses a self-signed certificate (not so good). Basically this means that the connection between the server and a user is secure, but doesn't guarantee that the server is actually the real www.giantitp.com server. While it's not very likely that anyone would bother to perform a man-in-the-middle attack against this site, that's really no excuse to have such an obvious security hole, especially since Let's Encrypt is a free and widely used certificate authority.

  5. - Top - End - #5
    Dwarf in the Playground
     
    Drumbum42's Avatar

    Join Date
    Jul 2005
    Gender
    Male

    Default Re: Insecure connection?

    Quote Originally Posted by Random Poster View Post
    So apparently www.giantitp.com does support https (which is good) but uses a self-signed certificate (not so good). Basically this means that the connection between the server and a user is secure, but doesn't guarantee that the server is actually the real www.giantitp.com server. While it's not very likely that anyone would bother to perform a man-in-the-middle attack against this site, that's really no excuse to have such an obvious security hole, especially since Let's Encrypt is a free and widely used certificate authority.
    So, I was about to say that this may not be possible depending on their setup, but apparently certbot has a manual mode! Though it is a little time intensive, as you need to do this every 90 days. (A problem solved through automation if you have a VPS)

    I'm actually going to go use manual mode on a server this weekend. (Using selfsigned for a minor webpage)
    Proud 1st edtion player!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •