Page 1 of 1
Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Fri Apr 28, 2017 7:26 pm
by thinkpadcollection
Most of web sites of all kinds have converted to HTTPS for safety and security reason. Why not here?
Cheers, thinkpadcollection
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sat Apr 29, 2017 9:31 am
by dr_st
What are the risks that require this kind of mitigation?
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sat Apr 29, 2017 10:17 am
by RealBlackStuff
If you are that concerned, use an add-on like:
HTTPS Everywhere
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sat Apr 29, 2017 12:39 pm
by axur-delmeria
dr_st wrote:What are the risks that require this kind of mitigation?
Normal HTTP login means username and password are transmitted in plaintext (not encrypted), which makes it trivially easy to steal.
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sat Apr 29, 2017 1:22 pm
by dr_st
axur-delmeria wrote:dr_st wrote:What are the risks that require this kind of mitigation?
Normal HTTP login means username and password are transmitted in plaintext (not encrypted), which makes it trivially easy to steal.
Thought as much.
I don't use the same password for forums as I do for anything personal/important, for that reason among others.
Isn't there something in the login process itself that makes it transmit only the hash, or something like that? Otherwise you'd think that millions of passwords would be stolen by trivial means in the years before most moved to https.
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sun Apr 30, 2017 7:25 pm
by thinkpadcollection
I thought made this clear, once you go to this forum, it is already in HTTPS website mode means secure website even you are not logged in yet, and therefore login is secure enough already as well. My browser always flag this as insecure every time I log in and the little padlock in front of website address is red cross.
Majority of the websites I visit have implemented HTTPS.
Cheers, thinkpadcollection
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Sun Apr 30, 2017 8:20 pm
by MisterB
After reading this, I tried https on the site and got a browser warning.
This site has https via a lets encrypt certificate but it is not functioning fully. I recently dealt with a similar problem in a couple of sites of mine that had images and other content being transmitted by http which gets a browser flag these days. Fixing it in one, a Wordpress site, was done by installing a plugin that forced all content to https. The other had an Oscommerce store that just needed a couple of tweaks to the config file. This site needs some tweaking of the https but what needs to be done depends on the software used. It probably won't be that difficult and at worst will take the site offline a short while for maintenance. In my case, it didn't even require any downtime.
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Mon May 01, 2017 9:24 am
by RealBlackStuff
The Forum website has now been converted to HTTPS:// thanks to our in-house technician Joe.
This may cause some (or all?) of you to have been logged out.
Before you log in again, you should delete all your forum.thinkpads.com cookies.
For a HOW-TO, see this: https://www.howtogeek.com/111925/delete ... n-windows/
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Mon May 01, 2017 11:00 am
by Omineca
The https upgrade may have broken Tapatalk compatibility. I can't log in anymore via the app.
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Mon May 01, 2017 11:15 am
by RealBlackStuff
I don't have a smartphone, but you may need to change your own phone's Tapatalk link to the Forum, to reflect https://
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Mon May 01, 2017 6:24 pm
by thinkpadcollection
Confirmed that https is now working here.
Cheers, thinkpadcollection
Re: RE: Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Mon May 01, 2017 7:43 pm
by Omineca
RealBlackStuff wrote:I don't have a smartphone, but you may need to change your own phone's Tapatalk link to the Forum, to reflect https://
Thanks. I don't think that's a change that users can make, but the app has started to work again in any case.
Sent from my Passport using Tapatalk
Re: Prudent to convert this forum to HTTPS for login and rest of forum.
Posted: Tue May 02, 2017 8:22 am
by MisterB
Https working. No more browser flags. I did have to login again which is normal for changing from http to https.