#1  
Old 23-11-2018, 10:07 AM
doug mc's Avatar
doug mc
Registered User

doug mc is offline
 
Join Date: Feb 2007
Location: Mt Tamborine
Posts: 619
Security warnings

Why do I get security warnings on this site?
Reply With Quote
  #2  
Old 23-11-2018, 10:17 AM
Zuts
Registered User

Zuts is offline
 
Join Date: Mar 2007
Location: sydney
Posts: 1,837
Quote:
Originally Posted by doug mc View Post
Why do I get security warnings on this site?
see this thread

http://www.iceinspace.com.au/forum/s...d.php?t=171189
Reply With Quote
  #3  
Old 23-11-2018, 06:31 PM
brian nordstrom (As avatar)
Registered User

brian nordstrom is offline
 
Join Date: Apr 2007
Location: Perth WA
Posts: 4,374
Seems sloppy and lazy ! , when you read the linked thread .

Brian
Reply With Quote
  #4  
Old 23-11-2018, 06:58 PM
Merlin66's Avatar
Merlin66 (Ken)
Registered User

Merlin66 is offline
 
Join Date: Oct 2005
Location: Junortoun Vic
Posts: 8,927
If you’re not a website handlng financial transactions why bother???
Doesn’t mean anything.
Reply With Quote
  #5  
Old 23-11-2018, 07:32 PM
nsavage (Nick)
Registered User

nsavage is offline
 
Join Date: Aug 2018
Location: Adelaide
Posts: 87
Quote:
Originally Posted by Merlin66 View Post
If you’re not a website handlng financial transactions why bother???
Doesn’t mean anything.
Actually it does.

If you use the same password for IceinSpace as you do anything else I would seriously suggest you change it. I would even go as far as to say that you should ensure that it is not even remotely similar to any other password you use.

Additionally I would recommend that you not share any personal information that you wish to remain secure in PM's.

A lot of people consider a secured site as simply having an SSL certificate that verifies the site's identity. Whilst this is certainly the case it also allows the website to encrypt all information and traffic using the SSL protocol over port 443. Typically unsecured sites use port 80 and therefore utilise no encryption protocols. Not only is the data on the website typically stored in plain text and not encrypted the communications are also not encrypted and easily intercepted.

Free SSL certificates are available and whilst they do not provide the same level of verification as a paid for certificate (some certificates cost in to the $10's of thousands of dollars and carry very well recognised verification standards) they do provide the opportunity to encrypt the website and all communications between your browser and the website.

As I mentioned in my previous thread SSL has quickly become the norm. Consider that even google.com which is a simple web search engine has a verified SSL certificate and uses port 443.
Reply With Quote
  #6  
Old 23-11-2018, 09:20 PM
RickS's Avatar
RickS (Rick)
PI cult recruiter

RickS is offline
 
Join Date: Apr 2010
Location: Brisbane
Posts: 10,584
Just a few observations...

Quote:
Originally Posted by nsavage View Post
If you use the same password for IceinSpace as you do anything else I would seriously suggest you change it.
Using different passwords on different sites is good practice regardless of whether you're interacting with a site that uses TLS/SSL. Plenty of sites using "secure" browser communication have been hacked by other means losing personal data, including encrypted and even clear text passwords.

Quote:
Originally Posted by nsavage View Post
Additionally I would recommend that you not share any personal information that you wish to remain secure in PM's.
Also good practice even on secured sites.


Quote:
Originally Posted by nsavage View Post
A lot of people consider a secured site as simply having an SSL certificate that verifies the site's identity. Whilst this is certainly the case it also allows the website to encrypt all information and traffic using the SSL protocol over port 443. Typically unsecured sites use port 80 and therefore utilise no encryption protocols. Not only is the data on the website typically stored in plain text and not encrypted the communications are also not encrypted and easily intercepted.
The port numbers used are irrelevant, only the protocol matters. Having a X.509 certificate and using TLS encryption over the wire also has nothing to do with how data is stored on the site. A site using secure communications can still store data in plain text on a poorly secured server.

Quote:
Originally Posted by nsavage View Post
Consider that even google.com which is a simple web search engine has a verified SSL certificate and uses port 443.
Google is a company with a market cap of 723 billion US dollars...

It would be nice if IIS was updated to have a certificate now that browsers are complaining about it but in reality nothing has changed. The site is behaving exactly the same as it has for years. It's not a banking or e-commerce site so it's just not that big a deal. Even if it was using TLS I wouldn't be sharing any sensitive data in public or private messages.

Cheers,
Rick.
Reply With Quote
Reply

Bookmarks

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 08:55 AM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement