Go Back   IceInSpace > General Astronomy > General Chat

Reply
 
Thread Tools Rate Thread
  #21  
Old 02-06-2021, 08:06 PM
RB's Avatar
RB (Andrew)
Moderator

RB is offline
 
Join Date: Aug 2005
Posts: 25,759
Quote:
Originally Posted by LewisM View Post
You have a point.


Or pointy ears.


Either eether
Now you're Putin me on....

Reply With Quote
  #22  
Old 02-06-2021, 08:15 PM
irwjager's Avatar
irwjager (Ivo)
Registered User

irwjager is offline
 
Join Date: Apr 2010
Location: Melbourne
Posts: 532
It's possible the unwelcome guest simply got a username/email + password combo from the many data breaches out there.


You can check whether you were victim of such a (known) breach and what was leaked here;
https://haveibeenpwned.com/
Reply With Quote
  #23  
Old 02-06-2021, 08:36 PM
DarkArts
Registered User

DarkArts is offline
 
Join Date: Dec 2014
Posts: 606
Quote:
Originally Posted by gary
If you have an existing bookmark, you might want to edit it
Well, shucks! I just updated a couple of hundred old bookmarks from HTTP to HTTPS and 95% of the sites accept a secure connection now. It's just goes to show, you can't be complacent online - it's always changing.

So, tip of the week: check your old bookmarks.

As others have said, encrypting a web connection is not a guarantee of safety, but locking the door is at least an improvement over leaving it open (with all the qualifying statements that would go with that analogy ...).

As for stronger passwords: entropy is what you want. The more entropy in your password, the stronger it is. Here's an explanation or two:

https://explainxkcd.com/wiki/index.p...sword_Strength

https://www.itdojo.com/a-somewhat-br...sword-entropy/
Reply With Quote
  #24  
Old 02-06-2021, 09:30 PM
DarkArts
Registered User

DarkArts is offline
 
Join Date: Dec 2014
Posts: 606
Quote:
Originally Posted by PCH View Post
There’s no need to do any of this
amending your bookmarks.

The site owner can easily and quickly
re-route all the variants to the https address
internally so that you go to the https site regardless
of what you type in (or have saved in your bookmark)

Just satin’
Except for all the sites that don't, such as ~90% of the ones I tested today. So thanks for that, but the advice was, in fact, pretty useless. Just sayin'.

More useful advice would be to install a browser extension called HTTPS Everywhere (available for most popular browsers), which forces use of HTTPS if available, regardless of whether you used HTTP or HTTPS in your address bar/bookmark:

Quote:
Originally Posted by Wikipedia
HTTPS Everywhere is a free and open-source browser extension for Google Chrome, Microsoft Edge, Mozilla Firefox, Opera, Brave, Vivaldi and Firefox for Android, which is developed collaboratively by The Tor Project and the Electronic Frontier Foundation.

It automatically makes websites use a more secure HTTPS connection instead of HTTP, if they support it. The option "Encrypt All Sites Eligible" makes it possible to block and unblock all non-HTTPS browser connections with one click.
But if you like your browser with minimal extensions - like me - you can edit your bookmarks.
Reply With Quote
  #25  
Old 02-06-2021, 10:28 PM
PCH's Avatar
PCH (Paul)
Registered User

PCH is offline
 
Join Date: Feb 2007
Location: Perth WA
Posts: 2,297
Quote:
Originally Posted by DarkArts View Post
Except for all the sites that don't, such as ~90% of the ones I tested today. So thanks for that, but the advice was, in fact, pretty useless. Just sayin'.

More useful advice would be to install a browser extension called HTTPS Everywhere (available for most popular browsers), which forces use of HTTPS if available, regardless of whether you used HTTP or HTTPS in your address bar/bookmark:



But if you like your browser with minimal extensions - like me - you can edit your bookmarks.
Ok, point taken. I’ve deleted my post since you found it so useless.
Not sure why you felt the need to be rude about it, - I guess you
felt you had a point to make.
Reply With Quote
  #26  
Old 02-06-2021, 10:31 PM
redbeard's Avatar
redbeard (Damien)
Registered User

redbeard is offline
 
Join Date: Nov 2010
Location: Adelaide
Posts: 558
Quote:
Originally Posted by DarkArts View Post
Well, shucks! I just updated a couple of hundred old bookmarks from HTTP to HTTPS and 95% of the sites accept a secure connection now. It's just goes to show, you can't be complacent online - it's always changing.

So, tip of the week: check your old bookmarks.

As others have said, encrypting a web connection is not a guarantee of safety, but locking the door is at least an improvement over leaving it open (with all the qualifying statements that would go with that analogy ...).

As for stronger passwords: entropy is what you want. The more entropy in your password, the stronger it is. Here's an explanation or two:

https://explainxkcd.com/wiki/index.p...sword_Strength

https://www.itdojo.com/a-somewhat-br...sword-entropy/
That was an awesome link with the comic. Never would have thought that as we've always been told by the network security people to do the hard to remember stuff.

Thanks for posting.

Only issue now is they won't let me use a really good easy to remember password and I have to have letters, numbers,characters and have to press the keys whilst standing on my head. Lol.😏

Cheers,
Damien
Reply With Quote
  #27  
Old 03-06-2021, 08:16 AM
lazjen's Avatar
lazjen (Chris)
PI cult member

lazjen is offline
 
Join Date: Dec 2012
Location: Flaxton, Qld
Posts: 2,064
Quote:
Originally Posted by redbeard View Post
That was an awesome link with the comic. Never would have thought that as we've always been told by the network security people to do the hard to remember stuff.

Thanks for posting.

Only issue now is they won't let me use a really good easy to remember password and I have to have letters, numbers,characters and have to press the keys whilst standing on my head. Lol.😏

Cheers,
Damien
Use a password manager. Let it generate and remember the passwords for you. As an added bonus you can have stupendously large passwords (40, 50, 60+ characters, etc) with symbols, letters, different case, numbers, etc. Then, all you need to remember is one password to access the password manager - make this decent, but memorable and you're in a much better position overall.
Reply With Quote
  #28  
Old 03-06-2021, 08:31 AM
multiweb's Avatar
multiweb (Marc)
ze frogginator

multiweb is offline
 
Join Date: Oct 2007
Location: Sydney
Posts: 22,062
Quote:
Originally Posted by LewisM View Post
Why the hell do I want the password "VertVertVertVertVertVertFroggy "?
You're missing one "vert". It's a recursive pwd based on the Russian dolls design. Uncrackable.
Reply With Quote
  #29  
Old 03-06-2021, 09:54 AM
Outcast's Avatar
Outcast (Carlton)
Always gonna be a NOOB...

Outcast is offline
 
Join Date: Oct 2008
Location: Cairns, Qld
Posts: 1,285
Quote:
Originally Posted by lazjen View Post
Use a password manager. Let it generate and remember the passwords for you. As an added bonus you can have stupendously large passwords (40, 50, 60+ characters, etc) with symbols, letters, different case, numbers, etc. Then, all you need to remember is one password to access the password manager - make this decent, but memorable and you're in a much better position overall.
Any advice on the 'free' password manager such as say Nordpass free? I use their paid VPN service.. so, any catches with a free password manager that you know of?
Reply With Quote
  #30  
Old 03-06-2021, 06:07 PM
lazjen's Avatar
lazjen (Chris)
PI cult member

lazjen is offline
 
Join Date: Dec 2012
Location: Flaxton, Qld
Posts: 2,064
If you're already using Nord for VPN, then that's probably a good enough option. The hassle will be if you leave Nord and need to transfer your passwords to a new manager.

I am using Lastpass right now, but recently they changed things to make it less useful. I'm probably going to change to Keepass for my requirements, but it's a bit more stuffing around to manage it properly and I haven't summoned the will to get it done yet.
Reply With Quote
  #31  
Old 03-06-2021, 06:29 PM
Outcast's Avatar
Outcast (Carlton)
Always gonna be a NOOB...

Outcast is offline
 
Join Date: Oct 2008
Location: Cairns, Qld
Posts: 1,285
Quote:
Originally Posted by lazjen View Post
If you're already using Nord for VPN, then that's probably a good enough option. The hassle will be if you leave Nord and need to transfer your passwords to a new manager.

I am using Lastpass right now, but recently they changed things to make it less useful. I'm probably going to change to Keepass for my requirements, but it's a bit more stuffing around to manage it properly and I haven't summoned the will to get it done yet.
Thankyou... I'm actually looking at the Nord Family Premium now with it's extra functionality of password sharing which, would be useful between the wife & I for shared accounts (Amazon, bank, creditcards, etc)...

Cost seems reasonable... I am struggling to convince my wife of the need though which is a little frustrating...
Reply With Quote
  #32  
Old 03-06-2021, 08:02 PM
DarkArts
Registered User

DarkArts is offline
 
Join Date: Dec 2014
Posts: 606
Quote:
Originally Posted by PCH View Post
Ok, point taken. I’ve deleted my post since you found it so useless.
Not sure why you felt the need to be rude about it, - I guess you
felt you had a point to make.
Yeah, I guess that was overly blunt - believe it or not, offense not intended. But there is an awful lot of 'lukewarm' advice out there that doesn't actually help people and that really ought to be set straight.
Reply With Quote
  #33  
Old 04-06-2021, 12:30 PM
Kal's Avatar
Kal (Andrew)
1¼" ñì®våñá

Kal is offline
 
Join Date: Nov 2006
Location: Sydney
Posts: 1,845
Quote:
Originally Posted by gary View Post
Hi Peter,

When you see the "Not Secure" message and an open padlock icon
next to the URL field on your browser, it means you accessed it
via a URL of the form http://www.iceinspace.com.au

If you have an existing bookmark, you might want to edit it to
be of the form https://www.iceinspace.com.au

Thanks for the tip, I had a http bookmark not a https one so I updated it
Reply With Quote
  #34  
Old 04-06-2021, 12:38 PM
multiweb's Avatar
multiweb (Marc)
ze frogginator

multiweb is offline
 
Join Date: Oct 2007
Location: Sydney
Posts: 22,062
Adding those lines to the .htacess file would redirect everything to https automatically and address the current indexing in Google as well.

Quote:
RewriteEngine on
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
RewriteBase /
RewriteCond %{SERVER_PORT} 80
RewriteRule ^(.*)$ https://www.iceinspace.com.au/$1 [R,L]
Having said that there is nothing of value on IIS. It is public domain. Storm in a teacup.
Reply With Quote
Reply

Bookmarks

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 03:23 PM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement
Testar
Advertisement