Author Topic: HTTPS: Please report any issues in this topic.  (Read 112420 times)

Birna Rørslett

  • Global Moderator
  • **
  • Posts: 5185
  • A lesser fierce bear of the North
Re: HTTPS: Please report any issues in this topic.
« Reply #180 on: January 01, 2020, 21:44:57 »
We have had issues with email/notification delivery, however the last obstacle of getting emails to gmail.com apparently now is defeated after I stepped up default server security setting to TLS1.2.

There was also a change of forum language to properly support UTF-8. That might trip up passwords with Nordic characters in them.

Akira

  • Homo jezoensis
  • NG Supporter
  • **
  • Posts: 12468
  • Tokyo, Japan
Re: HTTPS: Please report any issues in this topic.
« Reply #181 on: January 02, 2020, 12:39:56 »
The second page of January 2020 thread is not completely secured (the padlock is displayed with that orange triangle):

https://nikongear.net/revival/index.php?topic=9124.15

The orange triangle appears only in this second page.  Other pages (like the first page of January 2020 thread) are secured and no orange triangles are shown.

I'm not sure if this is related to the image(s) linked from outer website...
"The eye is blind if the mind is absent." - Confucius

"Limitation is inspiration." - Akira

Birna Rørslett

  • Global Moderator
  • **
  • Posts: 5185
  • A lesser fierce bear of the North
Re: HTTPS: Please report any issues in this topic.
« Reply #182 on: January 02, 2020, 13:30:11 »
We might have to adjust our .htaccess file to enforce https only. Strange still, as the linked images on that page (second in the January 2020 thread)  do follow the https protocol

Frank Fremerey

  • engineering art
  • NG Supporter
  • **
  • Posts: 12334
  • Bonn, Germany
Re: HTTPS: Please report any issues in this topic.
« Reply #183 on: January 03, 2020, 17:52:53 »
Currently when I browse the site all is fine, BUT:

I get a security warning on pages with extrenally linked pictures, just like Akira
You are out there. You and your camera. You can shoot or not shoot as you please. Discover the world, Your world. Show it to us. Or we might never see it.

Me: https://youpic.com/photographer/frankfremerey/

Birna Rørslett

  • Global Moderator
  • **
  • Posts: 5185
  • A lesser fierce bear of the North
Re: HTTPS: Please report any issues in this topic.
« Reply #184 on: January 03, 2020, 18:50:00 »
The page(in the January 2020 thread)  showing a broken padlock had a remotely linked image  originating from 500pix. That site is listed as suspicious due to a recent password breach.


Matthew Currie

  • NG Member
  • *
  • Posts: 676
  • You ARE NikonGear
Re: HTTPS: Please report any issues in this topic.
« Reply #185 on: January 27, 2020, 03:43:37 »
When the site went down back in fall I got notices for a while that it was under repair, then suddenly it just would not come up at all, just timing out. I finally got around to emailing Richard Haw, who said it was up and running, so I finally got around to trying to troubleshoot.  Something somewhere put the Nikongear URL in my hosts file.  Glad to be back, and will now see what happens whey I open pages with pictures.

Frank Fremerey

  • engineering art
  • NG Supporter
  • **
  • Posts: 12334
  • Bonn, Germany
Re: HTTPS: Please report any issues in this topic.
« Reply #186 on: August 30, 2020, 15:16:55 »
again ssl defunct...

You are out there. You and your camera. You can shoot or not shoot as you please. Discover the world, Your world. Show it to us. Or we might never see it.

Me: https://youpic.com/photographer/frankfremerey/

Birna Rørslett

  • Global Moderator
  • **
  • Posts: 5185
  • A lesser fierce bear of the North
Re: HTTPS: Please report any issues in this topic.
« Reply #187 on: August 30, 2020, 16:47:54 »
Well, you *did* access the NG site through the http protocol, *not* https. So response was as called for in terms of security.

We do have a redirect from http to https somewhere, but obviously one still can slip past that measure.

Perhaps the update of our SSL certificate this July have influenced the redirect opportunities? I'll have a peek if I can get some time off from other chores.

Birna Rørslett

  • Global Moderator
  • **
  • Posts: 5185
  • A lesser fierce bear of the North
Re: HTTPS: Please report any issues in this topic.
« Reply #188 on: September 01, 2020, 00:12:58 »
Hmmm. Looks like the updated new SSL certificate only works as we thought for direct https-based access. So add the "s" and you'll be just fine, Frank.

Http on its own is inherently 'unsafe' so should not be used for any web site where you log in or post contributions. Our automated redirect should take care of that if the wrong protocol is applied, but unfortunately it appears not to work at present. We probably have to invest in an additional SSL certificate for this so the autoswap http->https again becomes operative.

Where are our supporters when we need them? Please sign up as a supporter if you haven't already done so. Running NG is not cheap and we need a basic foundation of supporters to keep the site afloat.

BillO

  • NG Supporter
  • **
  • Posts: 54
  • Cruising the US in a Motorhome
Re: HTTPS: Please report any issues in this topic.
« Reply #189 on: March 31, 2021, 04:35:46 »
I received a strange error from my anti-virus program when I tried to access thread 9905 posted by Randy Strout. 
Trend Micro prevented opening the thread, posting that it held a phishing algorithm.
None of Randy's other threads showed the same issue.  Since I didn't want to override Trend Micro I couldn't see if the thread contained a normal post by Randy or if it was a copy from another source.

May be worth a look by someone with more tech savvy than I have.
Regards,
Bill Oliver

afx

  • NG Member
  • *
  • Posts: 454
  • Grumpy Bavarian from Munich
    • AFXImages
Re: HTTPS: Please report any issues in this topic.
« Reply #190 on: April 01, 2021, 19:45:10 »
Trend Micro
Get rid of that rubbish.

On current OSes all those 3rd party AV products actually increase your risks (check their CVE entries, Yuck).
Use a decent JavaScript Blocker in your Browser and the AV tools included natively in the OS.

cheers
afx