Page 1 of 5 123 ... LastLast
Results 1 to 10 of 42

Thread: thank you! - All forums now HTTPS

  1. #1
    tsu2's Avatar
    tsu2 is online now Wise Penguin
    Join Date
    Jun 2008
    Location
    San Diego, Ca, USA
    Posts
    1,942

    Default thank you! - All forums now HTTPS

    With the increasing hacking and loss of anonyminity across the Internet, I applaud the move to secure all web access to the openSUSE forums with SSL.

    Was a suggestion I made long ago in this forum, is a welcome development to ensuring the integrity and privacy accessing Forums.

    A suggestion to further prevent information leakage is to ennumerate post IDs instead of using subject lines. This is what Google is now doing "sometimes" instead of inserting query keywords into the URL(well, sometimes it's still done the old way. Don't know why).

    TSU

  2. #2
    hendersj is offline Administrator
    Join Date
    Jul 2008
    Location
    Salt Lake City, Utah
    Posts
    11,256

    Default Re: thank you! - All forums now HTTPS

    On Wed, 12 Dec 2012 03:36:01 +0000, tsu2 wrote:

    > With the increasing hacking and loss of anonyminity across the Internet,
    > I applaud the move to secure all web access to the openSUSE forums with
    > SSL.
    >
    > Was a suggestion I made long ago in this forum, is a welcome development
    > to ensuring the integrity and privacy accessing Forums.


    It also simplifies a lot of stuff on the backend, I understand.

    > A suggestion to further prevent information leakage is to ennumerate
    > post IDs instead of using subject lines. This is what Google is now
    > doing "sometimes" instead of inserting query keywords into the URL(well,
    > sometimes it's still done the old way. Don't know why).


    I'm not sure I follow, but I also don't know that vBulletin can do this.

    Jim

    --
    Jim Henderson
    openSUSE Forums Administrator
    Forum Use Terms & Conditions at http://tinyurl.com/openSUSE-T-C

  3. #3
    hcvv's Avatar
    hcvv is online now Global Moderator
    Join Date
    Jun 2008
    Location
    Netherlands
    Posts
    12,435

    Default Re: thank you! - All forums now HTTPS

    I may be a daft end-user, but I am reading this very page, being loged in in the forums, and I do not see any sign of it being HTTPS.
    Henk van Velden

  4. #4
    keellambert is offline Parent Penguin
    Join Date
    Jun 2009
    Location
    Mangfall, Germany
    Posts
    889

    Default Re: thank you! - All forums now HTTPS

    here the address line reads

    "https://forums.opensuse.org/english/other-forums/forums-feedback/forums-comments-suggestions/481364-thank-you-all-forums-now-https.html"

  5. #5
    hcvv's Avatar
    hcvv is online now Global Moderator
    Join Date
    Jun 2008
    Location
    Netherlands
    Posts
    12,435

    Default Re: thank you! - All forums now HTTPS

    I have:
    http://forums.opensuse.org/english/other-forums/forums-feedback/forums-comments-suggestions/481364-thank-you-all-forums-now-https.html#post2510398
    Henk van Velden

  6. #6
    consused is online now Flux Capacitor Penguin
    Join Date
    Jun 2008
    Location
    United Kingdom
    Posts
    4,390

    Default Re: thank you! - All forums now HTTPS

    Quote Originally Posted by hcvv View Post
    I have same as @keellambert. If that's more secure, then add my thank you for the implementation.

  7. #7
    hcvv's Avatar
    hcvv is online now Global Moderator
    Join Date
    Jun 2008
    Location
    Netherlands
    Posts
    12,435

    Default Re: thank you! - All forums now HTTPS

    When I use @keellambert's, I land on the same page (using HTTPS of course).

    But when I use the link from the mail send to me because I am subscibed to this thread, it is HTTP. And the other links there (for stopping the subscription, etc.) are also all HTTP.

    Thus it seem that there are two parallel worlds now ???????????
    Henk van Velden

  8. #8
    hcvv's Avatar
    hcvv is online now Global Moderator
    Join Date
    Jun 2008
    Location
    Netherlands
    Posts
    12,435

    Default Re: thank you! - All forums now HTTPS

    I can add that using the link from my RSS feeds (where I normaly pry for interesting new threads) do give me HTTPS.

    Seems to be a sort of mixture. In any case, @tsu2's remark:
    ... to secure all web access to the openSUSE forums with SSL.
    is only partly true.
    Henk van Velden

  9. #9
    hendersj is offline Administrator
    Join Date
    Jul 2008
    Location
    Salt Lake City, Utah
    Posts
    11,256

    Default Re: thank you! - All forums now HTTPS

    On Wed, 12 Dec 2012 14:26:01 +0000, hcvv wrote:

    > I can add that using the link from my RSS feeds (where I normaly pry for
    > interesting new threads) do give me HTTPS.
    >
    > Seems to be a sort of mixture. In any case, @tsu2's remark:
    >> ... to secure all web access to the openSUSE forums with SSL.

    > is only partly true.


    Interesting, I'll check with Matt and see why the http stuff isn't
    redirecting - it was my understanding that it should be.

    Jim



    --
    Jim Henderson
    openSUSE Forums Administrator
    Forum Use Terms & Conditions at http://tinyurl.com/openSUSE-T-C

  10. #10
    MatthewEhle is offline Technical Staff
    Join Date
    Jan 2010
    Location
    Provo, UT
    Posts
    110

    Default Re: thank you! - All forums now HTTPS

    Quote Originally Posted by hendersj View Post
    On Wed, 12 Dec 2012 14:26:01 +0000, hcvv wrote:

    Interesting, I'll check with Matt and see why the http stuff isn't
    redirecting - it was my understanding that it should be.
    We don't enforce HTTPS for anonymous users, but they should be able to just put the "s" in there and start using it that way if they choose. HSTS is enabled as well, so if you start using HTTPS, it should be enforced by Firefox and Chrom(e|ium).

    For authenticated users, this should be a different story. You ought to have a cookie set that is named "authenticated" if you are logged in. Our ADC looks for that cookie and redirects you to HTTPS if you aren't already using it. Furthermore, the session cookie has the secure flag set, so you really shouldn't be authenticated over a non-secure connection. It seems to have worked very consistently, so I would be interested if you have found a way to "break" it!
    Last edited by MatthewEhle; 12-Dec-2012 at 12:24.

Page 1 of 5 123 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO 3.5.2 PL2