[CLOSED] Lack Of Ssl (https) Support

Discussion in 'Support' started by Arakel, May 27, 2021.

  1. Arakel

    Arakel First Team

    Joined:
    Sep 14, 2010
    Messages:
    26,758
    Likes Received:
    8,245
    Trophy Points:
    113
    Location:
    Redacted
    This site has been operating without a SSL certificate for quite a while now. I've considered bringing it up before as it is a huge security issue, but I've now definitely been breached due to this.

    I received a fairly obvious blackmail template scam email in my primary email account. In that email, they identified a password I had been using (without saying where it was used). Thing is, I use a unique password on every site and service I utilize, so it's fairly easy to identify where the security breach came from. In this case, the exposed password listed in the email was from this site - it's the only place I use that particular password.

    Without an SSL certificate it's impossible to encrypt communication between a client machine and the site, so it means a bad actor can intercept information and easily access it due to it not being encrypted. For those using the same username/email address/password on multiple sites, this creates a huge risk of exposure/potential for account breaches.

    I'd strongly suggest getting a SSL certificate into place as soon as possible. There are free services around if paying for one is a problem (they can be expensive from some providers).
     
    wfcmoog, wfc78, IRB and 4 others like this.
  2. Arakel

    Arakel First Team

    Joined:
    Sep 14, 2010
    Messages:
    26,758
    Likes Received:
    8,245
    Trophy Points:
    113
    Location:
    Redacted
    Oh and from a user perspective: if you use the same password you use on this site on other sites too, I would STRONGLY recommend changing it immediately (and using a unique password here at a bare minimum). It's very likely that more accounts than mine have been compromised (probably most, if not all).
     
    wfcmoog and FromDiv4 like this.
  3. UEA_Hornet

    UEA_Hornet First Team Captain

    Joined:
    Nov 7, 2006
    Messages:
    69,414
    Likes Received:
    25,913
    Trophy Points:
    113
    Location:
    The Midlands
    [​IMG]
     
  4. UEA_Hornet

    UEA_Hornet First Team Captain

    Joined:
    Nov 7, 2006
    Messages:
    69,414
    Likes Received:
    25,913
    Trophy Points:
    113
    Location:
    The Midlands
    Any updates this? @hornmeister? I’m pretty concerned that my ‘password123’ will have to be changed all over the shop as a result of this.
     
  5. hornmeister

    hornmeister Tired

    Joined:
    Sep 14, 2006
    Messages:
    71,011
    Likes Received:
    5,506
    Trophy Points:
    113
    As I understand it @nisman94 is looking into it. We have the certificate but it's not being activated or some such jiggery pokery.

    Beyond my skillset I'm afraid and moving into semi-retirement from the mod game the report function will be best going forward as I'm not around much these days.
     
    Bwood_Horn, Diamond and UEA_Hornet like this.
  6. cyaninternetdog

    cyaninternetdog Forum Hippie

    Joined:
    Feb 7, 2007
    Messages:
    15,711
    Likes Received:
    3,344
    Trophy Points:
    113
    Location:
    Tyne And Wear
    I have https everywhere installed on my browser and this is one of the very few sites it doesnt work on.
     
  7. Diamond

    Diamond First Team

    Joined:
    Oct 15, 2011
    Messages:
    17,120
    Likes Received:
    6,349
    Trophy Points:
    113
    Whilst an SSL certificate is a mighty fine idea for any site, most forum software will transmit passwords across the internet as a hash value so "sniffing" network data won't help in gathering them. More likely is either a key logger is installed on the users device or the company that host the forums have been compromised.
     
  8. Arakel

    Arakel First Team

    Joined:
    Sep 14, 2010
    Messages:
    26,758
    Likes Received:
    8,245
    Trophy Points:
    113
    Location:
    Redacted
    Hashing is used to store passwords in a database so that they're useless if the database is compromised. When a user authenticates to something that is using a hashed password, the password is sent in the way the user enters it (which on a port 80 connection means unencrypted plain text) and it then hashed and compared to the hashed string in the database. This is the main reason so many companies say "we can't see or retrieve your password"; they literally don't have it and couldn't look it up if they wanted to, as they only have the hashed value.

    What this means is that the password has to be received and converted into the hashed value in the first place, which is where the possibility for intercept arises. Without a SSL certificate you can't encrypt the connection between client and server using TLS and as a result the password is exposed any time the user enters it. This is the primary reason you put SSL certificates on websites. You can't encrypt the client/server connection without one, which is the methodology by which supplied credentials are protected in transit after they leave the client machine. Without that TLS encryption the data can be sniffed at any node between source and destination inclusive, including remotely.
     
    Last edited: Jun 4, 2021
  9. Steve Leo Beleck

    Steve Leo Beleck Squad Player

    Joined:
    Feb 2, 2015
    Messages:
    11,343
    Likes Received:
    16,097
    Trophy Points:
    113
    Getting a lot of messages now when on mobile about how this site isn't safe. Any news on getting the encryption up and running?
     
    Hairyfrog and wfcmoog like this.
  10. GarbeliaHornet

    GarbeliaHornet Academy Graduate

    Joined:
    May 2, 2021
    Messages:
    463
    Likes Received:
    214
    Trophy Points:
    43
    Seconding above comment. I am starting to find this concerning.
     
    Hairyfrog likes this.
  11. HappyHornet24

    HappyHornet24 Crapster

    Staff Member
    Joined:
    May 7, 2013
    Messages:
    8,885
    Likes Received:
    3,666
    Trophy Points:
    113
    Gender:
    Female
    Location:
    Hampshire
    Yup I am getting more messages although I have used this site for years with, fingers crossed, no issues.
     
  12. nfh

    nfh Academy Graduate

    Joined:
    Jul 22, 2011
    Messages:
    296
    Likes Received:
    34
    Trophy Points:
    28
    Location:
    new forest horn
    Same here lots of messages saying insecure web site, plus getting strange page displays no yellow background just plain white, not sure if thats linked.
     
  13. Bwood_Horn

    Bwood_Horn Squad Player

    Joined:
    Jul 21, 2010
    Messages:
    14,779
    Likes Received:
    5,232
    Trophy Points:
    113
    Occupation:
    BMS
    Location:
    The 'Wood
    #me2*

    *...and I'm a smug b'stard using Linux.
     

Share This Page