HTTPS on AO

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Xyxyll
    Old School Airsmith

    • Apr 2003
    • 1161

    #1

    HTTPS on AO

    @admins

    Any option of securing AO with https? As it stands, it's dangerously vulnerable to man in the middle attacks. There's enough security (email verification for any changes) that I'm not worried about my account being taken over, but I have had to make a habit of only using temporary passwords and avoiding PMing any personal details.

    I'm sure if there's a paid/supporter option, the community would offset the cost. I'd certainly donate to help.
  • Walking Stick
    Inline Mechs

    • Jan 2007
    • 681

    #2
    Originally posted by Xyxyll
    I'm sure if there's a paid/supporter option, the community would offset the cost. I'd certainly donate to help.
    Ditto
    >>WTB<< Sydarm w/ constant air__WarpedMephisto half-c/f body__Ac!d c/f trigger__TASO humpback frame__an Oh-Mag

    Comment

    • stircrazzzy
      Registered User
      • Dec 2007
      • 163

      #3
      Originally posted by Xyxyll
      I'm sure if there's a paid/supporter option, the community would offset the cost. I'd certainly donate to help.
      Agreed that AO contains some personal details which should benefit from encryption, but Let’s Encrypt is free. I’m happy to help getting https configured here if help is needed.

      Comment

      • Dayspring
        aka- The Day Wang

        • May 2001
        • 9664

        #4
        I believe we have the SSL certificate installed. Will look into the settings this weekend.

        Comment

        • Dayspring
          aka- The Day Wang

          • May 2001
          • 9664

          #5
          The certificate is out of date, so even if I told the forum to run secure, it would throw an error.

          I have an email out to the hosting company, so hopefully this week it'll be resolved. I'll also set a calendar reminder for the certificate expiration date to make sure it's taken care of in a more timely fashion in the future.

          Comment

          • Xyxyll
            Old School Airsmith

            • Apr 2003
            • 1161

            #6
            Great news. Thank you!

            Comment

            • MiniMaggin
              Registered User
              • Mar 2019
              • 36

              #7
              This is interesting reading. I'm an Android developer and learning about webpages.

              Comment

              • Dayspring
                aka- The Day Wang

                • May 2001
                • 9664

                #8
                So the certificate is now on auto-update. There are some hard coded items in the templates (so far as we can tell) that are not using HTTPS. Requires some template editing.

                Once we tackle that, we'll see what else is showing as not secure. It's going to be a bit of a process - one thing at a time.

                So right now, LOTS of the site is secured via HTTPS, but it's not showing due to the template issues.

                Comment

                • Xyxyll
                  Old School Airsmith

                  • Apr 2003
                  • 1161

                  #9
                  Originally posted by Dayspring
                  So the certificate is now on auto-update. There are some hard coded items in the templates (so far as we can tell) that are not using HTTPS. Requires some template editing.

                  Once we tackle that, we'll see what else is showing as not secure. It's going to be a bit of a process - one thing at a time.

                  So right now, LOTS of the site is secured via HTTPS, but it's not showing due to the template issues.
                  Thank you for reacting so quickly and taking this so seriously! It's a much appreciated effort that I think will help keep AO relevant for years to come.

                  Comment

                  • Dayspring
                    aka- The Day Wang

                    • May 2001
                    • 9664

                    #10
                    Had some free time this evening. Went through and found the non-secure coded items in the template. As of 10:38pm on 10/15, AO is showing as 100% secure in Google Chrome. Feel free to let me know if you have any issues or find places where it doesn't come across as secure.

                    Comment

                    • Beemer
                      I could tell you but then.

                      • Oct 2003
                      • 3250

                      #11
                      Outstanding. Well done.

                      Comment

                      • Dayspring
                        aka- The Day Wang

                        • May 2001
                        • 9664

                        #12
                        One thing to keep in mind - any images that are hosted elsewhere and linked in a post will cause that page to show as not fully secure only because of those images - all of the data (passwords, etc.) is secured. Just the way the internet works (unless those hosts use SSL, I think - this is a hobby, not a full time thing) I think.

                        Comment

                        Working...