Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Despite in HTTPS, replies still not secured

views
     
TSeverling
post Aug 5 2011, 02:08 AM, updated 15y ago

Look at all my stars!!
*******
Senior Member
3,591 posts

Joined: Feb 2008
When at https://forum.lowyat.net/, replying takes us outside of the HTTPS session.

The code that does that is:
CODE
<form name="REPLIER" action="http://forum.lowyat.net/index.php?" method="post">


Would somebody fix this, please? With sugar and strawberry on top? wub.gif
wKkaY
post Aug 5 2011, 02:46 AM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
Thanks, never noticed that because the correct URL is produced when a moderator views the forum over HTTPS.
sniper69
post Aug 5 2011, 07:15 AM

.: One Shot One Kill :. .+|Level 9 Type Shit|+.
*******
Senior Member
7,173 posts

Joined: Jan 2003
From: PCH


erm, does this also include this one? on search box thingy down on left corner? i got this message whenever i try search and hit enter.

user posted image

and, when "continue", i notice it's HTTP instead of HTTPS on address.
wKkaY
post Aug 6 2011, 09:44 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
This should be fixed now.

In addition, I have provided a HTTPS Login option at the login page - http://forum.lowyat.net/index.php?act=Login&CODE=00

And a "Always browse with HTTPS" option at the board settings - http://forum.lowyat.net/index.php?act=UserCP&CODE=04

Can you give it a try?
TSeverling
post Aug 6 2011, 11:48 PM

Look at all my stars!!
*******
Senior Member
3,591 posts

Joined: Feb 2008
The new feature seems to be working well. Tested the posting and search issues.

There's a minor problem when you're in HTTP and then you try posting or searching with the HTTPS option checked, the forum will send you back to the index page. But it works fine if you're already browsing in HTTPS.

Thanks a lot wKkaY! notworthy.gif notworthy.gif notworthy.gif


Added on August 6, 2011, 11:57 pmOh, I hadn't realised one problem then. If our bookmarks were pointing at HTTPS but our Board Settings had HTTPS off, we would silently get redirected to HTTP.

I think this behaviour isn't optimal, because the user must know of the HTTPS option. Once your announcement expires or if people never read it (like first time visitors in 2012), they won't be able to use the forum's HTTPS option. It would be much better to default to an "Auto" option, where the forum doesn't care whether you use HTTP or HTTPS.

This post has been edited by everling: Aug 6 2011, 11:57 PM
wKkaY
post Aug 6 2011, 11:58 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
QUOTE(everling @ Aug 6 2011, 11:48 PM)
There's a minor problem when you're in HTTP and then you try posting or searching with the HTTPS option checked, the forum will send you back to the index page. But it works fine if you're already browsing in HTTPS.
*
That's because we redirect you to https:// if you happen to stumble upon a http:// link. That glitch will be rare in the field I hope. It can happen if you have two windows open and login with the HTTPS option in window A while window B is still on HTTP.


Added on August 7, 2011, 12:03 am
QUOTE(everling @ Aug 6 2011, 11:48 PM)
I think this behaviour isn't optimal, because the user must know of the HTTPS option. Once your announcement expires or if people never read it (like first time visitors in 2012), they won't be able to use the forum's HTTPS option. It would be much better to default to an "Auto" option, where the forum doesn't care whether you use HTTP or HTTPS.
*
Point taken. I made this decision because IE8 and below pops up a prompt about mixed ssl/non-ssl content. IE9 handles it more gracefully. I'll think about what I can do about this.
Human Nature
post Aug 7 2011, 04:27 PM

- student of human nature -
*********
All Stars
26,524 posts

Joined: Jan 2003
The login and pwd remember function seems not working anymore? I have to login everytime now.
Neo|ofGeo
post Aug 7 2011, 04:28 PM

Stop Complaining and Read
Group Icon
Elite
3,142 posts

Joined: Nov 2010


QUOTE(Human Nature @ Aug 7 2011, 04:27 PM)
The login and pwd remember function seems not working anymore? I have to login everytime now.
*
using firefox?
i have same problem also
wKkaY
post Aug 7 2011, 04:58 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
Ah crap. I forgot to test that (because I hardly close my browser).
Human Nature
post Aug 7 2011, 05:31 PM

- student of human nature -
*********
All Stars
26,524 posts

Joined: Jan 2003
i am using IE
Mr.Docter
post Aug 7 2011, 06:14 PM

Doctorpreneurs
*******
Senior Member
5,367 posts

Joined: Aug 2009




QUOTE(Human Nature @ Aug 7 2011, 04:27 PM)
The login and pwd remember function seems not working anymore? I have to login everytime now.
*
QUOTE(Neo|ofGeo @ Aug 7 2011, 04:28 PM)
using firefox?
i have same problem also
*
Same situation here.
zstan
post Aug 7 2011, 06:36 PM

10k Club
********
All Stars
15,856 posts

Joined: Nov 2007
From: Zion



Using chrome no problem wor.
mekboyz
post Aug 7 2011, 06:47 PM

Casual
***
Junior Member
438 posts

Joined: Apr 2007
From: Petaling Jaya



QUOTE(Human Nature @ Aug 7 2011, 04:27 PM)
The login and pwd remember function seems not working anymore? I have to login everytime now.
*
using firefox and chrome here and i have the same problem

1. If i login from the main webpage : http://forum.lowyat.net/ i have to login everytime i open and close my browser.

2. However my password is saved when i login here: https://forum.lowyat.net/index.php?act=Login&CODE=00 when i open and close my browser.

I already cleared the browser's cache and cookies in case.
Alpha_Tay
post Aug 8 2011, 09:31 AM

Beware The Spammer Star!
******
Senior Member
1,725 posts

Joined: Jan 2003
for the automatic log in issue, use this to clean the https cookie, so u can automatic log in at http again.

https://forum.lowyat.net/index.php?act=Login&CODE=06
saturn85
post Aug 8 2011, 04:12 PM

Folding@home
*******
Senior Member
8,686 posts

Joined: Mar 2009



i get this on the address bar: user posted imageuser posted image unsure.gif

This post has been edited by saturn85: Aug 8 2011, 04:13 PM
TSeverling
post Aug 8 2011, 08:08 PM

Look at all my stars!!
*******
Senior Member
3,591 posts

Joined: Feb 2008
Iianm, that icon only appears if there are unencrypted content on the page that you're viewing. Was it Chrome? The other browser vendors use different and less disturbing or troubling methods to indicate unencrypted content.

Unencrypted content in your encrypted HTML page is an impossible problem to solve for a forum if you want to allow your users to use external images that comes from sites without HTTPS (eg: signature images, photographs, hardware charts, etc) or don't have the technical expertise to know that they need to use HTTPS sources instead of unencrypted sources.
wKkaY
post Aug 8 2011, 08:42 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
Actually chrome will show a yellow icon if images are loaded from http:// sites.

The crossed padlock is due to our use of http:// scripts from our advertising providers, which don't have HTTPS support. We're out of luck here, because we do need the ads to be shown. But if you use IE9, it will conveniently avoid them wink.gif
TSeverling
post Aug 8 2011, 10:02 PM

Look at all my stars!!
*******
Senior Member
3,591 posts

Joined: Feb 2008
I don't understand why it is that way. HTTPS secured JavaScript scripts can still be super evil and malicious scripts.
saturn85
post Aug 9 2011, 12:00 AM

Folding@home
*******
Senior Member
8,686 posts

Joined: Mar 2009



QUOTE(everling @ Aug 8 2011, 08:08 PM)
Iianm, that icon only appears if there are unencrypted content on the page that you're viewing. Was it Chrome? The other browser vendors use different and less disturbing or troubling methods to indicate unencrypted content.

Unencrypted content in your encrypted HTML page is an impossible problem to solve for a forum if you want to allow your users to use external images that comes from sites without HTTPS (eg: signature images, photographs, hardware charts, etc) or don't have the technical expertise to know that they need to use HTTPS sources instead of unencrypted sources.
*

QUOTE(wKkaY @ Aug 8 2011, 08:42 PM)
Actually chrome will show a yellow icon if images are loaded from http:// sites.

The crossed padlock is due to our use of http:// scripts from our advertising providers, which don't have HTTPS support. We're out of luck here, because we do need the ads to be shown. But if you use IE9, it will conveniently avoid them wink.gif
*
yes, i m using google chrome.
still not very clear how https works. rclxub.gif
possible for the page to have this?: user posted imageuser posted image
wKkaY
post Aug 9 2011, 12:32 AM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
QUOTE(everling @ Aug 8 2011, 10:02 PM)
I don't understand why it is that way. HTTPS secured JavaScript scripts can still be super evil and malicious scripts.
*
In the event of an MITM, a script is provided a larger attack surface (think DOM manipulation, HTTP requests, etc) than multimedia are.


Added on August 9, 2011, 12:34 am
QUOTE(saturn85 @ Aug 9 2011, 12:00 AM)
yes, i m using google chrome.
still not very clear how https works. rclxub.gif
possible for the page to have this?: user posted imageuser posted image
*
Sorry, we can't make it green. But I assure you that your browsing with https:// is at worst as secure as http://

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0283sec    0.64    5 queries    GZIP Disabled
Time is now: 3rd December 2025 - 10:15 PM