Help Forum How To | General Corvetteforum Questions | Feedback

Forum SSL cert no longer valid...

Thread Tools
 
Search this Thread
 
Old 03-08-2017, 12:31 PM
  #1  
Thud
Team Owner
Thread Starter
 
Thud's Avatar
 
Member Since: Aug 1999
Location: Bagpipes put the "fun" in "funeral"
Posts: 69,020
Likes: 0
Received 0 Likes on 0 Posts

Default Forum SSL cert no longer valid...

Just be careful if you're logging in on public wifi. Somebody could sniff your password.
Thud is offline  
Old 03-08-2017, 12:33 PM
  #2  
themonk
Team Owner
 
themonk's Avatar
 
Member Since: Jul 2006
Location: Calgary, AB. There's a reason why white was the only color offered on every year Corvette. Proud Canadian German Jamaican!
Posts: 97,155
Received 1,456 Likes on 799 Posts
St. Jude Donor '09, '12-'13-'14-'15-'16-'17

Default

the people in my building don't have a sniff about computers and I sure as hell don't go to a library or St. Arbucks just to use free wifi to come here.

But thanks for the heads up.
themonk is offline  
Old 03-08-2017, 12:40 PM
  #3  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

There is currently a bug with using Chrome and certain Symantec issued certificates. Google needs to fix Chrome. In the meantime, use Firefox or IE or Edge.
Thunder22 is offline  
Old 03-08-2017, 12:46 PM
  #4  
69L46
Team Owner
Support Corvetteforum!
 
69L46's Avatar
 
Member Since: Mar 2000
Location: Down in Bulldog country
Posts: 46,604
Received 107 Likes on 52 Posts
2015 C3 of Year Finalist
St. Jude Donor '15-'16-'17-'18-‘19-'20-'21-'22-'23

Default

Avoid the Starbucks wifi in Red Square and you'll be fine.
69L46 is offline  
Old 03-08-2017, 12:48 PM
  #5  
Jughead
Senior Member since 1492
Support Corvetteforum!
 
Jughead's Avatar
 
Member Since: Aug 2000
Location: Just because I'm paranoid doesn't mean people aren't out to get me...
Posts: 86,399
Received 152 Likes on 118 Posts
St. Jude Donor '09

Default

My PW is safe, it's password
Jughead is offline  
Old 03-08-2017, 01:13 PM
  #6  
Vetteman Jack
Administrator

Support Corvetteforum!
 
Vetteman Jack's Avatar
 
Member Since: Mar 2001
Location: In a parallel universe. Currently own 2014 Stingray Coupe.
Posts: 342,883
Received 19,282 Likes on 13,960 Posts
C7 of the Year - Modified Finalist 2021
MO Events Coordinator
St. Jude Co-Organizer
St. Jude Donor '03-'04-'05-'06-'07-'08-'09-'10-'11-'12-'13-'14-'15-'16-'17-'18-'19-
'20-'21-'22-'23-'24
NCM Sinkhole Donor
CI 5, 8 & 11 Veteran


Default

Have you reported this to the Forum Help Section?
Vetteman Jack is offline  
Old 03-08-2017, 01:14 PM
  #7  
Jbster
Le Mans Master
 
Jbster's Avatar
 
Member Since: Feb 2014
Location: hot 'lanta suburbs Georgia
Posts: 6,420
Received 14 Likes on 10 Posts
Default

Jbster is offline  
Old 03-08-2017, 02:47 PM
  #8  
Grumpy
MONARTOR

 
Grumpy's Avatar
 
Member Since: Aug 2001
Location: What I know, is dwarfed by what I pretend to know
Posts: 234,426
Received 132 Likes on 68 Posts
Cruise-In 5-6-7-8 Veteran
St. Jude '03-'04-'05-'06-'07-'08-'09-10-'11-12-'13-'14-'15-'16-17-'18-'19'-20-'21-'22-'23-'24
NCM Sinkhole Donor


Default

Originally Posted by Vetteman Jack
Have you reported this to the Forum Help Section?
hang on... won't hurt a bit
Grumpy is offline  
Old 03-09-2017, 08:11 AM
  #9  
Chevy Guy
Team Owner
 
Chevy Guy's Avatar
 
Member Since: Jan 2004
Location: NJ
Posts: 22,160
Received 64 Likes on 48 Posts

Default

The forum doesn't seem to have a cert at all right now - in fact is redirects from https http, no cert is presented.
Chevy Guy is offline  
Old 03-09-2017, 08:30 AM
  #10  
dvarapala
Making CFOT Great Again
Support Corvetteforum!
 
dvarapala's Avatar
 
Member Since: Oct 2001
Location: Tír na nÓg
Posts: 65,956
Received 89 Likes on 39 Posts

Default

So what's the deal with the certificate? When will the issue be fixed?

dvarapala is offline  
Old 03-09-2017, 09:43 AM
  #11  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

none of the sites that IB owns are secure right now, i just checked audiworld and it's "Not secure" as well. So I hope no one is stupid enough to use a username/password combo on IB sites and banking sites , because it's not being encrypted right now on IB.
Thunder22 is offline  
Old 03-09-2017, 02:15 PM
  #12  
J T
IB Staff
 
J T's Avatar
 
Member Since: Feb 2009
Posts: 9,447
Likes: 0
Received 4 Likes on 4 Posts
Default

This statement isn't quite accurate. This is not an IB only issue.

Some major browsers, such as FireFox and Chrome, recently began displaying a "not secure" message for any website that asks for a password and is not using HTTPS. CorvetteForum has not used HTTPS. This is also the case for the vast majority of community-based message forums like CorvetteForum.

The "not secure" message for any website asking for a password that's not using HTTPS is something new that browsers are doing. Previously, websites that collected passwords not using HTTPs did not have the browser generate such a message.

See this blog from Google:
https://security.googleblog.com/2016...ecure-web.html

As you can read, this is something new that browsers have started doing. Your browser may display a "not secure" message on CorvetteForum because CorvetteForum doesn't use HTTPS but does require a password to access your account. Again, the vast majority of websites like CorvetteForum are the same.

Internet Brands does, in fact, use some HTTPS on a few sites and is in testing. CorvetteForum currently is not one of those sites as Internet Brands continues to test and monitor.

Originally Posted by Thunder22
none of the sites that IB owns are secure right now, i just checked audiworld and it's "Not secure" as well. So I hope no one is stupid enough to use a username/password combo on IB sites and banking sites , because it's not being encrypted right now on IB.
J T is offline  
Old 03-09-2017, 02:24 PM
  #13  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

JT - To be clear, the issue with Chrome and Symantec Certs is a problem, agreed, but that results in an error message on Chrome with the usual "there is a problem with the cert" etcetc, I'm working with Google and Symantec where I work to fix that on our websites, but it looks like the simplest solution is to upgrade the cert and just bybass the problem completely.

But I was referencing that login on CF (as well as other IB sites e.g. AudiWorld) don't use HTTPS to login nor for browsing, which means that there is no secure cert at all. And yes, login does require a password, but that password is not secure and can be hacked far more easily than if IB used https. Which led to my warning that I hope people aren't so short sighted as to use the same username/password comb on CF and their financial institutions, you know, just in case the worst happens

Last edited by Thunder22; 03-09-2017 at 02:24 PM.
Thunder22 is offline  
Old 03-09-2017, 05:22 PM
  #14  
J T
IB Staff
 
J T's Avatar
 
Member Since: Feb 2009
Posts: 9,447
Likes: 0
Received 4 Likes on 4 Posts
Default

Right, but what I'm saying is this is nothing new with CorvetteForum not using HTTPS for username/password on this site, and it's typically the same for any other community-based message forum like CorvetteForum. What is new is the message, which is coming from the browsers as a push to increase security.

Where are you getting a message about a problem with the certificate on CorvetteForum?

Originally Posted by Thunder22
JT - To be clear, the issue with Chrome and Symantec Certs is a problem, agreed, but that results in an error message on Chrome with the usual "there is a problem with the cert" etcetc, I'm working with Google and Symantec where I work to fix that on our websites, but it looks like the simplest solution is to upgrade the cert and just bybass the problem completely.

But I was referencing that login on CF (as well as other IB sites e.g. AudiWorld) don't use HTTPS to login nor for browsing, which means that there is no secure cert at all. And yes, login does require a password, but that password is not secure and can be hacked far more easily than if IB used https. Which led to my warning that I hope people aren't so short sighted as to use the same username/password comb on CF and their financial institutions, you know, just in case the worst happens
J T is offline  
Old 03-09-2017, 06:48 PM
  #15  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.



Last edited by Thunder22; 03-09-2017 at 06:51 PM.
Thunder22 is offline  
Old 03-09-2017, 07:16 PM
  #16  
Chevy Guy
Team Owner
 
Chevy Guy's Avatar
 
Member Since: Jan 2004
Location: NJ
Posts: 22,160
Received 64 Likes on 48 Posts

Default

Originally Posted by Thunder22
I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.


Your browser determines if a website is safe or not based on the presence of a cert and if the cert is valid or from a trusted issuer. This is normally done only when using https and or port 443.

I have never tried to access CF from https, so I don't know if it was ever working. My bet is you are using https://forums.corvetteforum.com

Just use http, I can access using http from IE/Edge/FF and Chrome with no issues.


**EDIT**

Ah I see, you are clicking the little info button - simply don't do that. CF doesn't offer a secure connection, never has, period.

Last edited by Chevy Guy; 03-09-2017 at 07:23 PM.
Chevy Guy is offline  
Old 03-09-2017, 07:16 PM
  #17  
J T
IB Staff
 
J T's Avatar
 
Member Since: Feb 2009
Posts: 9,447
Likes: 0
Received 4 Likes on 4 Posts
Default

OK. Like I said, that's because the major browsers (atleast Google Chrome and Mozilla Firefox) recently added an update to their browser to notify users that any website they access that asks for a password not using HTTPS is "not secure". The vast majority of websites like CorvetteForum will generate the very same message because most message forums don't use HTTPS. Typically, that was generally for banking.

In this regard, the website is not less secure today than it was last year prior to this notice that Google Chrome and Mozilla Firefox added to their browsers. There's just a security push to have any website asking for a password to use HTTPS - or atleast notify the user that the website isn't using HTTPS. CorvetteForum, for the 8 years I've been involved, has never used HTTPS - just like any other website like CorvetteForum.

Internet Brands, which owns CorvetteForum, is well aware and has been testing and discussing HTTPS across some of their networks.

The server was not hacked and is not compromised. In my opinion, this message from the browser is causing a lot of alarm about something that has always been present.

Originally Posted by Thunder22
I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.


J T is offline  

Get notified of new replies

To Forum SSL cert no longer valid...

Old 03-09-2017, 07:26 PM
  #18  
Chevy Guy
Team Owner
 
Chevy Guy's Avatar
 
Member Since: Jan 2004
Location: NJ
Posts: 22,160
Received 64 Likes on 48 Posts

Default

Originally Posted by Thud
Just be careful if you're logging in on public wifi. Somebody could sniff your password.
This site NEVER had a cert installed, so it never had HTTPS.

Nothing new. Certs from a real issuer like Symantec are expensive.
Chevy Guy is offline  
Old 03-09-2017, 07:31 PM
  #19  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

I'm not trying to argue with you, I've got a 25 year career in IT and I've designed/supported over 100 web sites, so I'm just trying to point out the difference between what Thud reported, and that this site doesn't use a cert so it couldn't have expired, BUT, credentials can still be stolen as they're not encrypted. That's all.

I never said it was less secure today than yesterday as it's never been secure but that doesn't excuse IB and the original owner for the situation, but I'm glad it's finally being addressed. Every site that has a login should use encryption (banking sites stopped being the https poster boys years ago, most sites with a login function are https, especially in this day and age of "hack everything". )
Thunder22 is offline  
Old 03-09-2017, 07:33 PM
  #20  
Thunder22
Team Owner
 
Thunder22's Avatar
 
Member Since: May 2004
Location: Long Island
Posts: 31,245
Received 2,312 Likes on 1,457 Posts

Default

Originally Posted by Chevy Guy
This site NEVER had a cert installed, so it never had HTTPS.

Nothing new. Certs from a real issuer like Symantec are expensive.
They sure are. It's also expensive when some dolt uses the same username/password combo on a forum that they use for their banking, it gets hacked and their bank account gets emptied, but that's mostly on the user for not practicing good security.
Thunder22 is offline  


Quick Reply: Forum SSL cert no longer valid...



All times are GMT -4. The time now is 07:58 PM.