Help Forum How To | General Corvetteforum Questions | Feedback

Forum SSL cert no longer valid...

Thread Tools
 
Search this Thread
 
Old Mar 8, 2017 | 12:31 PM
  #1  
Thud's Avatar
Thud
Thread Starter
Team Owner
20 Year Member
 
Joined: Aug 1999
Posts: 69,020
Likes: 0
From: Bagpipes put the "fun" in "funeral"
Default Forum SSL cert no longer valid...

Just be careful if you're logging in on public wifi. Somebody could sniff your password.
Old Mar 8, 2017 | 12:33 PM
  #2  
themonk's Avatar
themonk
Team Owner
 
Joined: Jul 2006
Posts: 97,155
Likes: 1,471
From: Calgary, AB. There's a reason why white was the only color offered on every year Corvette. Proud Canadian German Jamaican!
St. Jude Donor '09, '12-'13-'14-'15-'16-'17
Default

the people in my building don't have a sniff about computers and I sure as hell don't go to a library or St. Arbucks just to use free wifi to come here.

But thanks for the heads up.
Old Mar 8, 2017 | 12:40 PM
  #3  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

There is currently a bug with using Chrome and certain Symantec issued certificates. Google needs to fix Chrome. In the meantime, use Firefox or IE or Edge.
Old Mar 8, 2017 | 12:46 PM
  #4  
69L46's Avatar
69L46
Team Owner
Supporting Lifetime
20 Year Member
 
Joined: Mar 2000
Posts: 46,602
Likes: 109
From: Down in Bulldog country
2015 C3 of Year Finalist
St. Jude Donor '15-'16-'17-'18-‘19-'20-'21-'22-'23
Default

Avoid the Starbucks wifi in Red Square and you'll be fine.
Old Mar 8, 2017 | 12:48 PM
  #5  
Jughead's Avatar
Jughead
Senior Member since 1492
Supporting Lifetime Gold
25 Year Member
Photogenic
Photoriffic
Liked
 
Joined: Aug 2000
Posts: 87,936
Likes: 156
From: Just because I'm paranoid doesn't mean people aren't out to get me...
St. Jude Donor '09
Default

My PW is safe, it's password
Old Mar 8, 2017 | 01:13 PM
  #6  
Vetteman Jack's Avatar
Vetteman Jack
Administrator
Supporting Lifetime
Veteran: Navy
St. Jude 20 Year Donor
25 Year Member
Veteran: Reserves
 
Joined: Mar 2001
Posts: 368,402
Likes: 24,797
From: In a parallel universe. Currently own 2014 Stingray Coupe.
C7 of the Year - Modified Finalist 2021
MO Events Coordinator
St. Jude Co-Organizer
St. Jude Donor '03 thru '26
NCM Sinkhole Donor
CI 5, 8 & 11 Veteran
Default

Have you reported this to the Forum Help Section?
Old Mar 8, 2017 | 01:14 PM
  #7  
Jbster's Avatar
Jbster
Le Mans Master
 
Joined: Feb 2014
Posts: 6,420
Likes: 15
From: hot 'lanta suburbs Georgia
Default

Old Mar 8, 2017 | 02:47 PM
  #8  
Grumpy's Avatar
Grumpy
MONARTOR
20 Year Member
Veteran: Army
St. Jude 20 Year Donor
Top Answer: 1
 
Joined: Aug 2001
Posts: 250,238
Likes: 146
From: What I know, is dwarfed by what I pretend to know
Cruise-In 5-6-7-8 Veteran
St. Jude Donor '03 thru '26
NCM Sinkhole Donor
Default

Originally Posted by Vetteman Jack
Have you reported this to the Forum Help Section?
hang on... won't hurt a bit
Corvette Stories

The Best of Corvette for Corvette Enthusiasts

story-0

10 Ugly Corvettes That We Still Kinda Love

 Joe Kucinski
story-1

Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

 Brett Foote
story-2

10 Things Every Corvette Owner Needs (2026 Edition)

 Michael S. Palmer
story-3

8 Most "Only Corvette Owners Understand" Quirks and Problems

 Pouria Savadkouei
story-4

10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

 Joe Kucinski
story-5

How Much Horsepower Every Corvette Engine "LOST" in 1972

 Joe Kucinski
story-6

Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

 Michael S. Palmer
story-7

Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

 Joe Kucinski
story-8

150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

 Joe Kucinski
story-9

8 Coolest Corvette Pace Cars (and Replicas) of All Time

 Verdad Gallardo
Old Mar 9, 2017 | 08:11 AM
  #9  
Chevy Guy's Avatar
Chevy Guy
Team Owner
20 Year Member
 
Joined: Jan 2004
Posts: 22,185
Likes: 65
From: NJ
Default

The forum doesn't seem to have a cert at all right now - in fact is redirects from https http, no cert is presented.
Old Mar 9, 2017 | 08:30 AM
  #10  
dvarapala's Avatar
dvarapala
Making CFOT Great Again
Supporting Lifetime Gold
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2001
Posts: 66,299
Likes: 89
From: Tír na nÓg
Default

So what's the deal with the certificate? When will the issue be fixed?

Old Mar 9, 2017 | 09:43 AM
  #11  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

none of the sites that IB owns are secure right now, i just checked audiworld and it's "Not secure" as well. So I hope no one is stupid enough to use a username/password combo on IB sites and banking sites , because it's not being encrypted right now on IB.
Old Mar 9, 2017 | 02:15 PM
  #12  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

This statement isn't quite accurate. This is not an IB only issue.

Some major browsers, such as FireFox and Chrome, recently began displaying a "not secure" message for any website that asks for a password and is not using HTTPS. CorvetteForum has not used HTTPS. This is also the case for the vast majority of community-based message forums like CorvetteForum.

The "not secure" message for any website asking for a password that's not using HTTPS is something new that browsers are doing. Previously, websites that collected passwords not using HTTPs did not have the browser generate such a message.

See this blog from Google:
https://security.googleblog.com/2016...ecure-web.html

As you can read, this is something new that browsers have started doing. Your browser may display a "not secure" message on CorvetteForum because CorvetteForum doesn't use HTTPS but does require a password to access your account. Again, the vast majority of websites like CorvetteForum are the same.

Internet Brands does, in fact, use some HTTPS on a few sites and is in testing. CorvetteForum currently is not one of those sites as Internet Brands continues to test and monitor.

Originally Posted by Thunder22
none of the sites that IB owns are secure right now, i just checked audiworld and it's "Not secure" as well. So I hope no one is stupid enough to use a username/password combo on IB sites and banking sites , because it's not being encrypted right now on IB.
Old Mar 9, 2017 | 02:24 PM
  #13  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

JT - To be clear, the issue with Chrome and Symantec Certs is a problem, agreed, but that results in an error message on Chrome with the usual "there is a problem with the cert" etcetc, I'm working with Google and Symantec where I work to fix that on our websites, but it looks like the simplest solution is to upgrade the cert and just bybass the problem completely.

But I was referencing that login on CF (as well as other IB sites e.g. AudiWorld) don't use HTTPS to login nor for browsing, which means that there is no secure cert at all. And yes, login does require a password, but that password is not secure and can be hacked far more easily than if IB used https. Which led to my warning that I hope people aren't so short sighted as to use the same username/password comb on CF and their financial institutions, you know, just in case the worst happens

Last edited by Thunder22; Mar 9, 2017 at 02:24 PM.
Old Mar 9, 2017 | 05:22 PM
  #14  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

Right, but what I'm saying is this is nothing new with CorvetteForum not using HTTPS for username/password on this site, and it's typically the same for any other community-based message forum like CorvetteForum. What is new is the message, which is coming from the browsers as a push to increase security.

Where are you getting a message about a problem with the certificate on CorvetteForum?

Originally Posted by Thunder22
JT - To be clear, the issue with Chrome and Symantec Certs is a problem, agreed, but that results in an error message on Chrome with the usual "there is a problem with the cert" etcetc, I'm working with Google and Symantec where I work to fix that on our websites, but it looks like the simplest solution is to upgrade the cert and just bybass the problem completely.

But I was referencing that login on CF (as well as other IB sites e.g. AudiWorld) don't use HTTPS to login nor for browsing, which means that there is no secure cert at all. And yes, login does require a password, but that password is not secure and can be hacked far more easily than if IB used https. Which led to my warning that I hope people aren't so short sighted as to use the same username/password comb on CF and their financial institutions, you know, just in case the worst happens
Old Mar 9, 2017 | 06:48 PM
  #15  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.



Last edited by Thunder22; Mar 9, 2017 at 06:51 PM.
Old Mar 9, 2017 | 07:16 PM
  #16  
Chevy Guy's Avatar
Chevy Guy
Team Owner
20 Year Member
 
Joined: Jan 2004
Posts: 22,185
Likes: 65
From: NJ
Default

Originally Posted by Thunder22
I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.


Your browser determines if a website is safe or not based on the presence of a cert and if the cert is valid or from a trusted issuer. This is normally done only when using https and or port 443.

I have never tried to access CF from https, so I don't know if it was ever working. My bet is you are using https://forums.corvetteforum.com

Just use http, I can access using http from IE/Edge/FF and Chrome with no issues.


**EDIT**

Ah I see, you are clicking the little info button - simply don't do that. CF doesn't offer a secure connection, never has, period.

Last edited by Chevy Guy; Mar 9, 2017 at 07:23 PM.
Old Mar 9, 2017 | 07:16 PM
  #17  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

OK. Like I said, that's because the major browsers (atleast Google Chrome and Mozilla Firefox) recently added an update to their browser to notify users that any website they access that asks for a password not using HTTPS is "not secure". The vast majority of websites like CorvetteForum will generate the very same message because most message forums don't use HTTPS. Typically, that was generally for banking.

In this regard, the website is not less secure today than it was last year prior to this notice that Google Chrome and Mozilla Firefox added to their browsers. There's just a security push to have any website asking for a password to use HTTPS - or atleast notify the user that the website isn't using HTTPS. CorvetteForum, for the 8 years I've been involved, has never used HTTPS - just like any other website like CorvetteForum.

Internet Brands, which owns CorvetteForum, is well aware and has been testing and discussing HTTPS across some of their networks.

The server was not hacked and is not compromised. In my opinion, this message from the browser is causing a lot of alarm about something that has always been present.

Originally Posted by Thunder22
I'm not getting a cert error, I'm getting a non-secure error message. if you click on the exclamation point in the url bar next to www.corvetteforum.com, you'll get the full message. I included a snip below of the security tab under development tools because i can't snag the other warning message.


Get notified of new replies

To Forum SSL cert no longer valid...

Old Mar 9, 2017 | 07:26 PM
  #18  
Chevy Guy's Avatar
Chevy Guy
Team Owner
20 Year Member
 
Joined: Jan 2004
Posts: 22,185
Likes: 65
From: NJ
Default

Originally Posted by Thud
Just be careful if you're logging in on public wifi. Somebody could sniff your password.
This site NEVER had a cert installed, so it never had HTTPS.

Nothing new. Certs from a real issuer like Symantec are expensive.
Old Mar 9, 2017 | 07:31 PM
  #19  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

I'm not trying to argue with you, I've got a 25 year career in IT and I've designed/supported over 100 web sites, so I'm just trying to point out the difference between what Thud reported, and that this site doesn't use a cert so it couldn't have expired, BUT, credentials can still be stolen as they're not encrypted. That's all.

I never said it was less secure today than yesterday as it's never been secure but that doesn't excuse IB and the original owner for the situation, but I'm glad it's finally being addressed. Every site that has a login should use encryption (banking sites stopped being the https poster boys years ago, most sites with a login function are https, especially in this day and age of "hack everything". )
Old Mar 9, 2017 | 07:33 PM
  #20  
Thunder22's Avatar
Thunder22
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2004
Posts: 31,800
Likes: 2,422
From: DFW/Long Island
Default

Originally Posted by Chevy Guy
This site NEVER had a cert installed, so it never had HTTPS.

Nothing new. Certs from a real issuer like Symantec are expensive.
They sure are. It's also expensive when some dolt uses the same username/password combo on a forum that they use for their banking, it gets hacked and their bank account gets emptied, but that's mostly on the user for not practicing good security.



All times are GMT -4. The time now is 12:52 AM.

story-0
10 Ugly Corvettes That We Still Kinda Love

Slideshow: 10 ugly Corvettes that we still kinda love.

By Joe Kucinski | 2026-06-03 10:34:17


VIEW MORE
story-1
Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

A lot of money has changed hands at the online auction house over the years.

By Brett Foote | 2026-06-03 10:21:50


VIEW MORE
story-2
10 Things Every Corvette Owner Needs (2026 Edition)

Slideshow: 10 great gifts Corvette enthusiasts actually want for Father's Day!

By Michael S. Palmer | 2026-06-03 15:43:40


VIEW MORE
story-3
8 Most "Only Corvette Owners Understand" Quirks and Problems

Slideshow: These are the quirks, annoyances, and oddly lovable problems that every Corvette owner eventually learns to live with.

By Pouria Savadkouei | 2026-05-28 09:31:39


VIEW MORE
story-4
10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

Slideshow: 10 reasons why the C6 Z06 is still a performance benchmark after 20 years.

By Joe Kucinski | 2026-05-27 17:20:09


VIEW MORE
story-5
How Much Horsepower Every Corvette Engine "LOST" in 1972

Slideshow: How much horsepower every Corvette engine lost in 1972.

By Joe Kucinski | 2026-05-27 16:54:53


VIEW MORE
story-6
Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

Slideshow: How to Protect A Convertible Top: 10 DOs & DON'Ts

By Michael S. Palmer | 2026-04-03 00:00:00


VIEW MORE
story-7
Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

Slideshow: The 10 most explosive Corvettes ever built based on power-to-weight ratio.

By Joe Kucinski | 2026-05-20 07:23:03


VIEW MORE
story-8
150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

Slideshow: From C1 to C8 we compare every Corvette generation by the numbers.

By Joe Kucinski | 2026-05-12 16:54:12


VIEW MORE
story-9
8 Coolest Corvette Pace Cars (and Replicas) of All Time

Slideshow: Some Corvette pace cars became collectible legends, while others perfectly captured the look and attitude of their era.

By Verdad Gallardo | 2026-05-11 09:50:51


VIEW MORE