Site has no SSL

The worst monsters in the Hearthlands warp the fabric of space and time...

Site has no SSL

Postby shibarib » Sat Jan 11, 2020 5:14 am

Hey there! Haven't played in a while and just came back.

The site currently has no SSL, meaning all traffic (including logins and passwords) are unencrypted. Setting up one through Lets Encrypt is pretty straightforward and free, so if this could be done that'd be great!
shibarib
 
Posts: 1
Joined: Sat Jan 11, 2020 5:11 am

Re: Site has no SSL

Postby vatas » Sat Jan 11, 2020 7:22 am

I'm not expert but supposedly it has some sort of SSL, just not the standard that basically every other website uses because you have to pay some organisation for it and Loftar considers that a racket.

How do you enable this SSL? I don't know, someone who knows should post step-by-step guide on how to enable it.
The most actively maintained Haven and Hearth Wiki (Not guaranteed to be up-to-date with all w14 changes.)

Basic Claim Safety (And what you’re doing wrong) (I recommend you read it in it's entirety, but TL:;DR: Build a Palisade.)

Combat Guide (Overview, PVE, PVP) (Tells you how to try and escape, and make it less likely to die when caught.)
User avatar
vatas
 
Posts: 4511
Joined: Fri Apr 05, 2013 8:34 am
Location: Suomi Finland Perkele

Re: Site has no SSL

Postby MagicManICT » Sat Jan 11, 2020 7:44 am

There is an SSL. You will need to manually accept the certificate offered when attempting to connect via HTTPS, and possibly manually install it. Firefox likes to give headaches over this. I'm unsure of how other browsers handle this currently.

vatas wrote:Loftar considers that a racket.

It's not so much a racket, but in the off chance that the system does get hacked, the entire security of the Internet would be compromised and the whole system collapses like the house of cards it is. The only upside is that there are so many layers to hack from the last I read anything on it, it's not likely to happen. Very remotely possible, but not likely.
Opinions expressed in this statement are the authors alone and in no way reflect on the game development values of the actual developers.
User avatar
MagicManICT
 
Posts: 18437
Joined: Tue Aug 17, 2010 1:47 am

Re: Site has no SSL

Postby Granger » Sat Jan 11, 2020 12:17 pm

Paid for SSL certificates are a racket, when viewed in conjunction .
Can be avoided these days by using letsencrypt which is easy to set up.

Would be better though in case the certificates could be queried through DANE (through DNS, secured by DNSSEC to make sure you get the right one for the site you want to connect to), but that hasn't gotten any traction so far (as of no built-in support in the browsers it's not ready for joe verage, hence it's not used).
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9263
Joined: Mon Mar 22, 2010 2:00 pm

Re: Site has no SSL

Postby vatas » Sat Jan 11, 2020 2:31 pm

I'm currently using Pale Moon and Chrome, neither of them has, at least easy/clear, way of enabling custom certificates.
The most actively maintained Haven and Hearth Wiki (Not guaranteed to be up-to-date with all w14 changes.)

Basic Claim Safety (And what you’re doing wrong) (I recommend you read it in it's entirety, but TL:;DR: Build a Palisade.)

Combat Guide (Overview, PVE, PVP) (Tells you how to try and escape, and make it less likely to die when caught.)
User avatar
vatas
 
Posts: 4511
Joined: Fri Apr 05, 2013 8:34 am
Location: Suomi Finland Perkele

Re: Site has no SSL

Postby MagicManICT » Sat Jan 11, 2020 9:58 pm

vatas wrote:I'm currently using Pale Moon and Chrome, neither of them has, at least easy/clear, way of enabling custom certificates.

Browsers have really had this stripped out the last few years because a lot of phishing sites have abused it (mostly they just depend on people clicking on non-SSL links). When you do enable allowing this, it is then up to the user to make sure they're following "safe surfing" standards like making sure you're going to the website you intend to go to. Phishing scams work because people blindly click through to sites without thinking.

One might equate it to the "Are you sure?" delete confirmation boxes. it became so ubiquitous that the need for undeletion software has actually increased. People don't think of "what's the importance of this" and just click yes. People get so used to hand holding in their browsing habits they never learn to police their own actions. Comparatively, the need to just block users from "unsafe corners" of the Internet has simply risen over the years to the point that Internet companies act as net nannies for us all.
Opinions expressed in this statement are the authors alone and in no way reflect on the game development values of the actual developers.
User avatar
MagicManICT
 
Posts: 18437
Joined: Tue Aug 17, 2010 1:47 am

Re: Site has no SSL

Postby Granger » Sat Jan 11, 2020 11:58 pm

MagicManICT wrote:
vatas wrote:I'm currently using Pale Moon and Chrome, neither of them has, at least easy/clear, way of enabling custom certificates.
One might equate it to the "Are you sure?" delete confirmation boxes. it became so ubiquitous that the need for undeletion software has actually increased. People don't think of "what's the importance of this" and just click yes. People get so used to hand holding in their browsing habits they never learn to police their own actions. Comparatively, the need to just block users from "unsafe corners" of the Internet has simply risen over the years to the point that Internet companies act as net nannies for us all.

No.

The problem is in the hand holding instead of letting Darwin do his job.
The longer we let this continue the more likely we'll all end up in padded cells we'll be forced into to protect us.
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9263
Joined: Mon Mar 22, 2010 2:00 pm


Return to Bugs

Who is online

Users browsing this forum: No registered users and 5 guests