Why the forum doesn't use https?

Thoughts on the further development of Haven & Hearth? Feel free to opine!

Why the forum doesn't use https?

Postby rainland » Wed Apr 19, 2017 11:09 am

Or more like: Error code: SEC_ERROR_UNKNOWN_ISSUER

I thought its very easy nowadays with lets encrypt etc.
User avatar
rainland
 
Posts: 47
Joined: Sun Jun 10, 2012 9:40 am

Re: Why the forum doesn't use https?

Postby shubla » Wed Apr 19, 2017 11:23 am

It does, but you have to manually install the certificate. Most browsers wont allow you to install it, at least very easily.
Tbh most people probably dont use it because they dont even know that they should manually install it from some completely random domain.
Devs should just buy one or use the free alternatives and force everyone to use https on the site.

http://dolda2000.com/
Even that site basically asks you to call loftar in order to verify authenticity of the certificate
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Why the forum doesn't use https?

Postby rainland » Wed Apr 19, 2017 11:43 am

shubla wrote:Devs should just buy one or use the free alternatives and force everyone to use https on the site.

Yeah, precisely. Current setup is just irresponsible and bad practice imo.
User avatar
rainland
 
Posts: 47
Joined: Sun Jun 10, 2012 9:40 am

Re: Why the forum doesn't use https?

Postby Granger » Wed Apr 19, 2017 12:22 pm

rainland wrote:Current setup is just irresponsible and bad practice imo.

That is what the ones that want to sell certificates say, hoping for you to fall for it and pressure you site operator to pay up - basically it's a scheme to turn you into an unpaid mob enforcer for them. Given your post it seems to work :(

More details about this particular scam here.
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9254
Joined: Mon Mar 22, 2010 2:00 pm

Re: Why the forum doesn't use https?

Postby rainland » Wed Apr 19, 2017 12:30 pm

Granger wrote:
rainland wrote:Current setup is just irresponsible and bad practice imo.

That is what the ones that want to sell certificates say, hoping for you to fall for it and pressure you site operator to pay up - basically it's a scheme to turn you into an unpaid mob enforcer for them. Given your post it seems to work :(

More details about this particular scam here.

What do you mean? Let's encrypt doesn't cost anything

EDIT: Sorry I think you misunderstood me. The bad practice I was referring to is the fact to not enable https by default. This leaves majority of the userbase logging in with plain http!
IMHO using the self-signed certificate is a bit meh because you can get them from trusted CA:s for free now.
User avatar
rainland
 
Posts: 47
Joined: Sun Jun 10, 2012 9:40 am

Re: Why the forum doesn't use https?

Postby Granger » Wed Apr 19, 2017 1:22 pm

rainland wrote:
Granger wrote:
rainland wrote:Current setup is just irresponsible and bad practice imo.

That is what the ones that want to sell certificates say, hoping for you to fall for it and pressure you site operator to pay up - basically it's a scheme to turn you into an unpaid mob enforcer for them. Given your post it seems to work :(

More details about this particular scam here.

What do you mean? Let's encrypt doesn't cost anything

Let's encrypt isn't the reason for the browser warning, but a recent reaction from a community that was fed up by such shit.
Some argue that using it is effectively just supporting the certificate scam, having the browsers featuring sites with higher paid certificates in more elaborate ways in their UI might be an indication toward this theory.

I'm quite confident that Loftar is aware of it, so my guess is that there are $reasons why it hasn't happened (yet).

A reasonable way to deal with the inherent flaws of the current certificate system would be DANE to have the cert delivered by the DNS which in itself is cryptologically secured against any tempering, afaik there is a smallish movement toward this but as the big browsers don't support it out of the box...
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9254
Joined: Mon Mar 22, 2010 2:00 pm

Re: Why the forum doesn't use https?

Postby rainland » Wed Apr 19, 2017 3:12 pm

Thanks for the reply.
Granger wrote:I'm quite confident that Loftar is aware of it

Yeah, he must be. I made this thread hoping to catch his attention and get him to answer to me.
I hope I haven't appeared to be too hostile :?
User avatar
rainland
 
Posts: 47
Joined: Sun Jun 10, 2012 9:40 am


Return to Critique & Ideas

Who is online

Users browsing this forum: Claude [Bot] and 77 guests