You are not logged in.

#126 2010-08-13 01:03:26

MkFly
Member
From: Mars
Registered: 2009-12-10
Posts: 141

Re: This bbs now uses https exclusively

I see the certificate has changed ... very nice.  The Arch SSL went from 'F' to 'A' overnight on Qualys' SSL Labs Server Test:
https://www.ssllabs.com/ssldb/analyze.h … hlinux.org

Offline

#127 2010-08-13 01:53:20

sand_man
Member
From: Australia
Registered: 2008-06-10
Posts: 2,164

Re: This bbs now uses https exclusively

What was causing the low score previously?


neutral

Offline

#128 2010-08-13 02:07:24

anonymous_user
Member
Registered: 2009-08-28
Posts: 3,059

Re: This bbs now uses https exclusively

So will we have to download a new certificate for this? What about for non-Arch supplied browsers?

Offline

#129 2010-08-13 06:01:04

Pierre
Developer
From: Bonn
Registered: 2004-07-05
Posts: 1,964
Website

Re: This bbs now uses https exclusively

No you don't need to do anything as the new cert is included in virtually all browsers and operating systems.

Offline

#130 2010-08-18 13:29:49

kbrosnan
Member
Registered: 2010-08-18
Posts: 8

Re: This bbs now uses https exclusively

sand_man wrote:

What was causing the low score previously?

Using an untrusted CA, https://www.ssllabs.com/ssldb/analyze.html?d=cacert.org

Offline

#131 2010-08-18 15:39:47

bobdob
Member
Registered: 2008-06-13
Posts: 138

Re: This bbs now uses https exclusively

After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?

Offline

#132 2010-08-20 14:09:01

angvp
Forum Fellow
From: Buenos Aires, Argentina
Registered: 2008-05-15
Posts: 32
Website

Re: This bbs now uses https exclusively

I think that there is a re-locator rule for conserving the old links (301) tongue

Offline

#133 2010-09-26 05:51:44

adamlau
Member
Registered: 2009-01-30
Posts: 418

Re: This bbs now uses https exclusively

HTTPS bites! My mobile newsreader (FreeRange Reader) cannot load the HTTPS forums and bugtracker feeds sad .


Arch Linux + sway
Debian Testing + GNOME/sway
NetBSD 64-bit + Xfce

Offline

#134 2010-09-27 23:34:12

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: This bbs now uses https exclusively

adamlau wrote:

HTTPS bites! My mobile newsreader (FreeRange Reader) cannot load the HTTPS forums and bugtracker feeds sad .

You could probably use a yahoo pipes thing to convert the https feed to an http feed.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#135 2010-09-28 00:03:12

chris-kun
Member
From: SF Bay Area
Registered: 2010-09-07
Posts: 235
Website

Re: This bbs now uses https exclusively

what's the point in using https exclusively?


[home page] -- [code / configs]

"Once you go Arch, you must remain there for life or else Allan will track you down and break you." -- Bregol

Offline

#136 2010-09-28 08:33:54

itman
Member
From: Switzerland
Registered: 2010-05-21
Posts: 124

Re: This bbs now uses https exclusively

bobdob wrote:

After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?

By homepage you're referring to  http://home.archlinux.ca/? I've mailed to the author with the request to change it to https, but didn't get any answer.

Offline

#137 2010-09-28 12:23:53

mrunion
Member
From: Jonesborough, TN
Registered: 2007-01-26
Posts: 1,938
Website

Re: This bbs now uses https exclusively

chris-kun wrote:

what's the point in using https exclusively?

Agreed. Seems like we could at least have a choice of whether we wanted https or http. I don't mind manually removing the 's' myself either.


Matt

"It is very difficult to educate the educated."

Offline

#138 2010-09-28 13:02:01

karol
Archivist
Registered: 2009-05-06
Posts: 25,440

Re: This bbs now uses https exclusively

itman wrote:
bobdob wrote:

After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?

By homepage you're referring to  http://home.archlinux.ca/? I've mailed to the author with the request to change it to https, but didn't get any answer.

Homepage http://www.archlinux.org/

Offline

#139 2010-10-27 06:29:52

Ledti
Member
Registered: 2010-07-31
Posts: 122
Website

Re: This bbs now uses https exclusively

http://codebutler.com/firesheep-a-day-later is relevant to this discussion.

Arch has good timing. t_t

Offline

#140 2010-10-27 07:27:01

litemotiv
Forum Fellow
Registered: 2008-08-01
Posts: 5,026

Re: This bbs now uses https exclusively

Ledti wrote:

http://codebutler.com/firesheep-a-day-later is relevant to this discussion.

Arch has good timing. t_t

I was just thinking about that. tongue


ᶘ ᵒᴥᵒᶅ

Offline

#141 2010-10-27 14:45:33

Kosmonavt
Member
Registered: 2010-02-15
Posts: 100

Re: This bbs now uses https exclusively

When talking about AUR, it's all right (nobody wants to compile unknown-whatever). But using it for forum IS ridiculous. Of course, session hijacking can occur, but what will be lost if some messages in a thread about latest screenshots would be corrupted. Looks like nothing.

Also, real alternative is not "SSL Everywhere", but using IPv6 globally, since it has built-in, enabled-by-default IPsec. THEN it will be nice and truly secured. Sadly, it isn't near future.

Offline

#142 2010-10-28 23:26:48

655321
Member
From: Costa Rica
Registered: 2009-12-08
Posts: 412
Website

Re: This bbs now uses https exclusively

I enter everyday to the forums via blackberry browser, and every single time the browser asks me if I trust the certificate and accept, I have to do this everytime I enter a forums page, so annoying...other secure sites work perfectly, can you guys look into this?

Opera mini wont even let me log in to the forums, claims the password is wrong even though it isn't.

Bolt browser has the same problem than the native Blackberry browser.

hope you guys can help.

cheers


Linux user #498977
With microsoft you get windows and gates, with linux you get the whole house!
My Blog about ArchLinux and other stuff

Offline

#143 2010-10-30 21:44:18

atordo
Member
Registered: 2007-04-21
Posts: 147

Re: This bbs now uses https exclusively

Xyne wrote:

Even if you are not concerned about privacy, there is still no reason to be against it.

* concrete example and a potential taste of things to come: direct insertion of data into your data stream for marketing purposes

Interesting and scary link you posted there. Even though I think my info in this site is mostly irrelevant, the important thing is that somebody cared enough to do something and actually did it. This is more than most of us do, so I welcome the change to https even if it carries some minor annoyances.

Offline

Board footer

Powered by FluxBB