You are not logged in.
I see the certificate has changed ... very nice. The Arch SSL went from 'F' to 'A' overnight on Qualys' SSL Labs Server Test:
https://www.ssllabs.com/ssldb/analyze.h … hlinux.org
Offline
What was causing the low score previously?
Offline
So will we have to download a new certificate for this? What about for non-Arch supplied browsers?
Offline
No you don't need to do anything as the new cert is included in virtually all browsers and operating systems.
Offline
What was causing the low score previously?
Using an untrusted CA, https://www.ssllabs.com/ssldb/analyze.html?d=cacert.org
Offline
After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?
Offline
HTTPS bites! My mobile newsreader (FreeRange Reader) cannot load the HTTPS forums and bugtracker feeds .
Arch Linux + sway
Debian Testing + GNOME/sway
NetBSD 64-bit + Xfce
Offline
HTTPS bites! My mobile newsreader (FreeRange Reader) cannot load the HTTPS forums and bugtracker feeds .
You could probably use a yahoo pipes thing to convert the https feed to an http feed.
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
what's the point in using https exclusively?
[home page] -- [code / configs]
"Once you go Arch, you must remain there for life or else Allan will track you down and break you." -- Bregol
Offline
After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?
By homepage you're referring to http://home.archlinux.ca/? I've mailed to the author with the request to change it to https, but didn't get any answer.
Offline
what's the point in using https exclusively?
Agreed. Seems like we could at least have a choice of whether we wanted https or http. I don't mind manually removing the 's' myself either.
Matt
"It is very difficult to educate the educated."
Offline
bobdob wrote:After a combination of firefox 4.0b4 and adblock broke redirects, I noticed that the forum link on the home page points to http:// instead of https://.
Did this never get changed or is it supposed to be like that?By homepage you're referring to http://home.archlinux.ca/? I've mailed to the author with the request to change it to https, but didn't get any answer.
Homepage http://www.archlinux.org/
Offline
http://codebutler.com/firesheep-a-day-later is relevant to this discussion.
Arch has good timing. t_t
Offline
http://codebutler.com/firesheep-a-day-later is relevant to this discussion.
Arch has good timing. t_t
I was just thinking about that.
ᶘ ᵒᴥᵒᶅ
Offline
When talking about AUR, it's all right (nobody wants to compile unknown-whatever). But using it for forum IS ridiculous. Of course, session hijacking can occur, but what will be lost if some messages in a thread about latest screenshots would be corrupted. Looks like nothing.
Also, real alternative is not "SSL Everywhere", but using IPv6 globally, since it has built-in, enabled-by-default IPsec. THEN it will be nice and truly secured. Sadly, it isn't near future.
Offline
I enter everyday to the forums via blackberry browser, and every single time the browser asks me if I trust the certificate and accept, I have to do this everytime I enter a forums page, so annoying...other secure sites work perfectly, can you guys look into this?
Opera mini wont even let me log in to the forums, claims the password is wrong even though it isn't.
Bolt browser has the same problem than the native Blackberry browser.
hope you guys can help.
cheers
Linux user #498977
With microsoft you get windows and gates, with linux you get the whole house!
My Blog about ArchLinux and other stuff
Offline
Even if you are not concerned about privacy, there is still no reason to be against it.
Interesting and scary link you posted there. Even though I think my info in this site is mostly irrelevant, the important thing is that somebody cared enough to do something and actually did it. This is more than most of us do, so I welcome the change to https even if it carries some minor annoyances.
Offline