chrome to start naming and shaming

A place For General Chit Chat Etc
User avatar
psyolent
Posts: 1595
Joined: Tue Apr 26, 2011 9:52 pm
cars: VT Berlina Series 2 Wago
XP Falcon ex Geelong Taxi
SY Ford Territory
PD Hyundai nLine
SE Ford Capri
....too many fucking bikes

chrome to start naming and shaming

Post by psyolent »

fyi dudes

http://www.itnews.com.au/news/chrome-to ... tes-436765

in essence all non https sites will be flagged as being, well, not secured.

don't 'password' share your password with other sites, as, if the site is HTTP only, then, passwords are sent in plain text.

admins, any thoughts to a SSL cert for our fine site? happy to donate to make it possible. just say when.
Cheers,
Greg aka Sir Burnie Tanington

VX1 Berlina V6, VT1 Berlina V6 (Track), VN1 S V6, Hilux RN105 GMV8, Ford XP 170.
User avatar
antus
Site Admin
Posts: 9017
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: chrome to start naming and shaming

Post by antus »

We have had one for some time. Ive just been reluctant to force https as it could break someone somewhere. Untill i flick the forum switch some images etc remain http so right now you might see a mixed content warning. Trivial to lock it in properly though. Feel free to use it :) Maybe this is just the reason to start forcing it.

https://pcmhacking.net/forums/

It should score highly here too:
https://www.ssllabs.com/ssltest/analyze ... net&latest

Click the hosts once its run to see the details.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
Dylan
Posts: 3364
Joined: Mon Aug 02, 2010 6:35 pm
cars: VR Commodore V8

Re: chrome to start naming and shaming

Post by Dylan »

New bookmark saved.
User avatar
psyolent
Posts: 1595
Joined: Tue Apr 26, 2011 9:52 pm
cars: VT Berlina Series 2 Wago
XP Falcon ex Geelong Taxi
SY Ford Territory
PD Hyundai nLine
SE Ford Capri
....too many fucking bikes

Re: chrome to start naming and shaming

Post by psyolent »

good stuff antus.
it will sook over the non HTTPS stuff until you get that action solved mate, and all that HSTS shit.
as i mentioned b4 alot of people share their welcome1 passwords across sites and ; given the pwnedlists which are coming out these days every user almost needs to have a full blown password manager .....
Cheers,
Greg aka Sir Burnie Tanington

VX1 Berlina V6, VT1 Berlina V6 (Track), VN1 S V6, Hilux RN105 GMV8, Ford XP 170.
User avatar
antus
Site Admin
Posts: 9017
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: chrome to start naming and shaming

Post by antus »

Well, what do you know. Its was only the ipv6 logo at the bottom that was hard coded http (and didnt have a secure https server backing it). I moved the image over locally and that has resolved the mixed content warning. I dont think HSTS is a problem, and the apache build is too old to support it. Its fine for now and the next few years.

I wonder if I should force https though? Cant be a bad thing right? If anyone still wants to use the forum on android 2.x or internet explorer 6, or internet explorer 8 on windows XP speak now.... you're the folks who will have problems.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
j_ds_au
Posts: 387
Joined: Sun Jan 25, 2015 4:21 pm
Location: Sydney

Re: chrome to start naming and shaming

Post by j_ds_au »

Only the login need/should be SSL/TLS.

As for Chrome, couldn't care less ...

Joe.
User avatar
antus
Site Admin
Posts: 9017
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: chrome to start naming and shaming

Post by antus »

Well ive forced the whole site https (I dont have the time or care to find and add hooks for the various bits of login). Lets see what happens. Now the mixed content thing is solved it should work pretty well.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Tazzi
Posts: 3552
Joined: Thu May 17, 2012 8:53 pm
cars: VE SS Ute
Location: WA
Contact:

Re: chrome to start naming and shaming

Post by Tazzi »

antus wrote:Well ive forced the whole site https (I dont have the time or care to find and add hooks for the various bits of login). Lets see what happens. Now the mixed content thing is solved it should work pretty well.
Was the first thing I noticed.. bright green https up in the top corner!. Seems to be working hunky dorey :thumbup:
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
immortality
Posts: 3676
Joined: Thu Apr 09, 2009 12:31 pm
cars: VH, VN, VS, VX

Re: chrome to start naming and shaming

Post by immortality »

Working here for me.
User avatar
psyolent
Posts: 1595
Joined: Tue Apr 26, 2011 9:52 pm
cars: VT Berlina Series 2 Wago
XP Falcon ex Geelong Taxi
SY Ford Territory
PD Hyundai nLine
SE Ford Capri
....too many fucking bikes

Re: chrome to start naming and shaming

Post by psyolent »

Only the login need/should be SSL/TLS.
no, not really buddy, the whole shebang does, as, traffic can be intercepted (read hijacked) with mixed content ....
working all AOK here antus - good work. note the MITM web gateway has injected its cert in place of yours so it can inspect ; and ; it still works. no ssl bypass for me :)
Cheers,
Greg aka Sir Burnie Tanington

VX1 Berlina V6, VT1 Berlina V6 (Track), VN1 S V6, Hilux RN105 GMV8, Ford XP 170.
Post Reply