Unconfigured Ad Widget

Collapse

No HTTPS?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • freebug
    Senior Member
    • Jun 2012
    • 596

    No HTTPS?

    How come Calguns can't move to HTTPS especially for sign in and sign out? I get all sorts of browser warning that this site isn't secure (which it isn't).
    - 80% AR Fan
    - 300BLK all the way
  • #2
    SkyHawk
    I need a LIFE!!
    • Sep 2012
    • 23495

    They have a CA signed cert.

    Bookmark this - always use it to start your session.


    Be advised that youtube embeds wont work on some browsers if you are using calguns via SSL.
    Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

    Comment

    • #3
      Picturepro
      Senior Member
      • Feb 2014
      • 518

      why would you want or not want the https?

      I have both open and do not see a difference

      Comment

      • #4
        SkyHawk
        I need a LIFE!!
        • Sep 2012
        • 23495

        Originally posted by Picturepro
        why would you want or not want the https?

        I have both open and do not see a difference
        IMO, no good reason to use https here unless you are conspiring to commit crimes via PM or sharing credit card or banking info via Pm, or you reuse your calguns password on your online banks accounts.

        Everything you post here other than PM is public, and hackers dont get passwords very often from packet sniffing. They use keystroke loggers or they go for unsalted password databases. A browser is never going to warn you of a real hack on your information. Transport encryption is sort of low on the totem pole when it comes to security, and it's importance is over-hyped.

        The bigger question is, is your info encrypted at rest here (almost certainly not, save for your pwd which may or may not be properly salted). It is far easier to attack a stationary target than one in transport, and you have no control over how your info is stored at the far end nor any knowledge. And so many people have keystroke loggers and screen scrapers on their own machines but have no idea.

        A browser SSL warning or non-warning is a shiny penny; just because you see a green url bar tells you very, very little about your security on that site.

        But if you have more tinfoil than you know what to do with, fold up a hat and use the https calguns, and tell yourself you are smart and secure. Repeat regularly while staring into a mirror...

        Last edited by SkyHawk; 04-18-2017, 11:41 AM.
        Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

        Comment

        • #5
          SkyHawk
          I need a LIFE!!
          • Sep 2012
          • 23495

          Originally posted by bool1tholz
          If you use public WiFi https can help reduce the amount of some vectors of attack from less skilled attackers.

          For example... Not using https may make you more vulnerable to "side jacking" where someone steals the cookies in your request and replays it to impersonate you.
          The only problem with using public wi-fi is most folks have no idea if they are connecting to a hackers wi-fi, in which case SSL will not always help you. You do know there are proxies that can decrypt/recrypt SSL while sitting in the middle? And unless you know exactly what to do when presented with a certificate warning (most people do not), then it is not so helpful. And the hacker will try and get you to install his cert on the 'welcome to public wi-fi' redirect page when you connect.


          When you enable SSL decryption for your end users, SSL-encrypted traffic is decrypted, inspected, and then re-encrypted before it is sent to its destination.
          I guess there are people still using Firesheep to grab un-encrypted cookies but sophisticated hackers have moved on to man in the middle decrypt/recrypt.

          Yes Public wi-fi is ripe for shenanigans, but it starts with you connecting to public wi-fi. Once you are a client on a hackers network all bets are off. The best play on public wifi is to be very wary, expect that you are transmitting in the clear and act accordingly.

          I never, ever connect my laptop to public wifi. I will occasionally connect IPad to pub wifi, but not typically because I carry my own cellular hotspot.
          Last edited by SkyHawk; 04-18-2017, 12:02 PM.
          Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

          Comment

          • #6
            SkyHawk
            I need a LIFE!!
            • Sep 2012
            • 23495

            I agree with you, https is an absolute must on pub wifi - especially shopping or banking. Just don't trick yourself into thinking it is the end all solution, and if possible avoid those activities on pub wifi.

            And in any case, even on public wifi I am not concerned about using Calguns in the clear - seriously, not at all. No more concerned than I would be logging into candycrush in the clear. If you have sensitive information stored or you are sharing sensitive info on an internet discussion forum, or re-using your Morgan Stanley password on Calguns, you're doing it wrong. Nothing will save you.
            Last edited by SkyHawk; 04-18-2017, 12:33 PM.
            Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

            Comment

            • #7
              Picturepro
              Senior Member
              • Feb 2014
              • 518

              awesome thanks guy

              Comment

              Working...
              UA-8071174-1