Connection unsafe?

For Issues, Ideas, or Subjects That Do Not Fit Elsewhere

Moderators: Moderator, DM

Post Reply
chad878262
QC Coordinator
Posts: 9333
Joined: Thu Sep 18, 2014 6:55 pm

Connection unsafe?

Unread post by chad878262 »

Just about 30 minutes ago I started getting notification that my connection is unsafe when going to bgtscc... The bar says "! Not Secure" and the https has a diagonal slash through it.
Chord Silverstrings - Bard and OSR Squire / Tarent Nefzen - Arcane Wand Merchant and Master Alchemist / Irrace Arkentlar - Drow Adventurer / Finneaus Du'Veil - Gem Merchant and Executive Officer of SCCE

Tarent's Wands and Elixirs

A Wand Crafter's guide to using wands
User avatar
mrm3ntalist
Retired Staff
Posts: 7746
Joined: Wed Feb 29, 2012 5:31 pm
Location: US of A

Re: Connection unsafe?

Unread post by mrm3ntalist »

Me too. Already reported this to the admins and janniez. It looks like a certificate expired and that there is no real issue
Mendel - Villi of En Dharasha Everae | Nikos Berenicus - Initiate of the Mirari | Efialtes Rodius - Blood Magus | Olaf Garaeif - Dwarven Slayer

Spelling mistakes are purposely entered for your entertainment! ChatGPT "ruined" the fun :(
User avatar
Akroma666
Posts: 1888
Joined: Mon Jan 16, 2012 2:24 pm
Location: California

Re: Connection unsafe?

Unread post by Akroma666 »

Super annoying on a mobile.. pops up every time you navigate
Storm - The Blade Flurry
Druegar Grizzleclaw - The Mountain Ruin Tsar
Akroma Thuul - The Creepy Enchanter
Liliana Duskblade - The B*tch of Bane
Jamie Dawnbringer - The Light in the Darkness
User avatar
mrm3ntalist
Retired Staff
Posts: 7746
Joined: Wed Feb 29, 2012 5:31 pm
Location: US of A

Re: Connection unsafe?

Unread post by mrm3ntalist »

Zanniej is looking into it. Lets wait and hear from the man.
Mendel - Villi of En Dharasha Everae | Nikos Berenicus - Initiate of the Mirari | Efialtes Rodius - Blood Magus | Olaf Garaeif - Dwarven Slayer

Spelling mistakes are purposely entered for your entertainment! ChatGPT "ruined" the fun :(
User avatar
Calodan
Posts: 2032
Joined: Fri Apr 19, 2013 12:21 pm
Location: Missoula Montana BIG SKY COUNTRY

Re: Connection unsafe?

Unread post by Calodan »

mrm3ntalist wrote:Zanniej is looking into it. Lets wait and hear from the man.
Instant gratification world! WE WANTS OUR FIX NOWZ!!!! :lol:
Kory Sentinel
"We should take the army head on!"

"... it sounds like a terrible idea, but look at that smile."
"And he just sounds so confident ... he is a favored soul."
"Even if we don't survive, he will, and isn't that what matters?" -Red Lancer
User avatar
Maecius
Retired Admin
Posts: 11639
Joined: Sat May 16, 2009 4:24 pm

Re: Connection unsafe?

Unread post by Maecius »

Zanniej thought we'd renewed our security certificate, but we missed a step. He's going to be fixing it for us here soon (probably early tomorrow morning).

It should be safe in the sense that we don't have sensitive banking information or anything like that to steal here, but the warnings will keep showing until it's fixed.
User avatar
Omega07
Recognized Donor
Posts: 58
Joined: Wed May 10, 2017 11:05 pm

Re: Connection unsafe?

Unread post by Omega07 »

Just when I got paid from work and was gonna donate too! Haha.

Is Skynet attacking us?

Glad I'm not the only one to see this.

..

Image
"You remind me of myself...before I was slaughtered and cast into the Abyss."
Playername: TheGracefulOne (Old Account Since 2015)
User avatar
K'yon Oblodra
Recognized Donor
Posts: 1009
Joined: Wed Oct 28, 2009 3:38 am
Location: Berlin

Re: Connection unsafe?

Unread post by K'yon Oblodra »

The certificate has nothing to do with security really... It only marks the site as secure because they buy the certificate... Making money with this is all that's behind it... After all people get scared of they get the not secure message despite the site not working any different is really just the certificate that run out which does nothing but tell the browser: "this is a secure site"....
K'yon Oblodra
Necromancer of the school of Necromancy
Silent seat for the school of Necromancy
User avatar
Aspect of Sorrow
Custom Content
Posts: 2648
Joined: Fri Mar 28, 2014 7:11 pm
Location: Reliquary

Re: Connection unsafe?

Unread post by Aspect of Sorrow »

Swing and a miss. The transport layer negotiates the means of encryption the browser and Web server will communicate with a basis of the CA which it hinges on for authorization to ensure it is whom the recipient states it is. Run Wireshark and compare the readability of http POST vs https payloads.

If I were nefarious, a MitM attack would mean that someone on this forum probably uses the same log in password they would've used for their email account, which bypasses the one way hash that phpBB performs for the sake of not containing plaintext. HTTPS mitigates that.

We are still using the HTTPS encryption. The browser is just warning the user that yhe certificate used is not what a reliable third party can confirm.

For what it's worth, you can obtain free SSL CA from places like Let's Encrypt. Can't be a money grabbing scheme there.
User avatar
Zanniej
Posts: 2454
Joined: Sat Jan 11, 2014 11:28 am
Location: The dark parts of the forum

Re: Connection unsafe?

Unread post by Zanniej »

Sorry guys, it's fixed again.
I messed up the last step of renewing our certificate on tuesday. It should normally just pick up the new cert when the old one expires, which was yesterday, but since I missed a step, it didn't.

No real biggy, just pretty annoying :) So once again, sorry
Off to greener pastures
User avatar
Tsidkenu
Posts: 3962
Joined: Tue May 27, 2014 12:04 am
Location: Terra Nullis

Re: Connection unsafe?

Unread post by Tsidkenu »

Aspect of Sorrow wrote:*snip*
Image
User avatar
Zanniej
Posts: 2454
Joined: Sat Jan 11, 2014 11:28 am
Location: The dark parts of the forum

Re: Connection unsafe?

Unread post by Zanniej »

Tsidkenu wrote:
Aspect of Sorrow wrote:*snip*
Image
The latter ;-)
Though I must admit I must quite often read AoS' remarks (at least) twice to understand, and it's my area of expertise :lol:

But, in an effort to perhaps make it a bit more understandable:
The certificate tells you that the website is indeed who it claims to be. The HTTPS encrypts your connection. In short, that means that where you would first log in without HTTPS, you would send your username and password in plain text. This means that if someone manages to intercept your connection (by insecure WiFi for example), they'll be able to read your username and password. This is a Man-in-the-Middle (MitM) attack.
With HTTPS however, you first connect to the website, which creates a secured connection between you and the website. You both get an encryption code with which you can encode and decode your message. That way, the "Man-in-the-Middle" would only see gibberish, which is only readable if you have the key to decode it.

The above is in very short how it works, though I might've given a bit of a too short explanation here and there. So don't go using this information to pretend you know it all, as I don't know it all either :-P
Should you wish to know more in depth about such things, I recommend asking AoS, as he's more knowledgable in it than I am, I think.
Off to greener pastures
User avatar
K'yon Oblodra
Recognized Donor
Posts: 1009
Joined: Wed Oct 28, 2009 3:38 am
Location: Berlin

Re: Connection unsafe?

Unread post by K'yon Oblodra »

And overall the connection would still be safe even without the certificate only that your browser wouldn't be able to tell you if it is or not...
K'yon Oblodra
Necromancer of the school of Necromancy
Silent seat for the school of Necromancy
Post Reply

Return to “General Discussion”