Knuckle Cracker

Knuckle Cracker => Support => Topic started by: 12345ieee on March 11, 2017, 03:05:06 PM

Title: HTTP(S) woes
Post by: 12345ieee on March 11, 2017, 03:05:06 PM
Browsers are getting more and more paranoid these days (and people less and less, but this is another story) about unsecure online logins.
In particular Firefox 52.0, fresh from beta, started complaining about the forum login form, that is under http.

While I don't really care about the password I use here, it'd be nice to silence it.
I see you have a valid certificate for knucklecracker.com, the forum sort of works in https at the moment, but you serve images via http, but I hope it is fixable before browsers get even more paranoid by default.
Title: Re: HTTP(S) woes
Post by: Sorrontis on March 11, 2017, 03:29:42 PM
I know it's trying to say something, but I just don't understand.
Title: Re: HTTP(S) woes
Post by: 12345ieee on March 11, 2017, 05:19:40 PM
I'm sorry, it's Saturday and I didn't feel like filling a IT-ticket-like report.

----------------------

Dear maintainer,

I've noticed the knucklecracker forum  ( knucklecracker.com/forums ) login form is using an insecure http connection.
This was already known to me, and not a great bother, but a recent version of the Firefox web browser (52.0, Linux) has started complaining about such insecure forms.

Please migrate to a secure (https) connection.

Thanks
12345ieee

--------------------

Better?
Title: Re: HTTP(S) woes
Post by: Johnny Haywire on March 11, 2017, 10:17:09 PM
Or you COULD say...

My dear maintainer bloke,
Your forum form is broke.
Firefox awoke
"Unsafe!" it spoke;
It did my angst provoke.

I mean, you don't HAVE to say that but you COULD. Just sayin'.


Title: Re: HTTP(S) woes
Post by: Michionlion on March 12, 2017, 12:25:07 AM
I'm just going to come out of lurking to say good job on that, Johnny. Back to lurking...
Title: Re: HTTP(S) woes
Post by: knucracker on March 12, 2017, 11:55:31 AM
Looks like SMF might be addressing some of these issues in the upcoming 2.0.14 version. You can come close by just accessing https://knucklecracker.com/forums.  But as you say, images are mixed content so in firefox you still get a little unlocked icon up at the top.  We'll see what 2.0.14 does once it is released.
Title: Re: HTTP(S) woes
Post by: Johnny Haywire on March 12, 2017, 05:13:09 PM
Quote from: Michionlion on March 12, 2017, 12:25:07 AM
I'm just going to come out of lurking to say good job on that, Johnny. Back to lurking...

Heh heh, thanks m8!  ;D
Title: Re: HTTP(S) woes
Post by: Stickman on March 12, 2017, 05:45:37 PM
Quote from: Johnny Haywire on March 11, 2017, 10:17:09 PM
Or you COULD say...

My dear maintainer bloke,
Your forum form is broke.
Firefox awoke
"Unsafe!" it spoke;
It did my angst provoke.

I mean, you don't HAVE to say that but you COULD. Just sayin'.

That feels like almost a limerick.

There was a fine fellow from Italy
Whose FireFox acted quite jittery
So he asked the admin
To put some security in
So he wouldn't browse forum so bitterly
Title: Re: HTTP(S) woes
Post by: 12345ieee on March 13, 2017, 04:10:03 AM
From now on I'm posting all my bug reports here and have them converted in poetry before submitting.

Quote from: virgilw on March 12, 2017, 11:55:31 AM
Looks like SMF might be addressing some of these issues in the upcoming 2.0.14 version. You can come close by just accessing https://knucklecracker.com/forums.  But as you say, images are mixed content so in firefox you still get a little unlocked icon up at the top.  We'll see what 2.0.14 does once it is released.

Thanks V, let's see.
Title: Re: HTTP(S) woes
Post by: 12345ieee on June 05, 2017, 03:35:18 AM
SMF 2.0.14 has just been released: https://www.simplemachines.org/community/index.php?topic=553855.0

The changelog says 'Added HTTPS', so it should fix the reported problem.
Title: Re: HTTP(S) woes
Post by: Builder17 on June 05, 2017, 04:06:54 AM
Forum logo and michelion's avatar are http in this topic, it seems