Query failed: connection to localhost:9312 failed (errno=111, msg=Connection refused). Site unsecure at login warning ? - Help & Feedback Discussions on The Fretboard
UNPLANNED DOWNTIME: 12th Oct 23:45

Site unsecure at login warning ?

What's Hot
AliGorieAliGorie Frets: 308
edited March 2017 in Help & Feedback
using Firefox on a Mac / Sierra I'm getting this warning @ password login - ?
described here -
https://support.mozilla.org/t5/Protect-your-privacy/Insecure-password-warning-in-Firefox/ta-p/27861
0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
«1

Comments

  • TTonyTTony Frets: 26143
    Slightly further down the page that you linked ...

    About insecure pages

    Pages that need to transmit private information, such as credit cards, personal information and passwords, need to have a secure connection to help prevent attackers from stealing your information. (Tip: A secure connection will have "HTTPS" in the address bar, along with a green lock icon.)

    Pages that don’t transmit any private information can have an unencrypted connection (HTTP). It is not advised to enter private information, such as passwords, on a web page that shows HTTP in the address bar. The information you enter can be stolen over this insecure connection.

    Having trouble posting images here?  This might help.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • AliGorieAliGorie Frets: 308
    thanks TT
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • robinbowesrobinbowes Frets: 2922
    And you're submitting passwords over http, aren't you? I've brought this up before. Should really switch to https.
    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom · Share on Twitter
  • monquixotemonquixote Frets: 17108
    tFB Trader
    Yep but the http linked images all over the site would trigger warnings all over the place unfortunately
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • robinbowesrobinbowes Frets: 2922
    Insist on https links. Better that warning than passwords over http, IMHO.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • monquixotemonquixote Frets: 17108
    tFB Trader
    Insist on https links. Better that warning than passwords over http, IMHO.
    Unfortunately we need a time machine to fix that several years ago when the forum started.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • digitalscreamdigitalscream Frets: 25239
    Insist on https links. Better that warning than passwords over http, IMHO.
    Yep. Broken Javascript, broken image links everywhere...that's much preferable to having a functional site.

    We've been here before ;)
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • robinbowesrobinbowes Frets: 2922
    Bah.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • Surely... if the site is insecure... it just needs a few kind words of reassurance. Something to help boost its self esteem.
    4reaction image LOL 0reaction image Wow! 2reaction image Wisdom · Share on Twitter
  • crunchmancrunchman Frets: 10961
    Just changed my password.  My old password was used for some other sites.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • Yes, I'm aware.

    If you'd be so kind as to tell me which bits of the site to switch off in order to make it happen, it would be ever so helpful. I'm sure everyone can live without the text editor and just type HTML in the box, right?
    <space for hire>
    1reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • Gosh, you're right. There are absolutely no working sites on the internet right now that have text editors. ;)
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • digitalscreamdigitalscream Frets: 25239
    edited February 2018
    Gosh, you're right. There are absolutely no working sites on the internet right now that have text editors.
    Don't be a dick. *This* website, with its reliance on plugins which are coded by PHP monkeys rather than experts, relies on an editor which doesn't currently work with HTTPS. In fact, none of the editor plugins do except the stock one, which is broken in just about every other way.

    I mean...I could just take the site down for a year or so while I rewrite everything properly. Do you think that would be useful to anyone?
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • So what is your plan? You can't just ignore it. It's not going to go away. It will all stop working some day soon. Then what?
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • So what is your plan? You can't just ignore it. It's not going to go away. It will all stop working some day soon. Then what?
    I was actually just thinking of switching over to HTTPS and putting your email address on the front of the site for support queries, since you seem to think it's so simple :P

    As I've said every single other time that you've brought it up, I'm working on it. It's nowhere near as simple as you appear to think it is, and this site is not the focus of my entire life. Therefore...it'll happen when it's done and working.
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • m_cm_c Frets: 1128
    This argument was had on another forum I visit occasionally, and as somebody summed it up, what are hackers going to gain from hacking your forum account?
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • m_c said:
    This argument was had on another forum I visit occasionally, and as somebody summed it up, what are hackers going to gain from hacking your forum account?
    To be fair, most people use the same password everywhere - and thus if somebody manages to get a sniffer between you and the server, they can gain access to your other accounts. However, there are so many moving parts involved in doing so that it makes such attacks extremely effort-intensive for not a lot of gain; you can't harvest many passwords in a reasonable time frame that way, and it's usually more "sensible" to go straight for vulnerabilities in the server (or its software) itself.

    As I said, this is not something I'm ignoring, I'm just fighting against a lot of extremely poorly-developed third-party code to try to make it work.
    <space for hire>
    0reaction image LOL 1reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • m_c said:
    This argument was had on another forum I visit occasionally, and as somebody summed it up, what are hackers going to gain from hacking your forum account?
    That's not particularly the point.

    The issue is that at some stage relatively soon, browsers are going to stop working with http altogether.

    R.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • So what is your plan? You can't just ignore it. It's not going to go away. It will all stop working some day soon. Then what?
    I was actually just thinking of switching over to HTTPS and putting your email address on the front of the site for support queries, since you seem to think it's so simple :P

    As I've said every single other time that you've brought it up, I'm working on it. It's nowhere near as simple as you appear to think it is, and this site is not the focus of my entire life. Therefore...it'll happen when it's done and working.
    Happy to help, if I can.

    R.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter

  • The issue is that at some stage relatively soon, browsers are going to stop working with http altogether.
    They won't, for many many reasons. Certainly not before another secure-only protocol replaces HTTP/HTTPS.
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • PVO_DavePVO_Dave Frets: 2324
    Any appetite to change to a different forum platform @digitalscream ? Might make it easier for you in the long run, does seem (from reading some of your posts) like you have to do a fair bit of manual work to get stuff working with Vanilla. 

    Might be worth considering? (as long as it's not VBulletin!) Not that the https thing bothers me btw
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • digitalscreamdigitalscream Frets: 25239
    PVO_Dave said:
    Any appetite to change to a different forum platform @digitalscream ? Might make it easier for you in the long run, does seem (from reading some of your posts) like you have to do a fair bit of manual work to get stuff working with Vanilla. 

    Might be worth considering? (as long as it's not VBulletin!) Not that the https thing bothers me btw
    None of the available platforms are problem-free. My plan - which I'm also working on as we go - is to replicate the back-end in API form using Rails, which will feed into other development that we need to complete in order to meet our overall goals of turning this into more-than-just-a-forum.

    Once I've rebuilt the data structures and logic in a more sensible (and scalable) form, it opens up the possibility of using much better (and more modern) front-end libraries to solve all of these problems.
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • PVO_DavePVO_Dave Frets: 2324
    Headless forum! :)
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • FunkfingersFunkfingers Frets: 13312
    All those in favour of reverting to communication via weekly or monthly print publications, say aye. 
    Be seeing you.
    0reaction image LOL 0reaction image Wow! 2reaction image Wisdom · Share on Twitter
  • olafgartenolafgarten Frets: 1648
    You could setup a proxy page that serves insecure content over https. It would increase server load but you could also implement a caching system for content in popular posts to improve speed.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • thebreezethebreeze Frets: 2727
    Can I just ask a basic question please?  When people buy and sell gear on here a lot of that, if not all, takes place via PM including the exchange of a fair amount of private details.  Are PM's secure?  I'm no techy, so just need a yes or no I think so I can act accordingly.  Many thanks.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • thebreeze said:
    Can I just ask a basic question please?  When people buy and sell gear on here a lot of that, if not all, takes place via PM including the exchange of a fair amount of private details.  Are PM's secure?  I'm no techy, so just need a yes or no I think so I can act accordingly.  Many thanks.
    They're secure as in "there's no way to access the database, and the only other way to get them is to be involved in the thread". The only person outside a conversation who can read them is me, and I don't ever do that unless there's a serious legal issue at hand.
    <space for hire>
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • thebreezethebreeze Frets: 2727
    Thanks @digitalscream - that’s good to know.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • PVO_DavePVO_Dave Frets: 2324
    Not a moan as completely understand and have no issue with the https position, but bit of a heads up that it’s starting to show the warning now on my iPhone in Safari, hadn’t noticed it before, don’t know if it’s 12.2 release addition but might drive some more ‘enquiries’ your way :) 
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
Sign In or Register to comment.