Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

Topic # 93594 24-Nov-2011 18:00 Send private message

I have switched the PM pages (message composing, reading and listing) to accept SSL connections by default, and switch to SSL on non-secure requests.

Many reasons for that. You will know why, no need to ask.




View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
1599 posts

Uber Geek
Inactive user


  Reply # 549794 25-Nov-2011 09:44 Send private message

Why is it not possible to have site wide SSL? The login page is in SSL, this means that virtually everything else can be too (except, maybe, ads).



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549795 25-Nov-2011 09:45 Send private message

There, you answered your question.

Think about. It's not all our content. There are sometimes third party content such as speedtest images that will make your browser throw a tantrum for mixed content.

Also, why bother with SSL for a whole site if there's nothing sensitive in those other areas?
 




1599 posts

Uber Geek
Inactive user


  Reply # 549798 25-Nov-2011 09:47 Send private message

Its the question of session jacking. Maybe make it a feature for subscribers only?



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549803 25-Nov-2011 09:50 Send private message

I've edited your post. No need to quote a full post just above yours.

Answering your question, what can be achieved with session hijacking really? Impersonating someone on a forum? It's not as bad as impersonating someone on your banking site.

For that we already have the IP Change option in your profile. If we detect your session is being used from a different IP address we will terminate it. You can also easily click the link in your profile page to terminate ALL existing session, for all browsers.





1599 posts

Uber Geek
Inactive user


  Reply # 549806 25-Nov-2011 09:51 Send private message

Not if your in a Cafe and all share the same external IP.



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549808 25-Nov-2011 09:53 Send private message

*le sigh*

You can just logout as soon as you're done, and anyone else using the same session will be logged out too.

Using SSL site wide would impact our revenue. There's an obvious problem there - we can't run a site full time with no revenue.






BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549812 25-Nov-2011 09:55 Send private message

Also, instead of focusing on how this make things better for people relying on Geekzone PM to communicate (transactions between members, employee confidentiality) you worry about something that would have less impact...





1599 posts

Uber Geek
Inactive user


  Reply # 549817 25-Nov-2011 09:59 Send private message

The whole performance impact thing has been proven wrong for quite some time now:

"In January this year (2010), Gmail switched to using HTTPS for everything by default. Previously it had been introduced as an option, but now all of our users use HTTPS to secure their email between their browsers and Google, all the time. In order to do this we had to deploy no additional machines and no special hardware. On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead. Many people believe that SSL takes a lot of CPU time and we hope the above numbers (public for the first time) will help to dispel that."

As for revenues I'm not quite sure how that comes into it if its just for Subscribers. What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549819 25-Nov-2011 10:01 Send private message

If you read the thread again you will see I never mentioned the performance card, as I am well aware of the impact or non-impact of it. Please don't put words in my mouth.

As for "for subscribers only", I'm sorry but we work on priorities here. The subscriber uptake is too low, and people have already said that even $5 a month is "too expensive". Not very supporting is it?





7748 posts

Uber Geek
+1 received by user: 316

Trusted
Subscriber

  Reply # 550154 26-Nov-2011 05:14 Send private message

codyc1515:  

What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).


If you are going to use shared/public internet you would send all traffic over a vpn and use your home, work/work/hosts connection to avoid any man in the middle session jacking for all sites.






1599 posts

Uber Geek
Inactive user


  Reply # 550401 26-Nov-2011 19:44 Send private message

Ragnor:
codyc1515:  

What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).


If you are going to use shared/public internet you would send all traffic over a vpn and use your home, work/work/hosts connection to avoid any man in the middle session jacking for all sites.

Not everybody knows this though and its a waste of bandwidth.



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 550402 26-Nov-2011 19:45 Send private message

In such case I doubt they would know or worry about session hijacking either...





Infrastructure Geek
3705 posts

Uber Geek
+1 received by user: 88

Trusted
Microsoft NZ
Subscriber

  Reply # 550404 26-Nov-2011 19:58 Send private message

freitasm: In such case I doubt they would know or worry about session hijacking either...




LOL. +1 




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs


1599 posts

Uber Geek
Inactive user


  Reply # 550408 26-Nov-2011 20:14 Send private message

freitasm: In such case I doubt they would know or worry about session hijacking either...


In which case they should be protected, no?



BDFL
49938 posts

Uber Geek
+1 received by user: 4624

Administrator
Trusted
Geekzone
Subscriber

  Reply # 550409 26-Nov-2011 20:15 Send private message

Sure. Are you paying their subscription? Because I am sure they don't care enough to pay for one. 

As I said, it comes down to priorities, planning, costs. Should we just close the site because some people won't pay for a subscription, and having SSL means ads are going to be harder to deliver, just because  some idiot may impersonate someone on a non-commerce site?







 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





Trending now »

Hot discussions in our forums right now:

Speed limit when overtaking? Teach me please.
Created by nakedmolerat, last reply by Hobchild on 26-Oct-2014 00:11 (92 replies)
Pages... 5 6 7


House Auctions
Created by t0ny, last reply by Elpie on 26-Oct-2014 00:54 (45 replies)
Pages... 2 3


VDSL, which router/modem sub $200?
Created by TeaLeaf, last reply by NonprayingMantis on 25-Oct-2014 19:48 (28 replies)
Pages... 2


Neon - Sky's new streaming service
Created by JarrodM, last reply by JimmyH on 25-Oct-2014 17:37 (29 replies)
Pages... 2


iPad Air 2 and iPad Mini 3. Gonna get one?
Created by Dingbatt, last reply by tungsten on 25-Oct-2014 20:22 (115 replies)
Pages... 6 7 8


5Ghz AP recommendations?
Created by ubergeeknz, last reply by sbiddle on 24-Oct-2014 12:42 (12 replies)

Snap have failed our company!
Created by dafman, last reply by kornflake on 23-Oct-2014 17:41 (37 replies)
Pages... 2 3


Thief taunts 12 year old via stolen laptop
Created by macuser, last reply by charsleysa on 22-Oct-2014 23:49 (12 replies)


Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.