Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

Topic # 93594 24-Nov-2011 18:00 Send private message

I have switched the PM pages (message composing, reading and listing) to accept SSL connections by default, and switch to SSL on non-secure requests.

Many reasons for that. You will know why, no need to ask.




View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
1599 posts

Uber Geek
Inactive user


  Reply # 549794 25-Nov-2011 09:44 Send private message

Why is it not possible to have site wide SSL? The login page is in SSL, this means that virtually everything else can be too (except, maybe, ads).



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549795 25-Nov-2011 09:45 Send private message

There, you answered your question.

Think about. It's not all our content. There are sometimes third party content such as speedtest images that will make your browser throw a tantrum for mixed content.

Also, why bother with SSL for a whole site if there's nothing sensitive in those other areas?
 




1599 posts

Uber Geek
Inactive user


  Reply # 549798 25-Nov-2011 09:47 Send private message

Its the question of session jacking. Maybe make it a feature for subscribers only?



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549803 25-Nov-2011 09:50 Send private message

I've edited your post. No need to quote a full post just above yours.

Answering your question, what can be achieved with session hijacking really? Impersonating someone on a forum? It's not as bad as impersonating someone on your banking site.

For that we already have the IP Change option in your profile. If we detect your session is being used from a different IP address we will terminate it. You can also easily click the link in your profile page to terminate ALL existing session, for all browsers.





1599 posts

Uber Geek
Inactive user


  Reply # 549806 25-Nov-2011 09:51 Send private message

Not if your in a Cafe and all share the same external IP.



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549808 25-Nov-2011 09:53 Send private message

*le sigh*

You can just logout as soon as you're done, and anyone else using the same session will be logged out too.

Using SSL site wide would impact our revenue. There's an obvious problem there - we can't run a site full time with no revenue.






BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549812 25-Nov-2011 09:55 Send private message

Also, instead of focusing on how this make things better for people relying on Geekzone PM to communicate (transactions between members, employee confidentiality) you worry about something that would have less impact...





1599 posts

Uber Geek
Inactive user


  Reply # 549817 25-Nov-2011 09:59 Send private message

The whole performance impact thing has been proven wrong for quite some time now:

"In January this year (2010), Gmail switched to using HTTPS for everything by default. Previously it had been introduced as an option, but now all of our users use HTTPS to secure their email between their browsers and Google, all the time. In order to do this we had to deploy no additional machines and no special hardware. On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead. Many people believe that SSL takes a lot of CPU time and we hope the above numbers (public for the first time) will help to dispel that."

As for revenues I'm not quite sure how that comes into it if its just for Subscribers. What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 549819 25-Nov-2011 10:01 Send private message

If you read the thread again you will see I never mentioned the performance card, as I am well aware of the impact or non-impact of it. Please don't put words in my mouth.

As for "for subscribers only", I'm sorry but we work on priorities here. The subscriber uptake is too low, and people have already said that even $5 a month is "too expensive". Not very supporting is it?





7720 posts

Uber Geek
+1 received by user: 297

Trusted
Subscriber

  Reply # 550154 26-Nov-2011 05:14 Send private message

codyc1515:  

What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).


If you are going to use shared/public internet you would send all traffic over a vpn and use your home, work/work/hosts connection to avoid any man in the middle session jacking for all sites.






1599 posts

Uber Geek
Inactive user


  Reply # 550401 26-Nov-2011 19:44 Send private message

Ragnor:
codyc1515:  

What I'm getting at is that someone could go into a Cafe have their session jacked on an ordinary page and send PMs as that user, without them knowing (most likely).


If you are going to use shared/public internet you would send all traffic over a vpn and use your home, work/work/hosts connection to avoid any man in the middle session jacking for all sites.

Not everybody knows this though and its a waste of bandwidth.



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 550402 26-Nov-2011 19:45 Send private message

In such case I doubt they would know or worry about session hijacking either...





Infrastructure Geek
3681 posts

Uber Geek
+1 received by user: 87

Trusted
Microsoft NZ
Subscriber

  Reply # 550404 26-Nov-2011 19:58 Send private message

freitasm: In such case I doubt they would know or worry about session hijacking either...




LOL. +1 




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs


1599 posts

Uber Geek
Inactive user


  Reply # 550408 26-Nov-2011 20:14 Send private message

freitasm: In such case I doubt they would know or worry about session hijacking either...


In which case they should be protected, no?



BDFL
49734 posts

Uber Geek
+1 received by user: 4520

Administrator
Trusted
Geekzone
Subscriber

  Reply # 550409 26-Nov-2011 20:15 Send private message

Sure. Are you paying their subscription? Because I am sure they don't care enough to pay for one. 

As I said, it comes down to priorities, planning, costs. Should we just close the site because some people won't pay for a subscription, and having SSL means ads are going to be harder to deliver, just because  some idiot may impersonate someone on a non-commerce site?







 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Windows 10 announced, as well as developer preview
Created by macuser, last reply by Disrespective on 1-Oct-2014 15:57 (33 replies)
Pages... 2 3


Moment of Truth?
Created by BarTender, last reply by JimmyC on 29-Sep-2014 09:16 (441 replies)
Pages... 28 29 30


Can i have 2 ISP's at home?
Created by ReckITT, last reply by Lazarui on 30-Sep-2014 18:15 (49 replies)
Pages... 2 3 4


Why is your nickname what it is, what are the origins of it?
Created by Presso, last reply by hsvhel on 1-Oct-2014 11:52 (89 replies)
Pages... 4 5 6


What time will the Apple Store online be selling the iPhone 6?
Created by scotiwis, last reply by mrphil on 1-Oct-2014 16:59 (96 replies)
Pages... 5 6 7


iPhone 6 From Spark - Order Dates and Pricing?
Created by Otagolad, last reply by mahdibassam on 1-Oct-2014 17:03 (348 replies)
Pages... 22 23 24


Easiest way to have iPhone warranty service
Created by JoshWright, last reply by nitrotech on 30-Sep-2014 21:37 (15 replies)

Passwords and pesky teenagers
Created by martyyn, last reply by DaveDog on 1-Oct-2014 12:28 (26 replies)
Pages... 2



Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.