Bitcoin Forum

Other => Meta => Topic started by: marlboroza on June 07, 2017, 12:27:52 AM



Title: Connection is not secure
Post by: marlboroza on June 07, 2017, 12:27:52 AM
https://bitcointalk.org/index.php?topic=1951732.20

https://i.imgur.com/m6TJkaH.png

 ???

Only here.





Title: Re: Connection is not secure
Post by: mprep on June 07, 2017, 12:41:48 AM
It's not fully secure since it's linking to an avatar located on a website without SSL (as in an image outside the forum). Seems like one of the few remaining users (specifically this guy (https://bitcointalk.org/index.php?action=profile;u=19710)) who got an avatar before the avatar vulnerability was discovered and hasn't changed it since. I'll ping theymos about this.


Title: Re: Connection is not secure
Post by: marlboroza on January 05, 2019, 06:33:20 PM
I noticed something weird in this thread (https://bitcointalk.org/index.php?topic=5073793.0):

Page #1:
https://bitcointalk.org/index.php?topic=5073793.0
https://i.imgur.com/yoY4WNe.png

Page #2:
https://bitcointalk.org/index.php?topic=5073793.20
https://i.imgur.com/I3ZMRgi.png

Page #3 and #4
https://bitcointalk.org/index.php?topic=5073793.40
https://i.imgur.com/J368CXj.png
https://bitcointalk.org/index.php?topic=5073793.60
https://i.imgur.com/mKw26kS.png
Page #5:
https://bitcointalk.org/index.php?topic=5073793.80
https://i.imgur.com/D0XhaOZ.png

Then page #6:
https://bitcointalk.org/index.php?topic=5073793.100
https://i.imgur.com/kEoecCK.png

On pages #7 and #8 connection is not secure and then page number 9:
https://bitcointalk.org/index.php?topic=5073793.160
https://i.imgur.com/A5DGtvC.png

And so on.


Title: Re: Connection is not secure
Post by: khaled0111 on January 05, 2019, 07:08:01 PM
I think it is because of the http link in some users signatures codes.
http links are considered insecure thus your web browser will warn you.


Title: Re: Connection is not secure
Post by: marlboroza on January 05, 2019, 07:14:49 PM
I think it is because of the http link in
Jfsglady (https://bitcointalk.org/index.php?action=profile;u=17856) signature.
Everything is good here https://bitcointalk.org/index.php?topic=5087584.msg49059160#msg49059160 so I don't think spambie's signature is the reason. Don't know  :-\

No one has signature on this page https://bitcointalk.org/index.php?topic=5073793.460 and I don't see avatars and links either.

I noticed the same thing in these threads:

https://bitcointalk.org/index.php?topic=5088562.0
https://bitcointalk.org/index.php?topic=5064169.0
https://bitcointalk.org/index.php?topic=5036621.0 - avatar? (https://bitcointalk.org/index.php?topic=5036621.msg48916547#msg48916547) - it is fine here (https://bitcointalk.org/index.php?topic=5036621.msg48844765#msg48844765)
https://bitcointalk.org/index.php?topic=4475090.160 - I thought this is because of bit679'2 (https://bitcointalk.org/index.php?topic=4475090.msg40731179#msg40731179) avatar but on the next page (https://bitcointalk.org/index.php?topic=4475090.180) everything is ok.
https://bitcointalk.org/index.php?topic=4479636.0 page #4, 6, 7, 8, 12, 13 etc
https://bitcointalk.org/index.php?topic=2064871.0 page # 3,4,5 etc


Title: Re: Connection is not secure
Post by: o_e_l_e_o on January 05, 2019, 08:44:09 PM
If you press F12 in either Firefox or Chrome to enable the Web Console, it will tell you which parts of the page are insecure.

In some of those threads it is because of http:// links in signatures. Other threads are pulling content from various insecure sites, but I'm not sure why.

Edit:

According to the source code, the following users are displaying an invisible avatar from an insecure link. All these users were registered back in 2011 and have lain dormant until 2018.

leholmes12 (https://bitcointalk.org/index.php?action=profile;u=23653)
saymajaan24 (https://bitcointalk.org/index.php?action=profile;u=15965)
conklinliane (https://bitcointalk.org/index.php?action=profile;u=21040)
ArtHawk678 (https://bitcointalk.org/index.php?action=profile;u=12556)
RalphPitts (https://bitcointalk.org/index.php?action=profile;u=13969)
clark581 (https://bitcointalk.org/index.php?action=profile;u=19314)

It is explained in mprep's old post from above:

It's not fully secure since it's linking to an avatar located on a website without SSL (as in an image outside the forum). Seems like one of the few remaining users (specifically this guy (https://bitcointalk.org/index.php?action=profile;u=19710)) who got an avatar before the avatar vulnerability was discovered and hasn't changed it since. I'll ping theymos about this.