Bitcoin Forum
April 26, 2024, 09:43:22 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: No HTTPS  (Read 1470 times)
btcparanoid (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
May 17, 2011, 09:02:36 PM
 #1

HTTPS is broken. This coupled with reports of irregular IP addresses makes me wonder if somebody may be currently intercepting login credentials for this site.
1714167802
Hero Member
*
Offline Offline

Posts: 1714167802

View Profile Personal Message (Offline)

Ignore
1714167802
Reply with quote  #2

1714167802
Report to moderator
1714167802
Hero Member
*
Offline Offline

Posts: 1714167802

View Profile Personal Message (Offline)

Ignore
1714167802
Reply with quote  #2

1714167802
Report to moderator
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714167802
Hero Member
*
Offline Offline

Posts: 1714167802

View Profile Personal Message (Offline)

Ignore
1714167802
Reply with quote  #2

1714167802
Report to moderator
kseistrup
Hero Member
*****
Offline Offline

Activity: 566
Merit: 500


Unselfish actions pay back better


View Profile WWW
May 17, 2011, 09:08:52 PM
 #2


HTTPS is broken. This coupled with reports of irregular IP addresses makes me wonder if somebody may be currently intercepting login credentials for this site.

+1

Klaus Alexander Seistrup
Basiley
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
May 20, 2011, 07:47:41 AM
 #3

HTTPS is broken. This coupled with reports of irregular IP addresses makes me wonder if somebody may be currently intercepting login credentials for this site.
same issues and same concern.
can anyone[preferably forum admin]post authentic IP-adress ? there and somewhere tamper-proof[I2P ?]
SmokeTooMuch
Legendary
*
Offline Offline

Activity: 860
Merit: 1021


View Profile
May 20, 2011, 03:52:56 PM
 #4

yep, https isn't working on the main site anymore, but it still works on forum.bitcoin.org

Date Registered: 2009-12-10 | I'm using GPG, pm me for my public key. | Bitcoin on Reddit: https://www.reddit.com/r/btc
sirius
Bitcoiner
Sr. Member
****
Offline Offline

Activity: 429
Merit: 974



View Profile
May 22, 2011, 02:45:52 PM
 #5

We have a StartSSL certificate now.

Iris — for better social networks
I'm not a forum admin - please contact theymos instead.
sirius
Bitcoiner
Sr. Member
****
Offline Offline

Activity: 429
Merit: 974



View Profile
May 22, 2011, 02:57:42 PM
 #6

Bitcoin.org is on sf.net and they don't support https.

Iris — for better social networks
I'm not a forum admin - please contact theymos instead.
da2ce7
Legendary
*
Offline Offline

Activity: 1222
Merit: 1016


Live and Let Live


View Profile
May 22, 2011, 05:14:51 PM
 #7

updated https everywhere rule-set that redirects the old https forum links: http://www.bitcoinservice.co.uk/files/875

One off NP-Hard.
phillipsjk
Legendary
*
Offline Offline

Activity: 1008
Merit: 1001

Let the chips fall where they may.


View Profile WWW
June 12, 2011, 05:16:14 PM
 #8

Good to know. (I found this thread by actually using the "search" function)

HTTPS provides authentication (through the use of certificates) as well as encryption. Of course, if you don't trust organizations like VeriSign, you need and out-of-band method for communicating the public key.

Since the forums seem to support HTTPS, the link from http://bitcoin.org (http://bitcointalk.org/
) should be changed to use HTTPS by default. Until about 2 months ago, I did not understand the need for ubiquitous encryption; even of publicly available information. Then I read this:
Quote
Advertising-UNISERVE shall have the right, without notice, to insert advertising data into the Internet browser used by a UNSERVE customer, and transferred to a UNISERVE customer over UNISERVE’s network, so long as this does not involve UNISERVE transmitting any personal information of the customer to whom such data is sent in contravention of the UNISERVE Privacy Commitment;
- Section 27e, My ISP's Updated Terms of service.

PS: I don't use HTTPS everywhere because I leave Scripting disabled most the time.
PPS: I know my website does not support encryption. My webshost wants $200/year for a certificate.

James' OpenPGP public key fingerprint: EB14 9E5B F80C 1F2D 3EBE  0A2F B3DE 81FF 7B9D 5160
wumpus
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1022

No Maps for These Territories


View Profile
June 13, 2011, 01:59:02 PM
 #9

Since the forums seem to support HTTPS, the link from http://bitcoin.org (http://bitcointalk.org/
) should be changed to use HTTPS by default.
+1

The reason that the link is still http is afaik because we used to have a self-signed certificate. This is fixed now, however.

Forum should be HTTPS by default. Preferably, HTTP should be disabled completely, and cookies should be set to secure (SSL-only).

Bitcoin Core developer [PGP] Warning: For most, coin loss is a larger risk than coin theft. A disk can die any time. Regularly back up your wallet through FileBackup Wallet to an external storage or the (encrypted!) cloud. Use a separate offline wallet for storing larger amounts.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!