HTTPS sessions active for Tier 2 subscribers


Recommended Posts

We're happy to announce that we've added SSL sessions for Tier 2 ad free subscribers. Currently this is only active on the main news site, the forums will follow shortly.

 

Even more reason to subscribe :p

 

Inevitable answers to questions:

 

Q: Why isn't it available for everyone

A: Because most of our ad partners don't support SSL delivery.

 

Q: Why not look for a different advertiser?

A: The certificate wasn't free, nor the work to implement it; therefore a Tier 2 adfree perk.

 

Enjoy!

So when is the login going to post via SSL vs how it currently sends which is just http in clear text for username and password

post-14624-0-51669400-1376051453.png

Its a forum, its a news site - I don't really see any need for anything to be SSL --- OTHER THAN when I send my password ;)

So when is the login going to post via SSL vs how it currently sends which is just http in clear text for username and password

attachicon.gifpasswordinclear.png

Its a forum, its a news site - I don't really see any need for anything to be SSL --- OTHER THAN when I send my password ;)

 

@Neobond

 

Yeah, can we get SSL for EVERYONE when it sends the username and password on the login? a POST over SSL won't mess with the advertisements.

SSL certificates is expensive, what C.A issuer that neowin will use?

 

 

 

Because most of our ad partners don't support SSL delivery.

Theres was ad blocking services that actively listing ad-server certificates so their users can put those certificates into "Untrusted" or "Revoked" categories,

which effectively prevent any known SSL ads.

Knowing this most ads services won't bother to obtaining SSL certificates.

So only a B, you seem to have some chain issues

https://www.ssllabs.com/ssltest/analyze.html?d=www.neowin.net&s=74.204.71.246

Seems you did not install the intermediate CA bundle??

https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id=AR1372&actp=LIST&viewlocale=en_US

Please Note: On June 27th, 2010 Thawte upgraded its root hierachy to 2048bit RSA Keys to enhance the security of all SSL products. As a part of this upgrade, all newly issued certificates now require the installation of the new Primary and Secondary Intermediate CA's along with your SSL certificate. These new Intermediate CA's MUST be installed in order for your SSL certificate to be fully trusted in all browsers.

This causes an issue with firefox on the cert

post-14624-0-66352800-1376053582.png

  • Like 1

SSL certificates is expensive, what C.A issuer that neowin will use?

 

They're not expensive..  you can get chained certs that work wit most modern browsers for  < 60 bucks a year, otherwise root certs are around 80 bucks + (can be found cheaper on deals..)   SSL is cheaper than a data breach and hell, i would have helped pitch in for a cert if it meant everyone got it, SSL for subs is.. lame..

 

looks like it is a chained cert.

 

hell, godaddy has a chained cert without all the extras for like 5 bucks

 

http://www.godaddy.com/compare/gdcompare3_ssl.aspx?isc=dssl027&utm_source=MSN&utm_medium=cpc&utm_term=cheap%20ssl&utm_content=2400118724&utm_campaign=8936109240&ef_id=USaBHwAAAQUOWoSL:20130809130902:s

 

Premium feature worthy? not sure why anyone would go direct with thawt though, but they do have a large reseller network, so hopefully neowin didn't pay full retail for a chained.

So really what your saying is that only the people that pay for Tier 2 Subs are worth protecting for passwords sending ?? and not the people that come on here and helps others for free?

 

Great!

  • Like 2

So really what your saying is that only the people that pay for Tier 2 Subs are worth protecting for passwords sending ?? and not the people that come on here and helps others for free?

 

Great!

I thought passwords already have some kind of protection and that SSL is just adding another layer?

It always amazes me when people complain about how someone else runs THEIR free service.  

How about contributing to the sites monetary needs if you have such a problem with it? You may provide support to others for free, but to feed the monster they need virgin blood and that ****s expensive and can't be paid for with computer advice.

Neobond explained why it's not available to everyone, quit your bitchin...

  • Like 8

There was a thread a long time ago about the login posting being in clear text.. If I recall back then it was mentioned that it would be fixed when ssl was setup.

Well it seems that have setup ssl.. There is no need to encrypt the whole site.. sorry but I don't need my viewing of news articles or forum post to be encrypted. Nor do I need the stuff I am sending in a post that will be public encrypted.

What I would like is my password not to be sent in clear text. They have the ssl in place, all they need to do is change the posting from http to https and we are all good.

They can still require that you be a sub if you want the whole site via https, ads or no ads. But changing http to https in the post string for your login seems like a no brainer if the ssl cert has already been paid for and active.

Currently even if viewing the site view https, when I go to login the post in the html command is vis http.. So going to be sent in clear - even if everything else your viewing is via https -- the actual post of the username and password is still only http..

edit: For those that do not understand the issue. No your pc does not have to be compromised for someone to sniff your username and password.. So example your on a wireless network, anyone on that wireless network could see your traffic so could see your neowin username and password.

Now could they just hijack your cookie and auth as you that way - possible have not looked into the issue that deep, nor do I care too.

At any point between your PC and the neowin server it would be possible to see this traffic in the clear and get your username and password. I doubt that it is of much concern, but come on the ssl is there -- just change the post to https and this can discussion is over.

Even if your viewing gmail over http, when you go to login the post is https

  <form novalidate id="gaia_loginform" action="https://accounts.google.com/ServiceLoginAuth" method="post">
  <input type="hidden" 
<form action="https://www.neowin.net/forum/index.php?app=core&module=global&section=login&do=process" method="post" id='login'>
Simple change of a couple lines of code to https vs http and issue goes away now that they have ssl in place.

It always amazes me when people complain about how someone else runs THEIR free service.  

How about contributing to the sites monetary needs if you have such a problem with it? You may provide support to others for free, but to feed the monster they need virgin blood and that ****s expensive and can't be paid for with computer advice.

Neobond explained why it's not available to everyone, quit your bitchin...

 

 

Neobond already knows i will be tier two soon anyway lol

Ah well then I don't see the fuss about not having SSL logins then :p

Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure.

  • Like 1

Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure.

So there's even an alternative... :P

Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure.

What about tor or a proxy is that still unencrypted? I remember proxies can be encrypted but I don't know about tor :/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Anthropic pulls Fable 5 and Mythos 5 after US export control order by Pradeep Viswanathan In April this year, Anthropic launched the Claude Mythos Preview frontier model with state-of-the-art cyber and coding capabilities for a select set of companies around the world. After preparing appropriate guardrails, early this week, Anthropic launched Claude Fable 5 and Mythos 5, its most capable AI models. Claude Fable 5 is for general users and comes with strict safeguards, while Mythos 5 is designed with fewer safeguards for cybersecurity and biology use cases. Today, Anthropic abruptly suspended access to its Fable 5 and Mythos 5 AI models for all customers after receiving an export control directive from the US government. The company received the directive from the government today at 5:21 p.m. ET, and the received letter did not provide any details regarding the national security concern. Anthropic understands that the government became aware of a method to bypass, or “jailbreak,” Fable 5, which might be the reason behind the directive. The order was issued under national security authorities and requires the company to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether they are inside or outside the United States. The restriction also applies to foreign national employees working at Anthropic. As a result, the company has disabled both models for all customers to ensure compliance. Access to previous Anthropic models like Opus and Sonnet is not affected by this government order. The company highlighted that it had developed strong safeguards to reduce the possibility that Fable is misused for tasks related to cybersecurity. In fact, many developers are complaining that the safeguards are going overboard. Additionally, the company worked with the US government, the UK AISI, multiple private third-party organizations, and internal teams to red-team Fable’s safeguards for thousands of hours. Finally, Anthropic noted that no testers have yet been able to find a universal jailbreak on Fable 5. As expected, Anthropic disagrees that a narrow potential jailbreak should lead to the recall of a commercial model used by hundreds of millions of people. It warned that applying this standard across the AI industry could effectively halt new frontier model deployments. Anthropic concluded by mentioning that it is working to restore access to Fable 5 and Mythos 5 as soon as possible and plans to share more details within the next 24 hours.
    • Brave Browser 1.91.172 is out.
    • Any Video Converter Free 9.2.3 by Razvan Serea Any Video Converter is an All-in-One video converting tool with an easy-to-use graphical interface, fast converting speed and excellent video quality. Any Video Converter supports all popular video formats and converts your videos to different video formats including MP4, MOV, MKV, M2TS, M4V, MPEG, AVI, WMV, ASF, OGV, WEBM, and more. It supports converting videos to customized percent (50%, 100%, 200%, and more) or resolution (480p, 720p, 1080p, 4K, and more); It supports encoding videos into x264, x265, h263p, xvid, mpeg, wmv, and more. Any Video Converter Free key features: Compatible with Windows 11/10/8.1/8/7 (32-64bit) User interface are available in 14 languages Convert all kinds of video formats including high-definition videos Extract audio from any videos and save as MP3/WMA for your mp3 player Take snapshot from any videos and build your own picture collection Support high-definition for both input and output Batch add videos from hard drive and batch convert Customize output parameters completely as you like Manage your output videos files by group or output profile Merge several video files into a single and long one Clip a video into segments Free Audio Filter: Adjust audio volume and add audio effects Crop frame size to remove black bars and retain what you want only Adjust the brightness, contrast, saturation Rotate or flip or add noise/sharpen effects Produce output video with subtitles of your own dialogue and much, much more... Any Video Converter Free 9.2.3 changelog: Fixed video download engine auto-update failures. Added custom speed control support in the speed change tool. Added support for downloading YouTube AI-generated subtitles. Added support for preserving original audio stream in the format convert tool (e.g., Dolby Atmos, DTS:X). Fixed other bugs and improved overall performance. Download: Any Video Converter Free 9.2.3 | 7.6 MB (Freeware) View: Any Video Converter Free Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Not sure what country you’re in but in many countries you can absolutely jail the sellers behind businesses… in fact I’d say in most countries you can do that
    • I guess we are done since you refuse to read my comment you replied to or my other comment in another thread you were also a part of here.
  • Recent Achievements

    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
    • One Month Later
      Markus94287 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      ATLien_0
      92
    5. 5
      Steven P.
      79
  • Tell a friend

    Love Neowin? Tell a friend!