Neowin needs HTTPS login from main, not just forums


Recommended Posts

We already have a certificate, price isn't really the issue here

Sorry, just saw other people mentioning cheap $4/month certificates, and I decided I would mention a free one.

 

But really, the only ways you would be able to have HTTPS logins everywhere, would be to serve an iframe in the popup (kind of bad), or just redirect to the full login page.

Do self-signed certificates get along well with browser security? If the browser doesn't trust a certificate's issuer, then it inherintly does not trust the certificate. Self-signed certificates are their own issuer, which causes issues for situations like this.

 

First time the browser will give you a warning but after that you can add the self-signed to your trusted list and you are okay and wont see the nag screen anymore but it will add free security. Depends on the key lenght of course, if the server is really as strained as some are saying it would be easier to buy one with lower key lenght rahter than wasting time for a self-signed.

FWIW, you can access Neowin over HTTPS:  https://www.neowin.net/

 

That's a subscriber-only feature, otherwise we lose out on ad revenue

 

Not sure if anyone noticed, but https://neowin.net throws up an error, because the certificate being served in return only matches https://www.neowin.net You may want to take a look and fix that.

Just to point out what every other staff member has said already. ONLY Tier 2 (ad free) subscribers get full HTTPS browsing on Neowin, this is because none of our advertisers support ad display through HTTPS. It's one of the things I will be addressing when I go to San Francisco later this year with our main advertiser, because it does work for all the "big" sites out there (Facebook, Twitter, Google sites etc).

  • Like 2

StartCom gives free SSL certificates through https://www.startssl.com.

Never knew there was free ssl certificates, thanks though!

Some prick sniffed my password at a school computer lab. Is there any way for Neowin to get a secure logon? I know these things cost money, but it's such an easy target for any jackass with a computer. Hell, even a self-generated certificate (not from Thawte, Verisign, etc) would at least give some of us the option of using it.

When you use a pc/network that is not under your control, it is far easier for these things to happen. Let this be a lesson for you and learn from it. use a strong random password, even for a forum account, and like tiddlie stated, that neowin isn't a "Finacial institition".

 

When you use a pc/network that is not under your control, it is far easier for these things to happen. Let this be a lesson for you and learn from it. use a strong random password, even for a forum account, and like tiddlie stated, that neowin isn't a "Finacial institition".

 

I do not think that it is very constructive and helpful to stick another person's nose in it and effectively say "see what you've done?". Not being a financial institution does not excuse a web site from taking appropriate and reasonable measures to ensure safety and security of its users' data, both in-flight and at rest. I commend Neowin for securing my login data and for striving even further than that by wanting to secure the login form itself. Let this be an example to other communities. And no, Neobond did not pay an exorbitant amount of money to me to say this.

I do not think that it is very constructive and helpful to stick another person's nose in it and effectively say "see what you've done?". Not being a financial institution does not excuse a web site from taking appropriate and reasonable measures to ensure safety and security of its users' data, both in-flight and at rest. I commend Neowin for securing my login data and for striving even further than that by wanting to secure the login form itself. Let this be an example to other communities. And no, Neobond did not pay an exorbitant amount of money to me to say this.

Well, I guess it'll be encrypted for all eventually. Bets you are glad this topic was revived? :)

Well, I guess it'll be encrypted for all eventually. Bets you are glad this topic was revived? :)

 

If reviving this topic leads to greater security of Neowin users' data while remaining commercially sustainable for Neobond et al to operate, then yes, I am glad.

  • 2 weeks later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • What about it? The old MV2 version will not work.
    • Wow, this is some Iran, Cuba, China, Russia, North Korea-level citizen surveillance right there, the UK's government has gone totally mad. Power trip indeed, their politicians are totally out of control about this issue. They're starting to cross limits I wouldn't have imagined, to be honest. British people, fight this, your privacy and freedoms are in danger. Vote this government out of power.
    • Nintendo unveils The Legend of Zelda: Ocarina of Time remake, and it's out this year by Pulasthi Ariyasinghe Confirming many rumors, Nintendo officially announced a remake of the classic The Legend of Zelda: Ocarina of Time, the very first game in the series that offered a 3D experience to fans. Unlike previous remasters and re-releases, the originally 1998-released fantasy adventure game is being remade from the ground up for the Nintendo Switch 2 console this time. "The Nintendo 64 classic returns for a new generation in 2026, reborn exclusively for Nintendo Switch 2," said the company about today's announcement. While Nintendo didn't go into much detail about the project, other than confirming its existence, we did get a small teaser trailer at the Direct presentation today. Catch the footage below: With a tapestry as the backdrop, the first half of the trailer tells the tale of Hyrule, the Kokiri forest dwellers, and their fairy companions. It goes onto introduce "one particular boy" without a fairy, which then cuts to a sleeping Link, showcasing what looks like the new art style being introduced in the remake. Unfortunately, no gameplay or a look at the world has been revealed yet. The game originally released for the Nintendo 64 back in 1998, offering a time travel adventure where Link is once again going up against the evil king Ganondorf. The hugely well-received title has only been playable on modern Nintendo consoles using the Switch Online + Expansion Pack membership. The Legend of Zelda: Ocarina of Time remake for the Nintendo Switch 2 doesn't have a firm release date yet, but Nintendo says it will be released sometime in 2026. Considering just how many publishers are avoiding the Grand Theft Auto VI release nowadays, the company may copy that strategy and also opt to bring this out before November this year.
  • Recent Achievements

    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
    • One Year In
      jojodbn earned a badge
      One Year In
    • One Month Later
      jojodbn earned a badge
      One Month Later
    • Week One Done
      jojodbn earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      518
    2. 2
      PsYcHoKiLLa
      229
    3. 3
      +Edouard
      113
    4. 4
      ATLien_0
      87
    5. 5
      Steven P.
      83
  • Tell a friend

    Love Neowin? Tell a friend!