HTTPS is available

Announcements, advice, random banter, unrelated discussion, et cetera.

HTTPS is available

Postby Qbix » 2016-4-29 @ 11:39

It is still in testing, but https://www.vogons.org is available.
Please let me know if you encounter a problem.
Water flows down the stream
How to ask questions the smart way!
User avatar
Qbix
DOSBox Author
 
Posts: 10375
Joined: 2002-11-27 @ 14:50
Location: Fryslan

Re: HTTPS is available

Postby clueless1 » 2016-4-29 @ 13:32

Qbix wrote:It is still in testing, but https://www.vogons.org is available.
Please let me know if you encounter a problem.

Let's Encrypt?

edit: Yup. Nice. I've got a few websites I'm going to use this on when their certs expire later this year.
The more I learn, the more I realize how much I don't know.
Let's benchmark our systems with cache disabled
DOS PCI Graphics Card Benchmarks
User avatar
clueless1
l33t
 
Posts: 3289
Joined: 2015-12-22 @ 17:43
Location: Midwest US

Re: HTTPS is available

Postby mrau » 2016-5-02 @ 20:26

https://www.ssllabs.com/ssltest/analyze ... Results=on
purrfectly done, only my bank does better(sometimes), congratulations :)
mrau
Oldbie
 
Posts: 812
Joined: 2015-11-28 @ 12:43

Re: HTTPS is available

Postby j7n » 2016-5-08 @ 05:29

Thank you for keeping this site on an old, fast engine and SSL-free (optional). It is one of very few remaining that open on old PCs and browsers.
User avatar
j7n
Newbie
 
Posts: 71
Joined: 2013-10-06 @ 04:46

Re: HTTPS is available

Postby lightmaster » 2016-5-10 @ 17:18

Qbix wrote:It is still in testing, but https://www.vogons.org is available.
Please let me know if you encounter a problem.

Thanks Qbix!!
Image
User avatar
lightmaster
Oldbie
 
Posts: 601
Joined: 2005-10-01 @ 12:09
Location: Sol III(¡¿

Re: HTTPS is available

Postby kolano » 2016-5-10 @ 19:37

So it seems Firefox is complaining the "Connection is not secure" on many pages. Seems to be caused by non-HTTPS connections being used for images in peoples footers.
User avatar
kolano
Oldbie
 
Posts: 518
Joined: 2010-12-26 @ 21:03

Re: HTTPS is available

Postby mrau » 2016-5-10 @ 20:32

just noticed as well, entering this thread causes to drop secure connection with opera
mrau
Oldbie
 
Posts: 812
Joined: 2015-11-28 @ 12:43

Re: HTTPS is available

Postby Qbix » 2016-5-11 @ 13:29

Yeah it is caused by lightmasters signature.
I think he would need to change the url to start with
Code: Select all
//

so remove the
Code: Select all
http:

part.
Water flows down the stream
How to ask questions the smart way!
User avatar
Qbix
DOSBox Author
 
Posts: 10375
Joined: 2002-11-27 @ 14:50
Location: Fryslan

Re: HTTPS is available

Postby laxdragon » 2016-5-11 @ 13:46

Thanks for this.

For some added security you may want to add the following header:
X-Frame-Options: SAMEORIGIN

This will prevent any embedded, IFRAMES running.

You could also look into Content-Security-Policy header, but that one is a bit more complicated, esp since I see this site uses embedded javascript instead of linking to it in a .js file.
User avatar
laxdragon
Member
 
Posts: 387
Joined: 2004-10-22 @ 18:42
Location: Minneapolis, MN

Re: HTTPS is available

Postby kolano » 2016-5-12 @ 21:23

Qbix wrote:Yeah it is caused by lightmasters signature.
I think he would need to change the url to start with
Code: Select all
//

so remove the
Code: Select all
http:

part.


Can something be added to auto apply such to peoples existing signatures. Expecting people to update them is likely problematic.
User avatar
kolano
Oldbie
 
Posts: 518
Joined: 2010-12-26 @ 21:03

Re: HTTPS is available

Postby lightmaster » 2016-5-13 @ 03:04

Qbix wrote:Yeah it is caused by lightmasters signature.
I think he would need to change the url to start with
Code: Select all
//

so remove the
Code: Select all
http:

part.

Did try and didn't work, i'm sure i'ts my problem, pm me please.
Image
User avatar
lightmaster
Oldbie
 
Posts: 601
Joined: 2005-10-01 @ 12:09
Location: Sol III(¡¿

Re: HTTPS is available

Postby Qbix » 2016-5-13 @ 10:33

It seems it doesn't work for the img tag :(
I have set your signature to https now, which works fine, but Ideally I'd like to get the other solution working as well. Although we can't do it for everything. The img hoster needs to support it as well. A perfect solution doesn't exist.

So the best I can offer is this:
If you use an image in your signature and the host of the image supports https, please change the link to use the https instead of http.
Water flows down the stream
How to ask questions the smart way!
User avatar
Qbix
DOSBox Author
 
Posts: 10375
Joined: 2002-11-27 @ 14:50
Location: Fryslan

Re: HTTPS is available

Postby lightmaster » 2016-5-13 @ 15:16

Thanks again Qbix!!
Image
User avatar
lightmaster
Oldbie
 
Posts: 601
Joined: 2005-10-01 @ 12:09
Location: Sol III(¡¿

Re: HTTPS is available

Postby FFXIhealer » 2016-7-03 @ 01:05

Sounds cool, but I can't use the HTTPS version of the site from Firefox 2.0 on Windows 98 FE. I get an error code. The regular version works perfectly fine, though this is the first time I'm trying it out.

Error establishing an encrypted connection to http://www.vogons.org. Error Code: -8092.

Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20
Image
Image
Image
Image
FFXIhealer
Member
 
Posts: 433
Joined: 2016-6-22 @ 17:42
Location: Lake Charles, Louisiana (U.S.A.)

Re: HTTPS is available

Postby keenmaster486 » 2016-7-03 @ 03:15

Um, I didn't think Firefox 2.0 supported HTTPS, is that correct?
I flermmed the plootash just like you asked.
Very silly indeed: https://audaxeundum.wordpress.com
User avatar
keenmaster486
Oldbie
 
Posts: 949
Joined: 2016-2-16 @ 02:04
Location: Atroxus

Re: HTTPS is available

Postby laxdragon » 2016-7-05 @ 13:44

It did, but only older style encryption. Modern websites use TLS 1.1 and above. Anything else is considered insecure. Even 1.1 is being phased out I believe.
User avatar
laxdragon
Member
 
Posts: 387
Joined: 2004-10-22 @ 18:42
Location: Minneapolis, MN

Re: HTTPS is available

Postby KurtHectic » 2016-10-07 @ 14:30

Thanks Mr. Qbix.
W10: Phenom II X6 1090T@3.2GHz/6GB DDR3 1333/Radeon HD 6450 1GB DDR3
XP: *building* Athlon X2 6000/2GB DDR2 800/Geforce 7950GT 512MB
DOS/W98SE: PIII 550MHz/256MB PC100/Geforce FX 5200 128MB
User avatar
KurtHectic
Newbie
 
Posts: 7
Joined: 2016-9-21 @ 14:08
Location: Brazil

Re: HTTPS is available

Postby calvin » 2016-11-15 @ 02:31

Consider running with HSTS and pinning. Older browsers that don't understand will happily use the insecure site, while newer browsers that support it can enforce the TLS version.
2xP2 450, 512 MB SDR, GeForce DDR, Asus P2B-D, Windows 2000
P3 866, 512 MB RDRAM, Radeon X1650, Dell Dimension XPS B866, Windows 7
M2 @ 250 MHz, 64 MB SDE, SiS5598, Compaq Presario 2286, Windows 98
calvin
Member
 
Posts: 257
Joined: 2015-3-13 @ 22:38

Re: HTTPS is available

Postby clueless1 » 2016-12-26 @ 16:20

I just noticed https is now working by default. Has it been that way for awhile and I'm just now noticing?
The more I learn, the more I realize how much I don't know.
Let's benchmark our systems with cache disabled
DOS PCI Graphics Card Benchmarks
User avatar
clueless1
l33t
 
Posts: 3289
Joined: 2015-12-22 @ 17:43
Location: Midwest US

Re: HTTPS is available

Postby clueless1 » 2017-4-28 @ 15:51

I thought back in December https was on by default, but...
Every time I go to "vogons.org" and login, it defaults to the http page unless I manually type the https part. On my trusted PCs, it's not an issue, as lastpass logs me into the secure page. But I do access this site from public PCs on occasion.
The more I learn, the more I realize how much I don't know.
Let's benchmark our systems with cache disabled
DOS PCI Graphics Card Benchmarks
User avatar
clueless1
l33t
 
Posts: 3289
Joined: 2015-12-22 @ 17:43
Location: Midwest US

Next

Return to Milliways

Who is online

Users browsing this forum: Baidu [Spider] and 3 guests