Could CUK get one please?
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
SSL Certificate
Collapse
X
-
-
Costs £10Originally posted by Scratch It View PostCould CUK get one please?
Not in Brexit Britain, we need it for soup kitchens. -
It's free with automated renewals at https://letsencrypt.org
However adding ssl would be pointless due to all the unencrypted photos already linked to on this site so it's a can't see the point from meLast edited by eek; 28 June 2017, 08:42.merely at clientco for the entertainmentComment
-
Been using letsencrypt on http://camnomis.com/ for a while, seems to be god enough for most basic sites (ie nothing eComm) and most people expect to see a padlock etc. these daysOriginally posted by eek View PostIt's free with automated renewals at https://letsencrypt.org
However adding ssl would be broken due to all the unencrypted photos already linked to on this site so it's a can't see the point from meOriginally posted by Stevie Wonder BoyI can't see any way to do it can you please advise?
I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.Comment
-
Im curious as to what benefit an SSL cert would bring to CUK?
Yeah, ok the traffic to the site would be encrypted, but its a public forum, any traffic (except your password when you log in) will most likely end up on a public forum anyway...Comment
-
I guess the password is big un, would be fairly easy to monitor network traffic and get login details. Then anyone could login and post random crap, it's clear from General this happens frequently.Originally posted by Snarf View PostIm curious as to what benefit an SSL cert would bring to CUK?
Yeah, ok the traffic to the site would be encrypted, but its a public forum, any traffic (except your password when you log in) will most likely end up on a public forum anyway...Comment
-
At least they are sending a hash of the password over the Internet between your browser and CUK.Originally posted by woohoo View PostI guess the password is big un, would be fairly easy to monitor network traffic and get login details. Then anyone could login and post random crap, it's clear from General this happens frequently.
Not that it helps much against someone adequately motivated as it's a simple hash of the password, so someone could simply use that to perform a fake login (but at least they won't know your real password - e.g. if you use it on other sites).
If CUK were to maybe add digest authentication, then at least the hash would be different for each login attempt.
(still doesn't completely prevent a dedicated MITM to fool you into revealing your real password but would make it harder and more sophisticated)
It might just be easier to add SSL though.Comment
-
It's incredibly easy to break the hash that CUK uses to find out the actual password. So if you do use it on other sites then don't.Originally posted by yetanotherbob View PostAt least they are sending a hash of the password over the Internet between your browser and CUK.
Not that it helps much against someone adequately motivated as it's a simple hash of the password, so someone could simply use that to perform a fake login (but at least they won't know your real password - e.g. if you use it on other sites).
If CUK were to maybe add digest authentication, then at least the hash would be different for each login attempt.
(still doesn't completely prevent a dedicated MITM to fool you into revealing your real password but would make it harder and more sophisticated)
It might just be easier to add SSL though.
FYI just google break hash, one of the top ten will allow you to enter the hash and it will be converted to plain text. So you don't even need to be dedicated, just half interested.
TBH it's not that big a deal for me, CUK doesn't hold my cc details. Though it does hold my email and I suppose you could use that along with the password on a number of popular websites. I'm lucky I don't think that combination would work on anything, only because it's using an old email address.Last edited by woohoo; 9 July 2017, 17:47.Comment
-
Good point: https://en.wikipedia.org/wiki/MD5#SecurityOriginally posted by woohoo View PostIt's incredibly easy to break the hash that CUK uses to find out the actual password. So if you do use it on other sites then don't.Comment
-
You shouldn't be using the same password on sites you value as on CUK anyway."I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
- Voltaire/Benjamin Franklin/Anne Frank...Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- April’s umbrella PAYE risk: how contractors’ end-clients are prepping Today 05:45
- How EV tax changes of 2025-2028 add up for contractor limited company directors Yesterday 08:11
- Under the terms he was shackled by, Ray McCann’s Loan Charge Review probably is a fair resolution Jan 27 08:41
- Contractors, a £25million crackdown on rogue company directors is coming Jan 26 05:02
- How to run a contractor limited company — efficiently. Part one: software Jan 22 23:31
- Forget February as an MSC contractor seeking clarity, and maybe forget fairness altogether Jan 22 19:57
- What contractors should take from Honest Payroll Ltd’s failure Jan 21 07:05
- HMRC tax avoidance list ‘proves promoters’ nothing-to-lose mentality’ Jan 20 09:17
- Digital ID won’t be required for Right To Work, but more compulsion looms Jan 19 07:41
- A remote IT contractor's allowable expenses: 10 must-claims in 2026 Jan 16 07:03

Comment