• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

HTTPS on the ContractorUK

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    HTTPS on the ContractorUK

    No HTTPS on this website in any browser, even with HTTPSEverywhere extensions installed.

    It the OPSec of this forum really *that* bad?

    The various log on screens are http.
    Last edited by contractorinatractor; 24 November 2017, 11:36.

    #2
    Originally posted by contractorinatractor View Post
    No HTTPS on this website in any browser, even with HTTPSEverywhere extensions installed.

    It the OPSec of this forum really *that* bad?

    The various log on screens are http.
    It’s a public forum. What do you want to encrypt?
    See You Next Tuesday

    Comment


      #3
      Originally posted by Lance View Post
      It’s a public forum. What do you want to encrypt?
      Ideally, all posts by nlady. SHA-256 them and throw away the key.

      Comment


        #4
        Originally posted by contractorinatractor View Post
        No HTTPS on this website in any browser, even with HTTPSEverywhere extensions installed.

        It the OPSec of this forum really *that* bad?

        The various log on screens are http.
        If you are dumb enough to reuse a password from a public forum, HTTPS or not, you deserve what you get,
        "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

        Comment


          #5
          Originally posted by DaveB View Post
          If you are dumb enough to reuse a password from a public forum, HTTPS or not, you deserve what you get,
          And even dumber if you don’t have a burner email account...
          "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
          - Voltaire/Benjamin Franklin/Anne Frank...

          Comment


            #6
            Originally posted by cojak View Post
            And even dumber if you don’t have a burner email account...
            oh, dear, is my email account prone to spontaneous combustion??

            Comment


              #7
              Both Firefox and chrome will in the near future start marking sites not using https as insecure
              merely at clientco for the entertainment

              Comment


                #8
                Originally posted by eek View Post
                Both Firefox and chrome will in the near future start marking sites not using https as insecure
                and?

                Comment


                  #9
                  Originally posted by eek View Post
                  Both Firefox and chrome will in the near future start marking sites not using https as insecure
                  Then they will be wrong.
                  End to end transport encryption is a fairly small part of ‘being secure’.
                  See You Next Tuesday

                  Comment


                    #10
                    Originally posted by DaveB View Post
                    If you are dumb enough to reuse a password from a public forum, HTTPS or not, you deserve what you get,
                    that's the attitude. You don't want to make any effort to protect your members.

                    Comment

                    Working...
                    X