• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

HTTPS on the ContractorUK

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #31
    Originally posted by woohoo View Post
    If you are at a clients site. You decide to read or post something negative about the client. The client could be monitoring the network and will see the post in clear text. Just an example but you get my meaning.
    If you are that paranoid you should be using a VPN then, as any Wifi that is not your own is a risk
    Originally posted by Stevie Wonder Boy
    I can't see any way to do it can you please advise?

    I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

    Comment


      #32
      Originally posted by SimonMac View Post
      If you are that paranoid you should be using a VPN then, as any Wifi that is not your own is a risk
      I actually post directly on a forum that I host on my own server. I then have a bot that scrapes the content, encrypts it, connects to a VPN (hosted myself, obvs!), opens TOR, logs into CUK with my fake email account, decrypts the text, posts the reply for me, then changes my password to something that nobody will ever guess (256 characters, mixture of caps, lower case, numbers, symbols and characters that it's just invented specifically for this purpose) and logs out of everything. It then clears all caches on the computer, shuts down, and restarts.

      And it still falls down because of http rather than https
      Best Forum Advisor 2014
      Work in the public sector? You can read my FAQ here
      Click here to get 15% off your first year's IPSE membership

      Comment


        #33
        Originally posted by TheFaQQer View Post
        I actually post directly on a forum that I host on my own server. I then have a bot that scrapes the content, encrypts it, connects to a VPN (hosted myself, obvs!), opens TOR, logs into CUK with my fake email account, decrypts the text, posts the reply for me, then changes my password to something that nobody will ever guess (256 characters, mixture of caps, lower case, numbers, symbols and characters that it's just invented specifically for this purpose) and logs out of everything. It then clears all caches on the computer, shuts down, and restarts.

        And it still falls down because of http rather than https
        Meanwhile, someone pinched your TV.

        Comment


          #34
          Originally posted by SimonMac View Post
          If you are that paranoid you should be using a VPN then, as any Wifi that is not your own is a risk
          hah yeah install a VPN on a clients machine without their permission.

          Comment


            #35
            There is actually a fair bit of personal information which could be got at but only if you're going the whole hog and filling everything in under 'Settings':

            Home Page URL:
            If you would like to let other visitors to this site know the URL of your own web site, enter it here.
            Instant Messaging
            ICQ Number:
            AIM Screen Name:
            MSN Messenger Handle:
            Yahoo! Messenger Handle:
            Skype Name:
            And I bet some people have filled out the Biography section with some personal information!
            Brexit is having a wee in the middle of the room at a house party because nobody is talking to you, and then complaining about the smell.

            Comment


              #36
              Originally posted by darmstadt View Post
              There is actually a fair bit of personal information which could be got at but only if you're going the whole hog and filling everything in under 'Settings':



              And I bet some people have filled out the Biography section with some personal information!
              oh, dear, - you're not supposed to then??

              Comment


                #37
                Originally posted by BR14 View Post
                oh, dear, - you're not supposed to then??
                Aside from the nude photo, you're good.

                Comment


                  #38
                  Originally posted by SimonMac View Post
                  It's a risk vs reward situation, if you are protecting PCI data and at risk of millions of pounds in fines the reward for activating HTTPS is high, if the only think to protect are email addresses and password, it makes greater sense to educate the denizens in good practise when it comes to password management as HTTPS in itself is not 100% secure
                  You're not just protecting email addresses and passwords though. Our usernames, email addresses, IP addresses and our browsing habits are all in the open. In particular if you just look at the HMRC schemes section, without a VPN and a burner profile, it's possible they have already generated a profile on you without any involvement of the forum.

                  Given letsencrypt is free and fairly trivial to configure, the admin probably should enable TLS if they have control of the server. I don't really see what motivation anyone has in talking it down. Makes even less sense when much of the forum is IT contractors. You guys understand the issue, right?
                  Last edited by fool; 27 November 2017, 20:33.

                  Comment


                    #39
                    Originally posted by fool View Post
                    You're not just protecting email addresses and passwords though. Our usernames, email addresses, IP addresses and our browsing habits are all in the open. In particular if you just look at the HMRC schemes section, without a VPN and a burner profile, it's possible they have already generated a profile on you without any involvement of the forum.

                    Given letsencrypt is free and fairly trivial to configure, the admin probably should enable TLS. I don't really see what motivation anyone has in talking it down. Makes even less sense when much of the forum is IT contractors. You guys understand the issue, right?
                    Have you read the comments on this thread?

                    It's clear many of the people who have posted do not understand or (worse) believe they understand far more than they actually do...
                    merely at clientco for the entertainment

                    Comment


                      #40
                      Originally posted by eek View Post
                      Have you read the comments on this thread?

                      It's clear many of the people who have posted do not understand or (worse) believe they understand far more than they actually do...
                      Sadly I have.

                      Comment

                      Working...
                      X