HTTP vs HTTPS

sunni

Administrator
Staff member
It is something you as a Mod should suggest to the owners. It would make it a bit more difficult for hackers to bring the site down again. However if they really want to there is not much that can be done to stop- it. All you can do is to try and make it more difficult.
We have and I'm sure he has considered it
 

Michael Huntherz

Well-Known Member
Mods, owners, please check out letsencrypt.org - free https security certificates, trivial to obtain. Totally legit.

I would volunteer my time to help y'all install it. I almost didn't come back to RIU because it makes me so uncomfortable. I love too many people here to stay away, I guess.

Currently, anyone with rudimentary hacking skills can see an RIU user's password in plaintext when they log into the site via public wifi, for instance. They may not mean to target RIU or users here, but when script kiddies see unencrypted logins on the wire they swarm like flies on shit. Them's just facts.
 
Last edited:

Bubblin

Well-Known Member
Currently, anyone with rudimentary hacking skills can see an RIU user's password in plaintext when they log into the site via public wifi, for instance. They may not mean to target RIU or users here, but when script kiddies see unencrypted logins on the wire they swarm like flies on shit. Them's just facts.
This ^
If the site owners or mods had any idea how stupid it actually is to run a site like this w/o https, they'd walk in traffic...

The only thing users can do in the meantime is make sure they're using a different password for RIU, because like Michael H said, sites like this w/o https get farmed for logins, :arrow: and more often than not those logins will work elsewhere...
 

cannetix Inc

Well-Known Member

Found This for those that take security highly ...even those that don't

HTTPS Everywhere is a Firefox, Chrome, and Opera extension that encrypts your communications
with many major websites, making your browsing more secure.

Encrypt the web: Install HTTPS Everywhere today.
https://www.eff.org/https-everywhere
Just so you know, HTTPS everywhere does not make non-HTTPS connections HTTPS encrypted, it simply enforces HTTPS on web servers that have it enabled. Many web servers have both an HTTP and HTTPS version for back compatibility reasons so sometimes you can accidentally end up on an open connection. HTTPS everywhere prevents this and only this. If RIUs servers don't have the capability to handle HTTPS, which they don't appear to, attempting to "enforce" it will simply result in an error. The server would just see it as "jibberish". In the case of the "HTTPS everywhere" extension, it will just default to an HTTP connection.
 

cannetix Inc

Well-Known Member
But yes, I agree, I would very much like to see HTTPS encryption. It's not just about personal data, its just best common practice to use HTTPS. Once your password is exposed on one-site, if it is re-used on another site security is exponentially reduced.
 

greencropper

Well-Known Member
when i try to upload a pic i get warning now that data is being sent over an insecure connection?, and even when i proceed against the warning the pic does not upload?
 

Michael Huntherz

Well-Known Member
when i try to upload a pic i get warning now that data is being sent over an insecure connection?, and even when i proceed against the warning the pic does not upload?
They are working on it, it can be complex depending on one’s existing infrastructure and code. Y’all holler at me if you need help, RIU team.
 
Top