Welcome, Guest. Please login or register.
Did you miss your activation email?

Username: Password:

Author Topic: SSL  (Read 802 times)

Hypnotastic

  • Karma: 0
  • Posts: 3
SSL
« on: December 25, 2018, 04:53:11 pm »

Hi

Seems to be no https for sharetheseeds..
There are free certificates at https://www.sslforfree.com/ if its a matter of cost.

Logged

blackb0x

  • Member
  • Karma: 2
  • Posts: 48
  • Trading Score: +8
Re: SSL
« Reply #1 on: December 31, 2018, 05:02:53 pm »

I really wish the site would use it, but it's been discussed before: http://sharetheseeds.me/forum/index.php?topic=3915.15
Logged

Hypnotastic

  • Karma: 0
  • Posts: 3
Re: SSL
« Reply #2 on: January 02, 2019, 12:29:13 am »

I wouldn't call SSL weak, and there are certainly more things to worry about than man in the middle attacks. Nor would I recommend (as the admin does) to use Tor to login to this website. As no data here is encrypted, the exit-node will be able to look at all the data passing through in text. WTF is admin thinking suggesting this?
Logged

Jansch42

  • Member
  • Karma: 0
  • Posts: 9
  • Passionate shamanic herb grower since 2011
Re: SSL
« Reply #3 on: January 02, 2019, 01:59:34 pm »

I agree that a https:// vertificate would be nice, we wouldn't have to worry about the european DSVGO either then.
Logged
-Jansch42

humbleNinterested

  • Member
  • Karma: 1
  • Posts: 4
Re: SSL
« Reply #4 on: December 30, 2019, 01:36:30 pm »

another option which is super duper easy for the powers that be would be:

1. letsencrypt

or

2. cloudflare

the latter can be setup in less than 5 minutes by rerouting the DNS configuration through cloudflare, and both options are free
Logged

BubbleCat

  • Supreme feline leader
  • Administrator
  • Karma: 137
  • Posts: 1869
  • Trading Score: +140
  • <3
Re: SSL
« Reply #5 on: December 31, 2019, 05:17:40 pm »

SSL itself isn't weak. But most browsers implementation have a consistent history of 'my grandmother would do a better job writing it in x86-assembly while drunk'.
Either way: True. It would be nice to have. Certbot / Letsencrypt makes it easy as cake. Problem: We're a bus without a driver.
Logged
Praise is mandatory.