Jump to content

Recommended Posts

Posted (edited)

The whole web is going HTTPS. With Let's Encrypt offering easy and free certs, howcome Edugeek is still served over plaintext HTTP?

 

Edit: Wow. I just logged out and back in; Not even login page is over HTTPS. Pretty glad I don't use this credential combination elsewhere.

Edited by LemonEntry
  • Thanks 2
Posted (edited)

It has been requested before and we basically have wanted HTTPS for a while but are planning to do it when we migrated to our new site platform as vBulletin has a few issues with HTTPS and our setup. We had originally hoped to move across at the start of last year but being honest the platform wasn't stable enough for us to move across and risk causing issues for users so we had held off. Thankfully though the majority of issue appear to be fixed now and we are going through a check list of minor issues then some user testing before going live with it asap. The new site also supports 2 factor authentication.

 

The mobile apps are HTTPS now that as they use a different system and it was much more straight forward to implement, also mobiles inherently will hit more free wifi points where sniffing could occur.

 

Having HTTPS logins did kind of work but it wouldnt really secure the site fully as it was possible to get information transmitted after the fact when you switch back to http. We didnt want to present the system being https secured with those holes as it would lead people to think it wasnt possible to pull information when we knew they could which would only be lip service security.

 

We are very very keen to move to https asap though, when we do passwords will be rehashed as well and cookie auth will be different effectively resetting everything. The sites logo is currently being delivered via https to see if anyone reports any issues as we test some of the certificates as I know quite a few places can have https issues with filtering.

 

I hope this information helps to explain why we are http currently.

 

EDIT: You can activate an extra security feature where you have to confirm your login when you log in from a new ip address (does not apply to mobile apps) if you scroll down to the bottom of here http://www.edugeek.net/profile.php?do=editoptions

Edited by ZeroHour
  • Thanks 4
Posted
Couldn't the SSL phase be offloaded to a proxy so vbulletin doesn't even need to care?

 

Yeah that wouldnt be too hard but there a huge huge amount of mixed content problems that hit breaking ssl and also leaking the secured data. I may try securing logins again to test our https certs for the new migration but I just hate lip service security.

  • Thanks 1
Posted
When is the new site being released?

 

Asap really. I have an open ticket right now with the importer they say I will get a fix next week then we will do a fresh import and enable test access for you guys to have a play and break. The test site is https enabled right now.

  • Thanks 1
Posted
HTTPS does also increase the load on the server, that's why a few different sites are holding off for now.

That used to be true, but AES is now fully accelerated on all but the most low-end cores from Intel and AMD, and also modern VIA and ARM chips. Unless you're running your website on an K8 Athlon X-series or a Core2Duo-era CPU, the overhead is negligible.

  • 4 weeks later...
  • 1 month later...
Posted (edited)

As usual the goal posts got moved for the new site with an upcoming major update they have which finally adds some of the features I was going to have to hack in.

 

On another front though I am hacking in https login for use on this site right now. Currently https login is mostly done (not live) which means password submission will be via https. I am hacking the ability to change the password via https as well as well as password resets as those are 2 other areas. Registration will hopefully follow but I have not had a good look at how to hack that in yet.

This is not secure in the way I would like as cookies are a problem but it does mean passwords wont be submitted in the clear. I will be getting the mods to test it soon once the hacks are done then it will go live.

Our certs seem to be working well as a lot of our static content like logo images, css and js is now via https to test and no one has reported an issue so far.

 

EDIT: just to say our mobile apps are already using https for everything besides images so logins etc via those are already secure.

Edited by ZeroHour
  • Thanks 2
  • 1 month later...
Posted (edited)

HTTPS Login is ready for testing before I switch us over this week.

If you want to try it please go to https://www.edugeek.net/https.php and report any issues you may have behind the mass of school filtering out there.

I would like to thank @Stuajnht for early testing helping me work through some of the quirks with his filtering at his school.

 

This will primarily allow us to test our certificates for any issues before we move the whole site over to https. It will secure your password when entered and when you are logged in the same page will let you change your account password via https as well.

Edited by ZeroHour
  • Thanks 1
  • 2 months later...
Posted
HTTPS is now live for logins as the default, if there are no reports of issues it will roll out further.

I haven't seen any issues crop up so far.

  • Thanks 1
  • 3 years later...
  • 2 years later...
Posted (edited)
Asap really. I have an open ticket right now with the importer they say I will get a fix next week then we will do a fresh import and enable test access for you guys to have a play and break.

 

This was 6 years ago! Are we actually any closer? Can we have a play of the new site please?

 

When this was posted the iPhone 7 was the Apple's latest offering, since then they have released 10 newer models. Microsoft released Windows 11, Server 2019 & Server 2022. Windows 7, Server 2008 & 2008 R2 went end of life. Cyber security is now much more of a priority but Edugeek, and IT specialist forum still doesn't support HTTPS. Something that was basic 10 years ago. It's a little embarrassing considering we are all supposed to be IT professionals.

Edited by FN-GM
  • Thanks 3
  • 5 weeks later...
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...