Jump to content

Recommended Posts

  • 3 years later...
Posted
Just wondered if we were any closer on moving the site to HTTPS?

 

Just came back for a visit for the first time in a few years and this was my first thought when my firefox https everywhere settings warned of http only...

 

PS Hello everyone :)

  • Thanks 1
  • 9 months later...
Posted
If the application is too old for this sort of thing it should be really simple to do on the load balancers
Posted
THis definitely needs looking at, plus vBulletin is dead. If it's a case of technical abilities etc. I would be more than happy to donate to fund a developer to do the work etc.
  • Thanks 1
Posted
Please can we have an update this is honestly getting daft now - we should be a model of good practice - not using HTTPS in 2022 is ridiculous.
  • Thanks 3
  • 2 weeks later...
Posted (edited)
Bump

 

An update to where the site is on this would be great.

Bumpity bump bump bump @ZeroHour

 

Apoloogies if this comes across as nagging, but surely some communication on this is not too much to ask? :)

Edited by Cat_Jam148
  • Thanks 2
Posted
It's a shame there's been no response.

 

In all fairness to the guys there have been lots of responses telling you the same thing which is they're doing it on the new platform.

 

Now yes maybe it's a "soon" (TM Blizzard) response as to when that will be, but there have been lots of replies to the same question :p

 

Steve

Posted
In all fairness to the guys there have been lots of responses telling you the same thing which is they're doing it on the new platform.

 

Now yes maybe it's a "soon" (TM Blizzard) response as to when that will be, but there have been lots of replies to the same question :p

 

Steve

 

Nothing in quite some time and it is now really poor that the site that is meant to represent a community of people committed to discussing and following best practice isn't doing so with their own community site.

 

People have been very patient, no one is asking for something to happen overnight but AFAIK there's been no update on progress in a very long time and it's poor we're half way through 2022 with a site that most browsers now flag as not secure.

Posted

If it was just a case of starting from a fresh slate, I'm sure the team would of had a fully HTTPS site up and running years ago, however if they are trying to ensure all posts from the current system are copied over with the search engine linking not breaking and the platform of choice having updates at times after resources have been put into making it do just what as been released (based on the several threads posted over the last few years) then it's not exactly a small task.

 

So browsers report the site as "not secure"... not a big issue for me since the logins are secure. I'm sure Dos_Box and Zerohour will post when they have something to pass on, and of course we're all free to use the site or not I guess.

Posted
If it was just a case of starting from a fresh slate, I'm sure the team would of had a fully HTTPS site up and running years ago, however if they are trying to ensure all posts from the current system are copied over with the search engine linking not breaking and the platform of choice having updates at times after resources have been put into making it do just what as been released (based on the several threads posted over the last few years) then it's not exactly a small task.

 

So browsers report the site as "not secure"... not a big issue for me since the logins are secure. I'm sure Dos_Box and Zerohour will post when they have something to pass on, and of course we're all free to use the site or not I guess.

 

I'm sure management are aware, but none of these things are necessary to apply an ssl certificate. It's simply a case of running an HAProxy/Envoy/Nginx etc loadbalancer in front of the server and using this to supply the certificate. It wouldn't even need downtime. As we are speculating my guess is it's that it's not worth fixing a dying platform if the new one is 'soon'. Assuming soon is in geological terms.

Posted
I'm sure management are aware, but none of these things are necessary to apply an ssl certificate. It's simply a case of running an HAProxy/Envoy/Nginx etc loadbalancer in front of the server and using this to supply the certificate. It wouldn't even need downtime. As we are speculating my guess is it's that it's not worth fixing a dying platform if the new one is 'soon'. Assuming soon is in geological terms.

 

FWIW; Assuming a loadbalancer is too much overhead (which I can't see how it would be), Cloudflare is a super simple gui setup and will do SSL termination with DoS protection and a web firewall for $20 per month.

Posted
I'm sure management are aware, but none of these things are necessary to apply an ssl certificate. It's simply a case of running an HAProxy/Envoy/Nginx etc loadbalancer in front of the server and using this to supply the certificate. It wouldn't even need downtime. As we are speculating my guess is it's that it's not worth fixing a dying platform if the new one is 'soon'. Assuming soon is in geological terms.

 

It's not really speculating, all of these suggestions have been discussed before and they've given reasons why :p There are dozens of threads regarding the same issue over the last few years (Without waffling it was about the mixed content warnings with vbulletin which most browsers block and manual changes across the masses of data unless re-writing every url etc regarding the loadbalancer etc, but the latest issue was with importing tags into the new provider which was affecting thousands of posts when the last update was posted)

 

I guess all my point is no-one can claim they haven't had answers or responses, it's more just that people don't like the timeline. But there's not much that can be changed with that based on the responses everyones had already.

 

Steve

Posted

It’s not that I don’t like the timeline. It’s that there doesn’t appear to be a timeline. They said “soon” in 2018.

 

It might not both you as an individual if the site isn’t HTTPS but it doesn’t look good that our site is being flagged as not-secure when the vast majority of other sites sorted this quite some time ago.

 

I can claim we haven’t had a response when we haven’t had a response - previous responses are from so long ago. People aren’t being unreasonable in their polite requests for an update which hasn’t been forthcoming.

  • 1 year later...
Posted
MWe are pretty much there now

 

It has been another 12 months and we still aren't HTTPS - how much longer please? Another year?

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...