Quatermass Posted June 13, 2019 Posted June 13, 2019 Our admin users need Chrome for their CPOMS U2F keys...
sted Posted June 13, 2019 Posted June 13, 2019 yup few people have mentioned it to me this morning as well
Jaan Posted June 13, 2019 Posted June 13, 2019 From CPOMS: ---- Good morning, Thank you for your email. We have some reports today – Thursday 13 June that Google Chrome is once again serving some users with a ‘Deceptive site ahead’ warning as they try to access their CPOMS page. This is the same warning that we believe Google incorrectly applied on Wednesday 22 May 2019 which they later removed that evening. We want to assure users that there is nothing wrong with CPOMS and that it continues to function normally. In order to access your site you have two options: Select ‘Details’ on the warning screen and then ‘visit this unsafe site’ We appreciate that some users might not wish to select the unsafe site option which is perfectly understandable. To that end you can access your CPOMS site as normal via Internet Explorer (Windows Users) and Opera (Mac Users) We are doing everything we can to expedite a resolution from Google and will seek to have the warning removed as soon as is practically possible. In the meantime we want to apologise for any inconvenience caused and reassure you that CPOMS can be accessed as normal via the browsers noted above. Kind Regards,
sted Posted June 13, 2019 Posted June 13, 2019 thats all very well but im going to guess you dont get on googles "naughty list" for nothing twice
Jaan Posted June 13, 2019 Posted June 13, 2019 that's all very well but im going to guess you don't get on googles "naughty list" for nothing twice Which is why we've blocked it for staff, until it's resolved. #GDPRisAlie
localzuk Posted June 13, 2019 Posted June 13, 2019 My guess is they are doing something odd in the way they host the subdomains. Looking at the code for the site, there do seem to be some rather odd issues with it. Seeing / instead of slashes. They seem to be missing a https: before one of their script source files too.
Gorbyhail Posted June 13, 2019 Posted June 13, 2019 Happening again for us... only one report thus far although I expect others know about the IE workaround from the last occurrence.
Gorbyhail Posted June 13, 2019 Posted June 13, 2019 Wondering if we can expect this to be a regular occurrence... twice is one more than too much.
Jaan Posted June 13, 2019 Posted June 13, 2019 Wondering if we can expect this to be a regular occurrence... twice is one more than too much. I agree. Can't be good for business, we're already getting raised eyebrows here. 1
Quatermass Posted June 13, 2019 Posted June 13, 2019 Indeed, given its crucial role - it's not just any old site 1
Cazale Posted June 13, 2019 Posted June 13, 2019 All our schools are effected with this. I've been getting e-mails and calls all day about it (again). Their advice was to click details and then proceed past the security warning. Almost every school has responded along the lines of "well that sounds dodgy considering what we're using it for!" (to which I reply that I'm just passing along their advice, so feel free to ignore it). It sucks, I don't want to be getting people into the habit of doing what they're recommending to do! It really doesn't look good for them, especially having happened twice in a month. Are there any alternatives?
Marci Posted June 14, 2019 Posted June 14, 2019 My guess is they are doing something odd in the way they host the subdomains. Looking at the code for the site, there do seem to be some rather odd issues with it. Seeing / instead of slashes. They seem to be missing a https: before one of their script source files too. Missing protocol is perfectly normal - just means any scripts are loaded with the same protocol used to request the page and avoids errors relating to mixed mode content.
localzuk Posted June 14, 2019 Posted June 14, 2019 Missing protocol is perfectly normal - just means any scripts are loaded with the same protocol used to request the page and avoids errors relating to mixed mode content. Huh. Never seen that before - seems sloppy to me. Especially if the entire site is always served as https. It is also risky. https://www.paulirish.com/2010/the-protocol-relative-url/
lmcuak Posted June 14, 2019 Posted June 14, 2019 we had it on 1 pc yesterday but only that one very bizarre
mavhc Posted June 14, 2019 Posted June 14, 2019 Where does the Learn More link from google's red page go to?
Danp Posted June 14, 2019 Author Posted June 14, 2019 Indeed, given its crucial role - it's not just any old site /\ this. Being questioned here too.
Danp Posted July 16, 2019 Author Posted July 16, 2019 It's damn slow today, keeps timing out saying their site is under too much load. Good job it's holiday time for us and CPOMS isn't being used as much as normal otherwise the powers that be would be having words.
BFCIT Posted July 16, 2019 Posted July 16, 2019 Same as you here Danp - Website under heavy load queue full message.
Danp Posted July 16, 2019 Author Posted July 16, 2019 Sure it's unrelated but I just opened the app on my phone to login and it's asking me to scan the QR code again. Problem is it won't let me because I had it setup in the past, I've had to email them to get them to remove the security key linked to my account.
mavhc Posted July 16, 2019 Posted July 16, 2019 Sure it's unrelated but I just opened the app on my phone to login and it's asking me to scan the QR code again. Problem is it won't let me because I had it setup in the past, I've had to email them to get them to remove the security key linked to my account. Good job it's impossible to fake an email or the entire 2FA system would be pointless 2
Danp Posted July 16, 2019 Author Posted July 16, 2019 Good job it's impossible to fake an email or the entire 2FA system would be pointless I know, I'll see what their response is like, if they just remove it and let me in then that's a failure
djrscally Posted July 16, 2019 Posted July 16, 2019 Sure it's unrelated but I just opened the app on my phone to login and it's asking me to scan the QR code again. Problem is it won't let me because I had it setup in the past, I've had to email them to get them to remove the security key linked to my account. Their app is garbage, it constantly drops those settings, but there's not really any reason to use it. They're just using OTP, so any OTP app will work just fine. Google authenticator for example, or Free OTP. I started switching people to one of those and we never had problems again. https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 https://play.google.com/store/apps/details?id=org.fedorahosted.freeotp&hl=en_US 1
fiendishlyclever Posted July 16, 2019 Posted July 16, 2019 I know, I'll see what their response is like, if they just remove it and let me in then that's a failure We used to reset it for each other - all of our DPs could do this (although I've not used it for 18 months so functionality may have changed) I preferred authy to their app - why all these organisations try to get you to install their apps which all use the same standard...[emoji33]
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now