Page 1 of 4 1234 LastLast
Results 1 to 16 of 57

Thread: Where's HTTP SSL on Hexus?

  1. #1
    Senior Member
    Join Date
    Jul 2003
    Location
    Reading, Berkshire
    Posts
    1,250
    Thanks
    64
    Thanked
    53 times in 34 posts
    • tfboy's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD Ryzen 7 2700
      • Memory:
      • 2x8GB Corsair Vengeance LPX)
      • Storage:
      • Force MP600 1TB PCIe SSD
      • Graphics card(s):
      • 560 Ti
      • PSU:
      • Corsair RM 650W
      • Case:
      • CM Silencio 550
      • Operating System:
      • W10 Pro
      • Monitor(s):
      • HP LP2475w + Dell 2001FP
      • Internet:
      • VM 350Mb

    Where's HTTP SSL on Hexus?

    It seems that I now have to log in with an insecured connection. OK, chances of that being sniffed are small, but surely, at least logging in should be done via a secure page?
    I've tried, but https redirects to http only.

  2. #2
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,850
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Where's HTTP SSL on Hexus?

    I think something will have to be done soon with GDPR looming

  3. #3
    DR
    DR is offline
    on ye old ship HEXUS DR's Avatar
    Join Date
    Jul 2003
    Location
    HEXUS HQ, Elstree
    Posts
    13,411
    Thanks
    1,058
    Thanked
    831 times in 372 posts

    Re: Where's HTTP SSL on Hexus?

    It's coming we have a load of things in the work, including a new site, and forum.

  4. Received thanks from:

    ik9000 (06-06-2017),jimbouk (08-06-2017)

  5. #4
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Where's HTTP SSL on Hexus?

    Setup OpenVPN or use a SSH tunnel to connect to your home router when on an insecure connection. No more worries about unencrypted web-sites.

  6. #5
    Bagnaj97
    Guest

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Dashers View Post
    Setup OpenVPN or use a SSH tunnel to connect to your home router when on an insecure connection. No more worries about unencrypted web-sites.
    SSH tunnel to your home router only encrypts the data between your current location and home router. The connection between your home router and unencrypted web-sites is still unencrypted.

  7. #6
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Where's HTTP SSL on Hexus?

    So? Paranoid about UK Gov snooping on your Hexus opinions?

  8. #7
    Bagnaj97
    Guest

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Dashers View Post
    So? Paranoid about UK Gov snooping on your Hexus opinions?
    Not at all, just that your suggestion doesn't give you "No more worries about unencrypted web-sites." as there's still an unencrypted link between you and the endpoint.

  9. Received thanks from:

    Jonj1611 (06-06-2017)

  10. #8
    Senior Member
    Join Date
    Jul 2003
    Location
    Reading, Berkshire
    Posts
    1,250
    Thanks
    64
    Thanked
    53 times in 34 posts
    • tfboy's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD Ryzen 7 2700
      • Memory:
      • 2x8GB Corsair Vengeance LPX)
      • Storage:
      • Force MP600 1TB PCIe SSD
      • Graphics card(s):
      • 560 Ti
      • PSU:
      • Corsair RM 650W
      • Case:
      • CM Silencio 550
      • Operating System:
      • W10 Pro
      • Monitor(s):
      • HP LP2475w + Dell 2001FP
      • Internet:
      • VM 350Mb

    Re: Where's HTTP SSL on Hexus?

    I'm not so worried about my PC to home router connection as it's wired and any wireless is encrypted anyway with authentication.

    It's not the end of the world not having SSL, but seems a best practice thing and as everyone appears to be doing it, I was curious if it was an error, omission or something planned in the near future

  11. #9
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,331
    Thanks
    1,678
    Thanked
    1,272 times in 952 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Where's HTTP SSL on Hexus?

    Yeah I must admit I wondered why at least the log-in wasn't https, and maybe the acccount info pages too.

    Quote Originally Posted by DR View Post
    It's coming we have a load of things in the work, including a new site, and forum.
    A new site and forum? Interesting, but please don't break the forum. Having dotted round a few music forums in the last week this site is head and shoulders better than a good number out there when it comes to both format and function.

    Quote Originally Posted by Dashers View Post
    So? Paranoid about UK Gov snooping on your Hexus opinions?
    I think they have bigger things on their hands right now though tbh. Screening text is a doddle, they'll get through this site in no time with the tech they'll have available. But if they really care what my views are on Asus false advertising the P7H55M-USB3 and whether a circular runway is feasible then they can go for it.

  12. #10
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Bagnaj97 View Post
    Not at all, just that your suggestion doesn't give you "No more worries about unencrypted web-sites." as there's still an unencrypted link between you and the endpoint.
    Indeed they may still be unencrypted, but there's no need to worry about that when on a trusted line.

  13. #11
    Splash
    Guest

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Dashers View Post
    Indeed they may still be unencrypted, but there's no need to worry about that when on a trusted line.
    As soon as your connection leaves the network that you control those it's an untrusted network. The internet is a leper colony, and sending credentials in plaintext should be highly discouraged - you wouldn't login to your online banking over HTTP from your home network, would you?

  14. #12
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Splash View Post
    As soon as your connection leaves the network that you control those it's an untrusted network. The internet is a leper colony, and sending credentials in plaintext should be highly discouraged - you wouldn't login to your online banking over HTTP from your home network, would you?
    You're changing the goal-posts. This was talking about accessing unencrypted web-sites like Hexus on an open or "untrusted" network.

    I'd trust my ISP not to be interested in doing deep-packet-inspection to harvest my passwords for unsecured web-sites more than the government not to coerce CAs to allow them to intercept "secure" channels.

  15. #13
    Editable... jimbouk's Avatar
    Join Date
    Aug 2005
    Location
    Bristol
    Posts
    2,808
    Thanks
    241
    Thanked
    238 times in 191 posts
    • jimbouk's system
      • Motherboard:
      • Asrock B450M-HDV R4.0
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4 3200 MHz C16
      • Storage:
      • Sabrent Rocket Q 1TB NVMe PCIe M.2 2280
      • Graphics card(s):
      • Sapphire Pulse RX 580 8GB
      • PSU:
      • Seasonic Core Gold GC-650
      • Case:
      • Lian-Li PC-V1100 ATX
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC CU34G2/BK 34" Widescreen
      • Internet:
      • EE FTC

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by DR View Post
    It's coming we have a load of things in the work, including a new site, and forum.
    Sounds exciting, looking forward to it

  16. #14
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,230
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by Dashers View Post
    ... I'd trust my ISP not to be interested in doing deep-packet-inspection ...
    And when the traffic leaves your ISPs control? The internet isn't like an end-to-end courier service. You send the request to your ISP, and they basically just give it to the first person they meet who's going in the right direction. And that happens all the way down the line until it hits the destination. Your ISP have no control whatsoever past their own endpoints, and ANYONE could end up carrying the data. And you'll never be completely sure who's handled it.

  17. #15
    Splash
    Guest

    Re: Where's HTTP SSL on Hexus?

    You don't need DPI to sniff traffic sent plaintext. Traffic sent over HTTP is sent plaintext.

    I repeat: the I tenet is a leper colony. If you're interested enough to VPN to your home connection I'm amazed that you're not all for SSL(well, TLS) encrypted logins.

  18. #16
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Where's HTTP SSL on Hexus?

    Quote Originally Posted by scaryjim View Post
    And when the traffic leaves your ISPs control? The internet isn't like an end-to-end courier service. You send the request to your ISP, and they basically just give it to the first person they meet who's going in the right direction. And that happens all the way down the line until it hits the destination. Your ISP have no control whatsoever past their own endpoints, and ANYONE could end up carrying the data. And you'll never be completely sure who's handled it.
    "My ISP"/"random telehouse handling mindboggling amounts of low-latency switching".

    Yes, anyone of the switching houses and backbones that furnish the Internet will have your delicate vulnerable packets.

    They are not in the habit of sniffing packets randomly for passwords due to the shear volume of data that is handled.

    And remember, we're still talking about low-value sites such as Hexus and not your Internet banking.

    Quote Originally Posted by Splash View Post
    You don't need DPI to sniff traffic sent plaintext. Traffic sent over HTTP is sent plaintext.

    I repeat: the I tenet is a leper colony. If you're interested enough to VPN to your home connection I'm amazed that you're not all for SSL(well, TLS) encrypted logins.
    This is factually incorrect. You entirely do need DPI to sniff the content of packets. That's exactly what DPI is - inspecting the content of the packet instead of just the IP header. Your password is a HTTP POST which is very much high up that old network stack.

Page 1 of 4 1234 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •