Steven P. Administrators Posted August 9, 2013 Administrators Share Posted August 9, 2013 We're happy to announce that we've added SSL sessions for Tier 2 ad free subscribers. Currently this is only active on the main news site, the forums will follow shortly. Even more reason to subscribe :p Inevitable answers to questions: Q: Why isn't it available for everyone A: Because most of our ad partners don't support SSL delivery. Q: Why not look for a different advertiser? A: The certificate wasn't free, nor the work to implement it; therefore a Tier 2 adfree perk. Enjoy! Ian W, Phouchg, neo1911 and 5 others 8 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/ Share on other sites More sharing options...
articuno1au Posted August 9, 2013 Share Posted August 9, 2013 NSA resistance + 1. fusi0n, The Evil Overlord, gohpep and 4 others 7 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868233 Share on other sites More sharing options...
+Anarkii Subscriber² Posted August 9, 2013 Subscriber² Share Posted August 9, 2013 Awesome thanks to all involved :) Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868237 Share on other sites More sharing options...
bmdixon Posted August 9, 2013 Share Posted August 9, 2013 Should we be redirected automatically to https or do we need to specify it? Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868249 Share on other sites More sharing options...
+BudMan MVC Posted August 9, 2013 MVC Share Posted August 9, 2013 So when is the login going to post via SSL vs how it currently sends which is just http in clear text for username and password Its a forum, its a news site - I don't really see any need for anything to be SSL --- OTHER THAN when I send my password ;) +LogicalApex, Raa, +Heartripper and 4 others 7 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868291 Share on other sites More sharing options...
Jason S. Global Moderator Posted August 9, 2013 Global Moderator Share Posted August 9, 2013 im not seeing any https: on the main news site. when i manually type in https://www.neowin.net it seems to work but i dont see any other SSL cert info. what am i missing? Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868303 Share on other sites More sharing options...
SuperKid Posted August 9, 2013 Share Posted August 9, 2013 So when is the login going to post via SSL vs how it currently sends which is just http in clear text for username and password passwordinclear.png Its a forum, its a news site - I don't really see any need for anything to be SSL --- OTHER THAN when I send my password ;) @Neobond Yeah, can we get SSL for EVERYONE when it sends the username and password on the login? a POST over SSL won't mess with the advertisements. thealexweb 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868323 Share on other sites More sharing options...
Sandor Posted August 9, 2013 Share Posted August 9, 2013 Implying it isn't stored in plain text in the DB...lol Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868357 Share on other sites More sharing options...
Torolol Posted August 9, 2013 Share Posted August 9, 2013 SSL certificates is expensive, what C.A issuer that neowin will use? Because most of our ad partners don't support SSL delivery. Theres was ad blocking services that actively listing ad-server certificates so their users can put those certificates into "Untrusted" or "Revoked" categories, which effectively prevent any known SSL ads. Knowing this most ads services won't bother to obtaining SSL certificates. Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868359 Share on other sites More sharing options...
+BudMan MVC Posted August 9, 2013 MVC Share Posted August 9, 2013 So only a B, you seem to have some chain issues https://www.ssllabs.com/ssltest/analyze.html?d=www.neowin.net&s=74.204.71.246 Seems you did not install the intermediate CA bundle?? https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id=AR1372&actp=LIST&viewlocale=en_US Please Note: On June 27th, 2010 Thawte upgraded its root hierachy to 2048bit RSA Keys to enhance the security of all SSL products. As a part of this upgrade, all newly issued certificates now require the installation of the new Primary and Secondary Intermediate CA's along with your SSL certificate. These new Intermediate CA's MUST be installed in order for your SSL certificate to be fully trusted in all browsers. This causes an issue with firefox on the cert +LogicalApex 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868391 Share on other sites More sharing options...
spudtrooper Posted August 9, 2013 Share Posted August 9, 2013 SSL certificates is expensive, what C.A issuer that neowin will use? They're not expensive.. you can get chained certs that work wit most modern browsers for < 60 bucks a year, otherwise root certs are around 80 bucks + (can be found cheaper on deals..) SSL is cheaper than a data breach and hell, i would have helped pitch in for a cert if it meant everyone got it, SSL for subs is.. lame.. looks like it is a chained cert. hell, godaddy has a chained cert without all the extras for like 5 bucks http://www.godaddy.com/compare/gdcompare3_ssl.aspx?isc=dssl027&utm_source=MSN&utm_medium=cpc&utm_term=cheap%20ssl&utm_content=2400118724&utm_campaign=8936109240&ef_id=USaBHwAAAQUOWoSL:20130809130902:s Premium feature worthy? not sure why anyone would go direct with thawt though, but they do have a large reseller network, so hopefully neowin didn't pay full retail for a chained. Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868393 Share on other sites More sharing options...
Sandor Posted August 9, 2013 Share Posted August 9, 2013 SSL for subs is.. lame.. +9001 Lirodon 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868401 Share on other sites More sharing options...
Haggis Veteran Posted August 9, 2013 Veteran Share Posted August 9, 2013 So really what your saying is that only the people that pay for Tier 2 Subs are worth protecting for passwords sending ?? and not the people that come on here and helps others for free? Great! Konstantine and FarCry3r 2 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868811 Share on other sites More sharing options...
Draconian Guppy Posted August 9, 2013 Share Posted August 9, 2013 So really what your saying is that only the people that pay for Tier 2 Subs are worth protecting for passwords sending ?? and not the people that come on here and helps others for free? Great! I thought passwords already have some kind of protection and that SSL is just adding another layer? Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868825 Share on other sites More sharing options...
Haggis Veteran Posted August 9, 2013 Veteran Share Posted August 9, 2013 I thought passwords already have some kind of protection and that SSL is just adding another layer? as budman says they are sent in Cleartext Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868831 Share on other sites More sharing options...
Draconian Guppy Posted August 9, 2013 Share Posted August 9, 2013 as budman says they are sent in Cleartext Yeah, but wouldn't someone have to compromise ones PC or the Hosts Pc in order for that to be a matter? Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868833 Share on other sites More sharing options...
rr_dRock Posted August 9, 2013 Share Posted August 9, 2013 It always amazes me when people complain about how someone else runs THEIR free service. How about contributing to the sites monetary needs if you have such a problem with it? You may provide support to others for free, but to feed the monster they need virgin blood and that ****s expensive and can't be paid for with computer advice.Neobond explained why it's not available to everyone, quit your bitchin... Nick H., Chasethebase, +Anarkii and 5 others 8 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868837 Share on other sites More sharing options...
Unksi Posted August 9, 2013 Share Posted August 9, 2013 Yeah, but wouldn't someone have to compromise ones PC or the Hosts Pc in order for that to be a matter? If they have a router or other network device running between the server and your PC, no. Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868843 Share on other sites More sharing options...
Draconian Guppy Posted August 9, 2013 Share Posted August 9, 2013 If they have a router or other network device running between the server and your PC, no. Ah well then I don't see the fuss about not having SSL logins then :P Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868845 Share on other sites More sharing options...
+BudMan MVC Posted August 9, 2013 MVC Share Posted August 9, 2013 There was a thread a long time ago about the login posting being in clear text.. If I recall back then it was mentioned that it would be fixed when ssl was setup. Well it seems that have setup ssl.. There is no need to encrypt the whole site.. sorry but I don't need my viewing of news articles or forum post to be encrypted. Nor do I need the stuff I am sending in a post that will be public encrypted. What I would like is my password not to be sent in clear text. They have the ssl in place, all they need to do is change the posting from http to https and we are all good. They can still require that you be a sub if you want the whole site via https, ads or no ads. But changing http to https in the post string for your login seems like a no brainer if the ssl cert has already been paid for and active. Currently even if viewing the site view https, when I go to login the post in the html command is vis http.. So going to be sent in clear - even if everything else your viewing is via https -- the actual post of the username and password is still only http.. edit: For those that do not understand the issue. No your pc does not have to be compromised for someone to sniff your username and password.. So example your on a wireless network, anyone on that wireless network could see your traffic so could see your neowin username and password. Now could they just hijack your cookie and auth as you that way - possible have not looked into the issue that deep, nor do I care too. At any point between your PC and the neowin server it would be possible to see this traffic in the clear and get your username and password. I doubt that it is of much concern, but come on the ssl is there -- just change the post to https and this can discussion is over. Even if your viewing gmail over http, when you go to login the post is https <form novalidate id="gaia_loginform" action="https://accounts.google.com/ServiceLoginAuth" method="post"> <input type="hidden" <form action="https://www.neowin.net/forum/index.php?app=core&module=global§ion=login&do=process" method="post" id='login'> Simple change of a couple lines of code to https vs http and issue goes away now that they have ssl in place. Haggis, Phouchg, Lewism and 4 others 7 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868861 Share on other sites More sharing options...
Haggis Veteran Posted August 9, 2013 Veteran Share Posted August 9, 2013 It always amazes me when people complain about how someone else runs THEIR free service. How about contributing to the sites monetary needs if you have such a problem with it? You may provide support to others for free, but to feed the monster they need virgin blood and that ****s expensive and can't be paid for with computer advice. Neobond explained why it's not available to everyone, quit your bitchin... Neobond already knows i will be tier two soon anyway lol fusi0n 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868865 Share on other sites More sharing options...
Ambroos Posted August 9, 2013 Share Posted August 9, 2013 Ah well then I don't see the fuss about not having SSL logins then :p Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure. Seahorsepip 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868895 Share on other sites More sharing options...
Draconian Guppy Posted August 9, 2013 Share Posted August 9, 2013 Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure. So there's even an alternative... :P rr_dRock 1 Share Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595868905 Share on other sites More sharing options...
Seahorsepip Veteran Posted August 9, 2013 Veteran Share Posted August 9, 2013 Public WiFi Hotspot = everyone instantly has your username and password. You should never, ever send your password unencrypted over a network that can possibly be used by others. I use Facebook login instead, which is secure. What about tor or a proxy is that still unencrypted? I remember proxies can be encrypted but I don't know about tor :/ Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595869001 Share on other sites More sharing options...
Torolol Posted August 9, 2013 Share Posted August 9, 2013 What about tor or a proxy is that still unencrypted? I remember proxies can be encrypted but I don't know about tor :/ if the proxy support SSL Pass-Thru, https connection is no problem. Some proxies doesn't support that however. Link to comment https://www.neowin.net/forum/topic/1169735-https-sessions-active-for-tier-2-subscribers/#findComment-595869013 Share on other sites More sharing options...
Recommended Posts