Results 1 to 26 of 26

Thread: Unsecure?

  1. #1
    Contributing Member Steve Demeter's Avatar
    Join Date
    07.01.01
    Location
    Beavercreek, Ohio 45434
    Posts
    6,372
    Liked: 909

    Default Unsecure?

    Firefox has started telling me that my log in on Apex is an insecure site.

    Has Firefox gone mad?????

  2. #2
    Classifieds Super License HayesCages's Avatar
    Join Date
    01.28.08
    Location
    Sagle, Idaho
    Posts
    1,556
    Liked: 180

    Default

    It's a Microsoft thing.
    Lawrence Hayes
    Hayes Cages, LLC
    Sagle, ID.

  3. #3
    Senior Member
    Join Date
    04.30.11
    Location
    NC
    Posts
    1,356
    Liked: 304

    Default

    Has Firefox gone mad?????
    Yes. They all do eventually.

  4. The following members LIKED this post:


  5. #4
    Senior Member xmazdatracy's Avatar
    Join Date
    09.28.11
    Location
    behind you
    Posts
    449
    Liked: 130

    Default

    I noticed that too. I wonder about switching to chrome.

  6. #5
    Administrator dc's Avatar
    Join Date
    11.24.00
    Location
    Chicagoland, Illinois
    Posts
    5,526
    Liked: 1417

    Default

    Odd, must be a PC thing. Not showing any issues on a Mac.

    We are currently working on a major forum upgrade at the moment, so hang tight, there will be good things coming.

  7. The following members LIKED this post:


  8. #6
    Classifieds Super License BeerBudgetRacing's Avatar
    Join Date
    09.04.13
    Location
    Goleta, California
    Posts
    4,179
    Liked: 1262

    Default

    Chrome and Firefox will not tell you connections are not secure if
    you do not connect via https......
    you connected via https and the website does not have a SHA-2 certifcate
    (many certificates issues for multiple years are SHA-1)

    I think Safari, like Internet Explorer, isn't warning......
    Last edited by BeerBudgetRacing; 03.15.17 at 1:44 PM.

  9. The following 2 users liked this post:


  10. #7
    Contributing Member DaveW's Avatar
    Join Date
    06.25.01
    Location
    Bath, OH
    Posts
    6,190
    Liked: 3322

    Default

    Quote Originally Posted by Steve Demeter View Post
    Firefox has started telling me that my log in on Apex is an insecure site.

    Has Firefox gone mad?????
    It's just a warning - any time a site is not "https" you may get that. I have not gotten it here, but on other non-secure sites I have.
    Dave Weitzenhof

  11. #8
    Senior Member mmi16's Avatar
    Join Date
    04.05.07
    Location
    Maryland
    Posts
    989
    Liked: 307

    Default

    Believe Firefox just issued a 'security upgrade'.

  12. #9
    Contributing Member John Nesbitt's Avatar
    Join Date
    07.04.03
    Location
    Ottawa
    Posts
    1,746
    Liked: 910

    Default

    Chrome warns that it is not a secure site (i.e. http, not https).


    Quote Originally Posted by xmazdatracy View Post
    I noticed that too. I wonder about switching to chrome.
    John Nesbitt
    ex-Swift DB-1

  13. #10
    Senior Member xmazdatracy's Avatar
    Join Date
    09.28.11
    Location
    behind you
    Posts
    449
    Liked: 130

    Default


  14. The following members LIKED this post:


  15. #11
    Contributing Member DaveW's Avatar
    Join Date
    06.25.01
    Location
    Bath, OH
    Posts
    6,190
    Liked: 3322

    Default

    Quote Originally Posted by DaveW View Post
    It's just a warning - any time a site is not "https" you may get that. I have not gotten it here, but on other non-secure sites I have.
    Quote Originally Posted by John Nesbitt View Post
    Chrome warns that it is not a secure site (i.e. http, not https).
    I use Chrome and I don't get the warning for ApexSpeed...
    Dave Weitzenhof

  16. The following members LIKED this post:


  17. #12
    Contributing Member John Nesbitt's Avatar
    Join Date
    07.04.03
    Location
    Ottawa
    Posts
    1,746
    Liked: 910

    Default

    Quote Originally Posted by DaveW View Post
    I use Chrome and I don't get the warning for ApexSpeed...
    As you say, it is just a warning - http, not https. Still, with a password-protected userid ...

    Look in the address bar, to the left of www.apexspeed.com, you should see a circle with an exclamation point inside.
    John Nesbitt
    ex-Swift DB-1

  18. #13
    Administrator dc's Avatar
    Join Date
    11.24.00
    Location
    Chicagoland, Illinois
    Posts
    5,526
    Liked: 1417

    Default

    I don't know of any forums using SSLs, so I'm not sure why the browsers are now searching for an SSL on every domain.


  19. #14
    Classifieds Super License BeerBudgetRacing's Avatar
    Join Date
    09.04.13
    Location
    Goleta, California
    Posts
    4,179
    Liked: 1262

    Default

    Quote Originally Posted by DaveW View Post
    I use Chrome and I don't get the warning for ApexSpeed...
    You WILL get a warning if you login. If you are already logged in and stay logged in you won't get the warning.

    It detects masked fields (where what you type is hidden) and expects https when those fields are present.....

  20. The following members LIKED this post:


  21. #15
    Contributing Member DaveW's Avatar
    Join Date
    06.25.01
    Location
    Bath, OH
    Posts
    6,190
    Liked: 3322

    Default

    Quote Originally Posted by BeerBudgetRacing View Post
    You WILL get a warning if you login. If you are already logged in and stay logged in you won't get the warning.

    It detects masked fields (where what you type is hidden) and expects https when those fields are present.....
    Interesting. Learn something new every day. I'll look for it when I next have to log in.
    Dave Weitzenhof

  22. #16
    Contributing Member John Nesbitt's Avatar
    Join Date
    07.04.03
    Location
    Ottawa
    Posts
    1,746
    Liked: 910

    Default

    Quote Originally Posted by Doug Carter View Post
    I don't know of any forums using SSLs, so I'm not sure why the browsers are now searching for an SSL on every domain.

    Given the amount of commerce and other confidential stuff going across the interwebz, I suspect that it would be best practice for browsers to warn you that a site is using http, not https.

    As you say, forums are maybe not a high-security application. As long as I use a different password and user name on my bank accounts etc., I do not give it any worry.

    I think that I speak on behalf of all of us when I say thanks for maintaining this site.
    Last edited by John Nesbitt; 03.15.17 at 1:57 PM. Reason: Sperring
    John Nesbitt
    ex-Swift DB-1

  23. #17
    Senior Member
    Join Date
    05.08.10
    Location
    Pittsburgh
    Posts
    743
    Liked: 296

    Default

    Just burn the house down. It's got viruses and is going to steel the change off your dresser.
    Chris Livengood, enjoying underpriced ferrous whizzy bits that I hacked out in my tool shed since 1999.

  24. The following 2 users liked this post:


  25. #18
    Contributing Member TimW's Avatar
    Join Date
    01.30.03
    Location
    Santa Cruz, CA
    Posts
    2,570
    Liked: 23
    ------------------
    'Stay Hungry'
    JK 1964-1996 #25

  26. #19
    Senior Member Cameron Wagner's Avatar
    Join Date
    09.28.04
    Location
    Vancouver, WA
    Posts
    110
    Liked: 9

    Default

    The company I am working for is in the middle of a "convert all our sites to secure (SSL)" initiative. Executives freak out when they read scary press releases. It's painful for larger companies like ours with tens of thousands of domains and dynamic content served cross-domain. Don't get me started about "flash is going away"... the RTMP protocol is just too valuable and there are no standards for live streaming video yet. I long for the simple days of IE vs. Firefox.

    Submitting all forms like login or registration to a secure domain will alleviate a bunch of error messages like this, even if the base site is http://. If you're on https:// and submit a form to http://, most browsers will throw a nasty error that scares people away nowadays. Just getting an SSL cert for apexspeed.com every year is another thing that costs money unfortunately. Then you need to make sure external content like images from a CDN are also served thru SSL to prevent other error messages from showing in the console (for now).

    I do know for sure that Google is penalizing SE-marketers for not serving from an SSL-certified domain.

  27. The following 2 users liked this post:


  28. #20
    Contributing Member
    Join Date
    04.17.06
    Location
    Vancouver, BC
    Posts
    389
    Liked: 17

    Default

    I just noticed, after all these years, that this site does not use TLS (https). When logging in to this site, your credentials are passed around as plain text that anyone in the middle can read.

    Use the same password for your email associated with this account? You could be in trouble.

    Use a unique password for this site and assume it is compromised.

    Doug, look into a low cost cert provider like letsencrypt. I can not stress how important this is.

  29. The following members LIKED this post:


  30. #21
    Senior Member holmberg's Avatar
    Join Date
    06.11.06
    Location
    Lafayette, CA
    Posts
    383
    Liked: 98

    Default

    Yes, the whole internet is moving to HTTPS secured with SSL/TLS certificates. It's been happening for several years now.

    With HTTP, anyone can listen and grab the passwords.

    It may not sound important for apexspeed.com (it's not a bank, afterall), but are there any cases where apexspeed.com retains credit card numbers? Say, for example, for the new paid classified ads? Or perhaps for donations?

    If so, those credit cards numbers could easily be stolen from apexspeed.com as it is configured today.

  31. #22
    Administrator dc's Avatar
    Join Date
    11.24.00
    Location
    Chicagoland, Illinois
    Posts
    5,526
    Liked: 1417

    Default

    We don't use or hold CC #s for any reason.

    We are looking into an SSL for ApexSpeed, but because there is no serious secure information handled with our forum, it hasn't been a priority.

  32. The following 4 users liked this post:


  33. #23
    Contributing Member
    Join Date
    04.17.06
    Location
    Vancouver, BC
    Posts
    389
    Liked: 17

    Default

    Quote Originally Posted by dc View Post
    We don't use or hold CC #s for any reason.

    We are looking into an SSL for ApexSpeed, but because there is no serious secure information handled with our forum, it hasn't been a priority.
    I just noticed that the site still does not use TLS/SSL. While there is no 'secure' information being handled, user passwords themselves should be treated as requiring secure transmission. A LOT of people use the same password for multiple sites, so your ApexSpeed password could also be your Amazon password, or say your email password. This is far more common than you would think, which is why bad actors still try to obtain unsalted, or worse un-hashed, passwords off of forums such as these.

  34. #24
    Administrator dc's Avatar
    Join Date
    11.24.00
    Location
    Chicagoland, Illinois
    Posts
    5,526
    Liked: 1417

    Default

    We are in the process of setting up an SSL, though it's taking longer than expected because we just moved (again, for the final time) and need to re-establish all of the business records for the new location before the SSL can be verified. I love waiting on the government to keep the process moving.

    Should be set up in the next couple of weeks, and we'll make an announcement when the domain will be changing to the new secure address.

  35. The following 2 users liked this post:


  36. #25
    Classifieds Super License
    Join Date
    09.13.02
    Location
    San Francisco
    Posts
    570
    Liked: 77

    Default Security

    I haven’t read all the posts on this and know diddly about running a site but I do remember FF Underground that completely disappeared years ago and it was a great shame. The password I’ve used here since 2012 would not g3 accepted by any modern site as too weak.
    id hate to see this great repository of knowledge disappear like FF Underground did.
    Hybels

  37. #26
    Administrator dc's Avatar
    Join Date
    11.24.00
    Location
    Chicagoland, Illinois
    Posts
    5,526
    Liked: 1417

    Default

    The new SSL should be set up sometime this week. What a bunch of BS to have to do to "secure" a site that isn't dealing with finances or transactions. Such a ridiculous money grab. We will look back on this era of website "security" and laugh at how much of a red herring it was.

    We will have 301 re-directs in place so your links will still work, but the site will be down for a brief time coming up at some point this week for the changeover.

  38. The following 3 users liked this post:


Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  




About Us
Since 2000, ApexSpeed.com has been the go-to place for amateur road racing enthusiasts, bringing together a friendly community of racers, fans, and industry professionals. We're all about creating a space where people can connect, share knowledge, and exchange parts and vehicles, with a focus on specific race cars, classes, series, and events. Our community includes all major purpose-built road racing classes, like the Sports Car Club of America (SCCA) and various pro series across North America and beyond. At ApexSpeed, we're passionate about amateur motorsports and are dedicated to helping our community have fun and grow while creating lasting memories on and off the track.
Social