(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

DS197

Original Poster:

992 posts

106 months

Tuesday 23rd February 2016
quotequote all
Funnily enough during my network security lab, we were learning about stealing cookies using wireshark and the website on the lab sheet was PistonHeads! This got me thinking as to why a relatively simple yet essential feature hasn't been implemented to date. Is it something that perhaps the IT team would deem useful as it certainly is in my eyes

DS197

Original Poster:

992 posts

106 months

Tuesday 23rd February 2016
quotequote all
anonymous said:
[redacted]
Totally agree with you. In fact I was able to retrieve the failed log in attempts of others in the lab and could clearly see the username and password they entered! If they're unwilling to do anything about it they should at least make users aware about the dangers.

Ollie_M

2,268 posts

106 months

Wednesday 24th February 2016
quotequote all
Thanks DS197: I'm not a techie but I'll make our Head of Development aware of your post and see what he says.

randlemarcus

13,518 posts

231 months

Wednesday 24th February 2016
quotequote all
Ollie_M said:
Thanks DS197: I'm not a techie but I'll make our Head of Development aware of your post and see what he says.
Last time I raised it, the response was that they were having issues with Firefox, so the rest of us could go unsecured. Nice.

RacingPete

8,871 posts

204 months

Wednesday 24th February 2016
quotequote all
We are currently, and have been, working on a project to move the whole site to HTTPS - so to answer the OPs question - Yes we are moving it, and it is important to us.

We have done most of the work, but the last part we are working on at the moment is the images in the classifieds that are a little more complicated due to the way it was initially designed back in 2011. So we hope to have this finished in April.

TankRizzo

7,259 posts

193 months

Wednesday 24th February 2016
quotequote all
I don't log into PH on public wifi anywhere for this reason. Crazy really.

thebraketester

14,221 posts

138 months

Wednesday 24th February 2016
quotequote all
Hey guys..... lets just hang out on the steps and chat face to face about cars until this is implemented...




Edited by thebraketester on Wednesday 24th February 19:37

George111

6,930 posts

251 months

Thursday 24th November 2016
quotequote all
No news ?

RacingPete

8,871 posts

204 months

Thursday 24th November 2016
quotequote all
It hit a bottle neck on ad serving which is currently being resolved with a January deadline.

Taita

7,602 posts

203 months

Thursday 24th November 2016
quotequote all
It's all fun and games until someone gets bored and is a bit naughty.....

There is truly no excuse.

Tankrizzo

7,259 posts

193 months

Thursday 24th November 2016
quotequote all
I do love the new centralised security system which forces logout every n days but sends everything over the wire in plain text.

Durzel

12,258 posts

168 months

Thursday 24th November 2016
quotequote all
One line in an Apache config file would seamlessly rewrite all HTTP requests to HTTPS. Zero programming changes required.

I guess this will get more attention from Haymarket early next year when Google start punishing sites for lack of SSL, ie when it impacts advertisers rather then users.

Alucidnation

16,810 posts

170 months

Thursday 24th November 2016
quotequote all
Good.

George111

6,930 posts

251 months

Sunday 27th November 2016
quotequote all
RacingPete said:
It hit a bottle neck on ad serving which is currently being resolved with a January deadline.
Thanks for the response, so done by the 1st Jan, so we can look forward to a little more security in the new year. That will be an improvement.


crmcatee

5,694 posts

227 months

Sunday 27th November 2016
quotequote all
They never said which January and judging by the length that it's taken them to implement some of the other features (most of which they still haven't), you'll be lucky if it's this decade.


DS197

Original Poster:

992 posts

106 months

Sunday 27th November 2016
quotequote all
crmcatee said:
They never said which January and judging by the length that it's taken them to implement some of the other features (most of which they still haven't), you'll be lucky if it's this decade.
Together with the picture above, the whole situation is summed up rather well rofl

hornetrider

63,161 posts

205 months

Wednesday 30th November 2016
quotequote all
I love these threads.

- User raises major problem

- PH response, oh yes, agree, we'll get it fixed asap

- Two years elapses

- Thread is bumped

- Rubbish excuse trotted out

- Rinse, repeat

George111

6,930 posts

251 months

Wednesday 30th November 2016
quotequote all
hornetrider said:
I love these threads.

- User raises major problem

- PH response, oh yes, agree, we'll get it fixed asap

- Two years elapses

- Thread is bumped

- Rubbish excuse trotted out

- Rinse, repeat
Well, I asked and they said January, so lets see what happens.

Funk

26,266 posts

209 months

Wednesday 30th November 2016
quotequote all
George111 said:
Well, I asked and they said January, so lets see what happens.
Place your bets....

Tankrizzo

7,259 posts

193 months

Wednesday 30th November 2016
quotequote all
Daft though really, the ads are all iframed in so I get that they have to have these HTTPS first before the main site else they'll hit the insecure content warning (iframes, yuk!)

But surely any ad company worth its salt can serve both secure and insecure channels? As a test, I just took 5 of the ads from the main site and requested the same ad under HTTPS specifically - each ad is served absolutely fine.

Surely this is trivial to switch over if you're using a centralised ad system? Then you just change IIS or your load balancer to use a HTTPS cert and force all bookmarked insecure requests to bounce to HTTPS, job done.