(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

All that jazz

7,632 posts

147 months

Tuesday 24th January 2017
quotequote all
You say that in jest Mr. Driver.... whistle

0000

13,812 posts

192 months

Tuesday 24th January 2017
quotequote all
Prizam said:
Sniffing packets in EC2 environments.

Here

Amazon Market even give you a one click launch for the instance. Sweet.

The downside... It will cost me $0.05 per our to harvest information. How many days will a quid get me ?
Not sure, they're a pain to calculate costs because they charge for things like traffic on top. But you won't be in the same network segment as the PH servers, you may as well try running wireshark locally for all the difference being on an EC2 host will make.

pincher

8,596 posts

218 months

Tuesday 24th January 2017
quotequote all
James - could you tell us if the developers are general HM devs or are they dedicated to PH?

Could you also give us some indication of their current project workload and deliverables i.e. The top 3 things that they are working on as a team as of today?

As you are obviously aware, this issue is a potential compromise to user security and the Phonesafe issue is bordering on illegal. Just how far up the HM chain have either of these gone, or are they both contained within the 'PH world' at the moment?

You can clearly see that users are getting more than a little fed up with critical problems being seemingly ignored for years at a time - the age old response of "if you don't like it, you know where the door is" simply doesn't wash with these - I get the feeling that there are several people that are very very close to reporting you to the regulatory authorities with regard to the Phonesafe debacle. And to be fair I wouldn't blame them in the slightest.

Both these items should have been prioritised right at the very top of the list a long long time ago and it is to the shame of Haymarket, let alone Pistonheads that the best (paraphrased) response you can give is 'Dunno mate'.

964Cup

1,448 posts

238 months

Wednesday 25th January 2017
quotequote all
Well, Google have announced that (over time) Chrome will be updated to mark all sites not defaulting to SSL as unsafe. So that may prompt some action...

https://threatpost.com/chrome-to-label-some-http-s...

dmsims

6,552 posts

268 months

Wednesday 25th January 2017
quotequote all
@thebraketester

Why are you surprised ? smile

thebraketester

14,261 posts

139 months

Wednesday 25th January 2017
quotequote all
dmsims said:
@thebraketester

Why are you surprised ? smile
I guess I am yes....

Does anyone have the wifi password for pistonheads HQ?? whistle

dmsims

6,552 posts

268 months

Wednesday 25th January 2017
quotequote all
thebraketester said:
Does anyone have the wifi password for pistonheads HQ?? whistle
That's not too hard ............

anyone got a large black van ?

All that jazz

7,632 posts

147 months

Wednesday 25th January 2017
quotequote all
@ braketester, you need to send that image to data.protection@haymarket.com and ask for an explanation. Is there a 'body' that oversees website security/privacy for this kind of thing in the event PH ignores you?

Prizam

2,346 posts

142 months

Wednesday 25th January 2017
quotequote all



Indeed, the costs are a bit complex to work out.

As for getting on the same network segment as Pistonheads... that bit is easy. The trick is the way AWS divides up instance traffic between tenancys.



Edited by Jack Mansfield on Wednesday 25th January 12:09

0000

13,812 posts

192 months

Wednesday 25th January 2017
quotequote all
Amazon said:
It is not possible for a virtual instance running in promiscuous mode to receive or “sniff” traffic that is intended for a different virtual instance. While customers can place their interfaces into promiscuous mode, the hypervisor will not deliver any traffic to them that is not addressed to them. Even two virtual instances that are owned by the same customer located on the same physical host cannot listen to each other’s traffic.
Link.

0000

13,812 posts

192 months

Wednesday 25th January 2017
quotequote all
PistonHeads said:
Your message has been deleted as it divulges information on how to obtain passwords. Sharing this information could land someone in a rather large spot of bother.
That's spectacularly naive, but not unexpected from a site using HTTP for password logins!

Have a word with yourselves!

thebraketester

14,261 posts

139 months

Wednesday 25th January 2017
quotequote all



Well... there is a very easy way to sort it out.... seriously you guys are a joke.

George111

6,930 posts

252 months

Wednesday 25th January 2017
quotequote all
thebraketester said:



Well... there is a very easy way to sort it out.... seriously you guys are a joke.
I was just thinking that it was getting a bit heated - James just works there like we work elsewhere, he probably doesn't set the budgets so it's a bit unfair to take anger out on him, then I see this and I think fu*k it, trying to sensor conversations is just daft and crazy and all the info is publicly available anyway, we all know where to go if you want to sniff traffic, it's not difficult.

I suspect financial problems with Haymarket are the cause - most publishers are suffering right now and I don't expect Haymarket to be any different.

dudleybloke

19,890 posts

187 months

Wednesday 25th January 2017
quotequote all
I know your IT bods say they are working on it but with not much happening and no timescale we have to think that someone is bulls#iting or more worrying, incompetent.

GreigM

6,732 posts

250 months

Wednesday 25th January 2017
quotequote all
0000 said:
That's spectacularly naive, but not unexpected from a site using HTTP for password logins!

Have a word with yourselves!
Yep, I got one as well. The irony being the post I had deleted specifically warned people not to do it on a public network.

A note for whoever did the deletion - what we were discussing is not illegal in any way so long as you are doing it on your own wifi (as my deleted post highlighted). This smacks of a cover up rather than deal with the issue being discussed.

Tonsko

6,299 posts

216 months

Wednesday 25th January 2017
quotequote all
Had the same email. smile

GreigM said:
Yep, I got one as well. The irony being the post I had deleted specifically warned people not to do it on a public network.

A note for whoever did the deletion - what we were discussing is not illegal in any way so long as you are doing it on your own wifi (as my deleted post highlighted). This smacks of a cover up rather than deal with the issue being discussed.
Indeed.

Edited by Tonsko on Wednesday 25th January 12:37

AndrewEH1

4,917 posts

154 months

Wednesday 25th January 2017
quotequote all
Who is going to be brave enough and post in the Lounge that this website isn't secure so everyone is aware of this issue?

Tonsko

6,299 posts

216 months

Wednesday 25th January 2017
quotequote all
Well, if you use the 'What's New' button, it will have been on the front page for a week or so anyway!

pincher

8,596 posts

218 months

Wednesday 25th January 2017
quotequote all
Where's James today? scratchchin

dudleybloke

19,890 posts

187 months

Wednesday 25th January 2017
quotequote all
Does Tarzan know about this problem?