(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

glenrobbo

35,258 posts

150 months

Thursday 16th February 2017
quotequote all
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.

Tonsko

6,299 posts

215 months

Thursday 16th February 2017
quotequote all
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
Yeh I started a separate thread about that, seeking clarification, as it's far too woolly to offer a convincing defence if pulled in under the CMA.

Edited by Tonsko on Thursday 16th February 15:52

TheInternet

4,717 posts

163 months

Thursday 16th February 2017
quotequote all
0000 said:
update users set agreed_terms = false;
Yet no time for:

 update https set enabled = true; 

SystemParanoia

14,343 posts

198 months

Thursday 16th February 2017
quotequote all
TheInternet said:
0000 said:
update users set agreed_terms = false;
Yet no time for:

 update https set enabled = true; 
nono

HTTPS isnt a Database issue wink

TheInternet

4,717 posts

163 months

Thursday 16th February 2017
quotequote all
SystemParanoia said:
nono

HTTPS isnt a Database issue wink
Let's hope not.

dmsims

6,523 posts

267 months

Thursday 16th February 2017
quotequote all
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
And at the risk of amateur sleuthing myself - please change that to:

If you report we will completely ignore you - so don't bother

We have much more "important" things to work on e.g. messing up the home page

0000

13,812 posts

191 months

Thursday 16th February 2017
quotequote all
This really is taking unbelievably long. Surely the work experience kid could've managed the login page by now?

Retiring to my bunker.


SystemParanoia

14,343 posts

198 months

Thursday 16th February 2017
quotequote all
0000 said:
This really is taking unbelievably long. Surely the work experience kid could've managed the login page by now?

Retiring to my bunker.

I'd take a closer look if i were you yikes

ryanthescot

287 posts

154 months

Friday 17th February 2017
quotequote all
interesting that they have ignored the documentation for the STS they're using. they'd have to override the default setting to get identityserver to work over http which is clearly stated as being unacceptable for production environments -

"By default, IdentityServer requires all incoming connections to come over HTTPS. It is absolutely mandatory that communication with IdentityServer is done over secured transports only."

so i'm guessing your identity/access token can be intercepted and used for impersonation attacks.

Condi

17,195 posts

171 months

Sunday 19th February 2017
quotequote all
dmsims said:
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
And at the risk of amateur sleuthing myself - please change that to:

If you report we will completely ignore you - so don't bother

We have much more "important" things to work on e.g. messing up the home page
Must admit this did make me laugh the other day when I read the new T+C's.









rolleyes

crmcatee

5,694 posts

227 months

Monday 20th February 2017
quotequote all
Condi said:
Must admit this did make me laugh the other day when I read the new T+C's.



rolleyes
It was also in the old T&Cs which makes the time they're taking to resolve this even more comical.

PistonTechs

36 posts

154 months

PH Techies

PH TEAM

Wednesday 22nd February 2017
quotequote all
We have some further updates on the implementation of HTTPS on PistonHeads.

As mentioned in a previous update on 2 Feb, this work is being done in stages with the highest priority being the implementation of HTTPS on all pages that have personal data (i.e. login, registration, change password, email confirmation and account details). We have completed the latter work, but it has some critical dependencies that need to be worked out before we can release it. We are aiming to be able to provide timeframes on when this work will be released next week at which point we will provide another update.

Thanks - Laura on behalf of the Tech team

anonymous-user

54 months

Monday 27th February 2017
quotequote all
PistonTechs said:
We have some further updates on the implementation of HTTPS on PistonHeads.

As mentioned in a previous update on 2 Feb, this work is being done in stages with the highest priority being the implementation of HTTPS on all pages that have personal data (i.e. login, registration, change password, email confirmation and account details). We have completed the latter work, but it has some critical dependencies that need to be worked out before we can release it. We are aiming to be able to provide timeframes on when this work will be released next week at which point we will provide another update.

Thanks - Laura on behalf of the Tech team
In case you guys weren't aware

http://www.pistonheads.com/gassing/topic.asp?h=0&a...

If you need anymore resource I suggest you show your bosses this, as people now cannot access the site which I am sure will impact revenues

Vaud

50,503 posts

155 months

Monday 27th February 2017
quotequote all
But how big a use base is Chrome on iOS? I'd forgotten that it was even available and have a myriad of Apple devices wink

Are they any benefits over Safari given the undying render engine is the same?

pc.iow

1,879 posts

203 months

Monday 27th February 2017
quotequote all
anonymous said:
[redacted]
Does it affect the classifieds?
They'd care then.

anonymous-user

54 months

Monday 27th February 2017
quotequote all
pc.iow said:
Does it affect the classifieds?
They'd care then.
Agree and yes I would assume so

rscott

14,758 posts

191 months

Monday 27th February 2017
quotequote all
Seems odd that Chrome on iPad would start blocking all http sites yet it's not happening on any other device running Chrome?

rscott

14,758 posts

191 months

Monday 27th February 2017
quotequote all
anonymous said:
[redacted]
For one, I'd expect it to hit Android first.

Also a bit odd that there's no mention in the app store or anywhere I've found on the net that Chrome is blocking http..

threadlock

3,196 posts

254 months

Monday 27th February 2017
quotequote all
I think it's highly unlikely that Google would just *block* non-secure sites arbitrarily for all users. They haven't announced plans to do this (yet).

More likely is that a subset of users have non-secure sites blocked by their corporate policy or a setting they've made in Chrome on those devices.

Hardly reason for Haymarket to panic just yet.

Condi

17,195 posts

171 months

Thursday 2nd March 2017
quotequote all
  • logs in for the first time this week*
  • still unsecure, says Chrome*
  • looks in this thread for progress*
  • no progress*
rolleyes


Would Laura/Haymarket please tell us why this is taking so long to sort?