(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

Jack Mansfield

3,256 posts

90 months

PH TEAM

Wednesday 18th January 2017
quotequote all
Hi,

Implementing HTTPS is still on the cards and a work in progress. Thank you for your patience.

Jack

randlemarcus

13,519 posts

231 months

Wednesday 18th January 2017
quotequote all
Jack Mansfield said:
Thank you for your patience.
Mine ran out. Which is why you'll be getting a memo from the Haymarket Global Data Protection Officer. Sorry.

All that jazz

7,632 posts

146 months

Wednesday 18th January 2017
quotequote all
Jack Mansfield said:
Hi,

Implementing HTTPS is still on the cards and a work in progress. Thank you for your patience.

Jack
It's been a "work in progress" for over 12 months. Can we have a date it will be implemented by please. ReacingPete promised it would be done by this month! Was that a lie then?

VEA

4,785 posts

201 months

Wednesday 18th January 2017
quotequote all
Jack Mansfield said:
on the cards
Sounds like it hasn't been decided at all.

Toss, utter toss.

Mattt

16,661 posts

218 months

Wednesday 18th January 2017
quotequote all
Haymarket should be ashamed of their performance with this issue.

MagicalTrevor

6,476 posts

229 months

Wednesday 18th January 2017
quotequote all
Mattt said:
Haymarket should be ashamed of their performance with this issue.
Just this one issue? wink

Vaud

50,446 posts

155 months

Wednesday 18th January 2017
quotequote all
MagicalTrevor said:
Mattt said:
Haymarket should be ashamed of their performance with this issue.
Just this one issue? wink
The "compliance" ones are important... https and phonesafe are easy fixes that no-one cares about, but they should as they could bite them very hard... it's not "can we have avatars". wink

dmsims

6,515 posts

267 months

Wednesday 18th January 2017
quotequote all
Vaud said:
The "compliance" ones are important... https and phonesafe are easy fixes that no-one cares about, but they should as they could bite them very hard... it's not "can we have avatars". wink
Yeah because Tarquin in marketing says it will have no effect on sales and whoever the latest white spectacled (no lenses), fixie bike manager is CBA

All that jazz

7,632 posts

146 months

Thursday 19th January 2017
quotequote all
anonymous said:
[redacted]
Clear cut to anyone with a basic understanding of English.

Dan_1981

17,387 posts

199 months

Thursday 19th January 2017
quotequote all
I still don't think Pete works here anymore.....

His posts don't have the PHStaff tag....

Vaud

50,446 posts

155 months

Thursday 19th January 2017
quotequote all
anonymous said:
[redacted]
Actually it's ambiguous, but I agree with your sentiment.

  • which is currently being resolved with a January deadline - could mean the "deadline" is in Jan, of the start of Jan, or the end of Jan
  • which is currently being resolved with a deadline of the start of of Jan - still ambiguous as "start" could mean around the 1st
  • which is currently being resolved with a deadline of Jan 31 5pm - clear cut
  • which is currently being resolved with a deadline of Jan 1 5pm - clear cut

But this is PH, we don't argue about semantics, do we? wink



All that jazz

7,632 posts

146 months

Thursday 19th January 2017
quotequote all
Regardless of the semantics, it needs to be in place within the next 12 days as per Pete's post. So let's make sure it happens Jack Mansfield (or whoever the chief cheese is here these days)?

All that jazz

7,632 posts

146 months

Thursday 19th January 2017
quotequote all
anonymous said:
[redacted]
Enough hair-splitting - find something better to do with your time - just get the damned https done already!

Mattt

16,661 posts

218 months

Thursday 19th January 2017
quotequote all
If the whole site HTTPS project is delayed, a company like Haymarket could sort the login form as a minimum within a day.

dmsims

6,515 posts

267 months

Thursday 19th January 2017
quotequote all
Mattt said:
If the whole site HTTPS project is delayed, a company like Haymarket could sort the login form as a minimum within an hour.
EFA

thebraketester

14,224 posts

138 months

Thursday 19th January 2017
quotequote all
Why doesnt someone breach the security flaw and send Haymarket some usernames and passwords? I would do If i could... but I dont know how.

GreigM

6,728 posts

249 months

Thursday 19th January 2017
quotequote all
dmsims said:
Mattt said:
If the whole site HTTPS project is delayed, a company like Haymarket could sort the login form as a minimum within an hour.
EFA
This is what I don't really understand - pretty much all we need is for the login to be https. The rest of the site (inc advertising ste) could be left as-is. JUST DON'T SEND THE PASSWORDS IN CLEAR TEXT!!!

So what if it isn't a permanent green padlock sign - I don't really care, so long as the password is encrypted.

And can we make the big assumption that the passwords are at least not kept unencrypted in the back end database?

Tonsko

6,299 posts

215 months

Thursday 19th January 2017
quotequote all
GreigM said:
And can we make the big assumption that the passwords are at least not kept unencrypted in the back end database?
MD5.

Run!

GreigM

6,728 posts

249 months

Thursday 19th January 2017
quotequote all
Tonsko said:
MD5.

Run!
Hey, I'd take it over cleartext. Most "hackers" have limited capability beyond running the scripts they download, would someone really put in the effort to extract and brute-force an MD5 hash....for PISTONHEADS logins?

That being said if it is MD5 the code structure is in place for the hashing process - so would be a 5 min job to upgrade to something with decent strength.

768

13,667 posts

96 months

Thursday 19th January 2017
quotequote all
MD5 is near enough pointless, it's not a barrier.

Some people will be using the same passwords elsewhere.