(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

glenrobbo

35,299 posts

151 months

Thursday 16th February 2017
quotequote all
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.

Tonsko

6,299 posts

216 months

Thursday 16th February 2017
quotequote all
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
Yeh I started a separate thread about that, seeking clarification, as it's far too woolly to offer a convincing defence if pulled in under the CMA.

Edited by Tonsko on Thursday 16th February 15:52

TheInternet

4,724 posts

164 months

Thursday 16th February 2017
quotequote all
0000 said:
update users set agreed_terms = false;
Yet no time for:

 update https set enabled = true; 

SystemParanoia

14,343 posts

199 months

Thursday 16th February 2017
quotequote all
TheInternet said:
0000 said:
update users set agreed_terms = false;
Yet no time for:

 update https set enabled = true; 
nono

HTTPS isnt a Database issue wink

TheInternet

4,724 posts

164 months

Thursday 16th February 2017
quotequote all
SystemParanoia said:
nono

HTTPS isnt a Database issue wink
Let's hope not.

dmsims

6,541 posts

268 months

Thursday 16th February 2017
quotequote all
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
And at the risk of amateur sleuthing myself - please change that to:

If you report we will completely ignore you - so don't bother

We have much more "important" things to work on e.g. messing up the home page

0000

13,812 posts

192 months

Thursday 16th February 2017
quotequote all
This really is taking unbelievably long. Surely the work experience kid could've managed the login page by now?

Retiring to my bunker.


SystemParanoia

14,343 posts

199 months

Thursday 16th February 2017
quotequote all
0000 said:
This really is taking unbelievably long. Surely the work experience kid could've managed the login page by now?

Retiring to my bunker.

I'd take a closer look if i were you yikes

ryanthescot

287 posts

155 months

Friday 17th February 2017
quotequote all
interesting that they have ignored the documentation for the STS they're using. they'd have to override the default setting to get identityserver to work over http which is clearly stated as being unacceptable for production environments -

"By default, IdentityServer requires all incoming connections to come over HTTPS. It is absolutely mandatory that communication with IdentityServer is done over secured transports only."

so i'm guessing your identity/access token can be intercepted and used for impersonation attacks.

Condi

17,259 posts

172 months

Sunday 19th February 2017
quotequote all
dmsims said:
glenrobbo said:
On topic, may I draw everyone's everyone's attention to the New Rules of Posting No.23? :
23.PistonHeads and Haymarket Media Group Limited are committed to the privacy, safety and security of all our users and customers. If you discover any potential security vulnerability, please report it to us through info@pistonheads.com or data.protection@haymarket.com and we will investigate it and respond to you as soon as possible. To help us to research and resolve any potential vulnerabilities as quickly as possible, please include full details of any issue when submitting your report. Publicly disclosing any potential vulnerability could put the wider community at risk, therefore we encourage you not to disclose any potential issues until they have been addressed and a resolution has been confirmed by us.

Just sayin'.
And at the risk of amateur sleuthing myself - please change that to:

If you report we will completely ignore you - so don't bother

We have much more "important" things to work on e.g. messing up the home page
Must admit this did make me laugh the other day when I read the new T+C's.









rolleyes

crmcatee

5,697 posts

228 months

Monday 20th February 2017
quotequote all
Condi said:
Must admit this did make me laugh the other day when I read the new T+C's.



rolleyes
It was also in the old T&Cs which makes the time they're taking to resolve this even more comical.

PistonTechs

36 posts

155 months

PH Techies

PH TEAM

Wednesday 22nd February 2017
quotequote all
We have some further updates on the implementation of HTTPS on PistonHeads.

As mentioned in a previous update on 2 Feb, this work is being done in stages with the highest priority being the implementation of HTTPS on all pages that have personal data (i.e. login, registration, change password, email confirmation and account details). We have completed the latter work, but it has some critical dependencies that need to be worked out before we can release it. We are aiming to be able to provide timeframes on when this work will be released next week at which point we will provide another update.

Thanks - Laura on behalf of the Tech team

anonymous-user

55 months

Monday 27th February 2017
quotequote all
PistonTechs said:
We have some further updates on the implementation of HTTPS on PistonHeads.

As mentioned in a previous update on 2 Feb, this work is being done in stages with the highest priority being the implementation of HTTPS on all pages that have personal data (i.e. login, registration, change password, email confirmation and account details). We have completed the latter work, but it has some critical dependencies that need to be worked out before we can release it. We are aiming to be able to provide timeframes on when this work will be released next week at which point we will provide another update.

Thanks - Laura on behalf of the Tech team
In case you guys weren't aware

http://www.pistonheads.com/gassing/topic.asp?h=0&a...

If you need anymore resource I suggest you show your bosses this, as people now cannot access the site which I am sure will impact revenues

Vaud

50,625 posts

156 months

Monday 27th February 2017
quotequote all
But how big a use base is Chrome on iOS? I'd forgotten that it was even available and have a myriad of Apple devices wink

Are they any benefits over Safari given the undying render engine is the same?

pc.iow

1,879 posts

204 months

Monday 27th February 2017
quotequote all
anonymous said:
[redacted]
Does it affect the classifieds?
They'd care then.

anonymous-user

55 months

Monday 27th February 2017
quotequote all
pc.iow said:
Does it affect the classifieds?
They'd care then.
Agree and yes I would assume so

rscott

14,774 posts

192 months

Monday 27th February 2017
quotequote all
Seems odd that Chrome on iPad would start blocking all http sites yet it's not happening on any other device running Chrome?

rscott

14,774 posts

192 months

Monday 27th February 2017
quotequote all
anonymous said:
[redacted]
For one, I'd expect it to hit Android first.

Also a bit odd that there's no mention in the app store or anywhere I've found on the net that Chrome is blocking http..

threadlock

3,196 posts

255 months

Monday 27th February 2017
quotequote all
I think it's highly unlikely that Google would just *block* non-secure sites arbitrarily for all users. They haven't announced plans to do this (yet).

More likely is that a subset of users have non-secure sites blocked by their corporate policy or a setting they've made in Chrome on those devices.

Hardly reason for Haymarket to panic just yet.

Condi

17,259 posts

172 months

Thursday 2nd March 2017
quotequote all
  • logs in for the first time this week*
  • still unsecure, says Chrome*
  • looks in this thread for progress*
  • no progress*
rolleyes


Would Laura/Haymarket please tell us why this is taking so long to sort?