LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback
User Name
Password
LQ Suggestions & Feedback Do you have a suggestion for this site or an idea that will make the site better? This forum is for you.
PLEASE READ THIS FORUM - Information and status updates will also be posted here.

Notices


Closed Thread
  Search this Thread
Old 06-23-2017, 05:13 PM   #1
NdFeB
LQ Newbie
 
Registered: Jun 2017
Posts: 7

Rep: Reputation: Disabled
No HTTPS as default protocol?


Hello LQ staff!

I realized that www.linuxquestions.org was not configured to impose HTTPS. Why? I am using a firefox plugin "https everywhere", so thanks to EFF, my credentials are protected (well not from you, but at least from malicious listeners). But what about other people?

Living in 2017, and most basic processors embedding basic encryption instructions, why don't you setup HTTPS as default protocol? Or even better, why don't you simply forbid plain HTTP? Nobody would lag because of this.

I see your certificate is signed by GeoTrust, so why don't you use it?

(By the way, it expires in 2 months)

Regards.
 
Old 06-23-2017, 05:47 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,317
Blog Entries: 28

Rep: Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140
You might find this thread interesting: https://www.linuxquestions.org/quest...ps-4175605642/

In a recent similar thread which I regret that I cannot find right now, Jeremy pointed out that login, contribution, and other information that should be confidential is encrypted.

My personal opinion is that encrypting stuff that doesn't need to be encrypted, such as the boating photos on my boating website, is not security; it's security theatre.
 
1 members found this post helpful.
Old 06-23-2017, 08:06 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,978

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
It would be simple for jeremy to set linuxquestions as a https only site.

Ask him would be the reply.


My take on it that all sites should be https but I know that it isn't fool proof.
 
Old 06-24-2017, 05:00 AM   #4
NdFeB
LQ Newbie
 
Registered: Jun 2017
Posts: 7

Original Poster
Rep: Reputation: Disabled
Thanks for the link. I join the "all link as https by default" team. However, to bypass some old protocol conflict (as stated in the thread), letting some pages be accessible in plain http (mainly for downloads) could be a good thing, and it changes my mind about "required https everywhere".

In general, anyone would want to be sure that they are talking to the person they are actually trying to contact, and not anyone else. A plain http download is pretty dangerous as if you don't check the file's fingerprint sum, you could potentially download any sh*t instead of your legit file. So, for this purpose (download over http), I still think it should be hosted on a separate site, to avoid fake DNS attack and malicious redirections. The separate site should have an enormous banner with written "AT YOUR OWN RISK". However, this is really not mandatory as you can download whatever you want from an other host supporting https and transfer it your own way to an old non-compatible toaster.

So, in my opinion, any internet page showing a logon formular should never be plain http anymore, not in 2017, and as much as possible, all websites should redirect http requests to https. While some websites are fighting against xss and cookie stealing (and https does not protect against that), some others let logon pages in plain text. I feel like this is disrespectful to the internet .
 
Old 06-25-2017, 09:50 AM   #5
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
Thanks for the feedback. As I've noted a couple times, https is fully supported at LQ (and has been for a very long time), the login page is https-only, and the site will be moving to https by default after the pending code update.

--jeremy
 
Old 06-25-2017, 11:34 AM   #6
NdFeB
LQ Newbie
 
Registered: Jun 2017
Posts: 7

Original Poster
Rep: Reputation: Disabled
Hello jeremy. I checked by myself and indeed, the logon form is sent over TLS. But an http prefix always leads to confusion. Thanks to you for the feedback !

Last edited by NdFeB; 06-25-2017 at 11:46 AM.
 
Old 07-25-2017, 12:36 PM   #7
elcore
Senior Member
 
Registered: Sep 2014
Distribution: Slackware
Posts: 1,753

Rep: Reputation: Disabled
Using a login link on the right, when it redirects automatically it redirects to http page not https.
Could be a bug, or intended. Not sure. The http page gets filtered by proxy, and then I need to add "s" and refresh the page every time.
 
Old 07-25-2017, 12:44 PM   #8
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
Not sure which link you are referring to, but the one in the main nav is https and the login page itself will reload as https if loaded as http.

--jeremy
 
Old 07-25-2017, 01:01 PM   #9
elcore
Senior Member
 
Registered: Sep 2014
Distribution: Slackware
Posts: 1,753

Rep: Reputation: Disabled
I'll try my best to explain.

The link on the screenshot, on the right side menu, it leads to:

https://www.linuxquestions.org/questions/lqlogin.php

Then I enter the info and when I hit login button it automatically redirects to:

http://www.linuxquestions.org/questions/index.php

Which just shows ERR_ACCESS_DENIED because the proxy blocks it.

Then I need to add https in front and refresh the page.
Attached Thumbnails
Click image for larger version

Name:	login.png
Views:	16
Size:	4.4 KB
ID:	25568  
 
Old 07-25-2017, 03:12 PM   #10
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
We'll be moving the entire site to https-only in the future. In there interim there are a couple browser addons to accomplish this.

--jeremy
 
1 members found this post helpful.
Old 07-26-2017, 01:59 AM   #11
elcore
Senior Member
 
Registered: Sep 2014
Distribution: Slackware
Posts: 1,753

Rep: Reputation: Disabled
Thank you for reply, it seems to work fine with noscript.httpsForced

Code:
user_pref("noscript.httpsForced", "www.linuxquestions.org");
user_pref("noscript.secureCookiesForced", "www.linuxquestions.org");
 
1 members found this post helpful.
Old 08-23-2017, 12:43 PM   #12
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
As an update: https://www.linuxquestions.org/quest...te-4175612452/

--jeremy
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Perl LWP::Protocol::https install failed via cpanm dhrumantgoradia Linux - Software 3 04-03-2013 11:04 PM
curl: (1) Protocol https not supported or disabled in libcurl guest Linux - Software 1 05-01-2009 03:40 AM
KDE 3.2: Protocol https not supported qwijibow Linux - Software 1 07-17-2004 09:38 PM
HTTPS protocol only, anyway around it? esears Linux - Networking 1 03-31-2004 01:20 PM
What is https protocol? ICO Programming 5 03-02-2004 08:34 AM

LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback

All times are GMT -5. The time now is 04:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration