Loading. Please Wait... 
 |
 |
 |
HTTPS and URL changes |
|
Aug 12 2017, 16:25
|
Rooping
Lurker
Group: Recruits
Posts: 8
Joined: 25-October 12

|
Was wondering where the old pages went
|
|
|
Aug 29 2017, 18:19
|
Looov3
Lurker
Group: Lurkers
Posts: 1
Joined: 29-August 17

|
Bad HTTPS, forum uses resources from non-safe websites
|
|
|
Aug 30 2017, 10:40
|
Tenboro

|
QUOTE(Looov3 @ Aug 29 2017, 18:19)  Bad HTTPS, forum uses resources from non-safe websites
The forum does not, but user posts may. The alternative is banning external images, which did not seem like a reasonable tradeoff.
|
|
|
Sep 4 2017, 11:04
|
Rationality
Group: Gold Star Club
Posts: 379
Joined: 29-December 15

|
QUOTE(Tenboro @ Aug 30 2017, 11:40)  The forum does not, but user posts may. The alternative is banning external images, which did not seem like a reasonable tradeoff.
Imgur supports https, perhaps run a script to convert all http links to imgur on the forum to https? Especially the user signatures, for example page 9 of this topic shows mixed content warnings because of 3 user signatures linking to http imgur, and a broken link to imageshack.
|
|
|
Sep 4 2017, 17:11
|
DoctorDove
Group: Members
Posts: 121
Joined: 28-November 13

|
Is that even a proper security issue?
|
|
|
Sep 4 2017, 21:28
|
blue penguin
Group: Gold Star Club
Posts: 10,046
Joined: 24-March 12

|
QUOTE(DoctorDove @ Sep 4 2017, 16:11)  Is that even a proper security issue? Not really. Mixed content warning on images does not hit any viable backdoors/bugs. The forums do not support SVG for example. For SVG see this: [ security.stackexchange.com] https://security.stackexchange.com/question...-img-src-xss-do . The only thing is that a Referer: header is leaked out of the HTTPS. But, unless you are using DNSSEC (which is still in development), your ISP already has that info. Also, all modern browsers refuse to send a Referer: header to HTTPS on an HTTP connection, so it is a moot point.
|
|
|
|
 |
|
Sep 6 2017, 01:19
|
Anonnnnnn
Newcomer
  Group: Members
Posts: 94
Joined: 21-April 14

|
QUOTE(Rationality @ Sep 4 2017, 14:04)  Imgur supports https, perhaps run a script to convert all http links to imgur on the forum to https? Especially the user signatures, for example page 9 of this topic shows mixed content warnings because of 3 user signatures linking to http imgur, and a broken link to imageshack.
You better solve this via browser extension (HTTPS Everywhere, Smart HTTPS, custom rules in Redirector) than ask every site's admin to convert imgur and other external links to https.
|
|
|
|
 |
|
Sep 6 2017, 16:01
|
hzqr
Group: Gold Star Club
Posts: 4,672
Joined: 13-May 09

|
If you're using Chrome/ium or one of its derivatives, you can navigate to chrome://net-internals/#hsts (can't link to it, the invisible broads won't let me) and manually add imgur and its subdomains (imgur.com, i.imgur.com, etc.) to the browser's HSTS list (which should force HTTP requests on said domains to be converted to HTTPS) The browser may still raise a mixed-content warning in the console, but the requests should be delivered via HTTPS
|
|
|
Sep 19 2017, 20:40
|
Rationality
Group: Gold Star Club
Posts: 379
Joined: 29-December 15

|
|
|
|
Dec 13 2017, 17:38
|
mewsf
Group: Gold Star Club
Posts: 564
Joined: 24-June 14

|
Letsencrypt is going to issue wildcard certificates...Maybe this is useful for h@h network, am I too obsessed with that green lock?
|
|
|
Dec 13 2017, 17:55
|
Maximum_Joe
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11

|
QUOTE(mewsf @ Dec 13 2017, 10:38)  Letsencrypt is going to issue wildcard certificates...Maybe this is useful for h@h network
It isn't, at least not to anywhere near the same extent as the regular servers.
|
|
|
Dec 18 2017, 05:29
|
@43883
Group: Gold Star Club
Posts: 31,481
Joined: 6-March 08

|
From the wiki (didn't write this so blame whoever did if it's wrong): QUOTE Is H@H traffic encrypted? No. If people are worried about H@H stuff, might want to not get a client at all. Once you get one, it'll stay even if it dies.
|
|
|
Jan 31 2018, 14:06
|
Cepesch
Lurker
Group: Recruits
Posts: 8
Joined: 22-July 12

|
Sorry for stupid question
But what happened with galleries in g.e-hentai.org? All of them redirected to e. or just be deleted?
Coz i cannot find some of doji and think than they was only at g.e-
|
|
|
Jan 31 2018, 15:17
|
Maximum_Joe
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11

|
Nothing is exclusive to any subdomain.
|
|
|
Feb 3 2018, 12:27
|
Cepesch
Lurker
Group: Recruits
Posts: 8
Joined: 22-July 12

|
Really? But i see many times this answer:
"This gallery has been removed or is unavailable.
You will be redirected to the front page momentarily."
When exist g.e and e. hentai it was mean that these gallery located only at g.e. But right now, if there is no exclusive, where this gallery removed? In what place???
|
|
|
Feb 13 2018, 17:42
|
0pera
Lurker
Group: Lurkers
Posts: 1
Joined: 4-September 15

|
(IMG:[ invalid] style_emoticons/default/sad.gif) don't know whether someone mentioned this before, when i view any image of any gallery, the browser got a 307 redirect code to use https connection but the server cannot provide https connection to it. as a result, all the images failed to load. tried to copy the image link(without using ssl) and open it in a new tab, the image can be loaded.
|
|
|
|
 |
|
Feb 13 2018, 19:43
|
Tenboro

|
QUOTE(0pera @ Feb 13 2018, 16:42)  (IMG:[ invalid] style_emoticons/default/sad.gif) don't know whether someone mentioned this before, when i view any image of any gallery, the browser got a 307 redirect code to use https connection but the server cannot provide https connection to it. as a result, all the images failed to load. tried to copy the image link(without using ssl) and open it in a new tab, the image can be loaded. Galleries will never use a 307 Temporary Redirect. Disable all your extensions and/or use a different browser.
|
|
|
Feb 23 2018, 15:05
|
katashi_sadamu
Lurker
Group: Lurkers
Posts: 2
Joined: 27-July 14

|
This is probably an issue with Firefox Nightly where it will forcefully upgrade HTTP passive mixed content to HTTPS and doesn't fallback if it fails. Change security.mixed_content.upgrade_display_content to false in about:config meanwhile.
|
|
|
Feb 24 2018, 01:09
|
thrade
Lurker
Group: Lurkers
Posts: 1
Joined: 12-May 13

|
QUOTE(katashi_sadamu @ Feb 23 2018, 14:05)  Change security.mixed_content.upgrade_display_content to false in about:config meanwhile.
I can confirm the problem and your fix. Since this happened to me after a regular Firefox nightly update I expect many more reports soon... This post has been edited by thrade: Feb 24 2018, 01:10
|
|
|
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:
|
 |
 |
 |
|
|
|