Welcome Guest ( Log In | Register )

14 Pages V « < 11 12 13 14 >  
Closed TopicStart new topic
> HTTPS and URL changes

 
post Aug 12 2017, 16:25
Post #241
Rooping



Lurker
Group: Recruits
Posts: 8
Joined: 25-October 12


Was wondering where the old pages went
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Aug 29 2017, 18:19
Post #242
Looov3



Lurker
Group: Lurkers
Posts: 1
Joined: 29-August 17


Bad HTTPS, forum uses resources from non-safe websites
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Aug 30 2017, 10:40
Post #243
Tenboro

Admin




QUOTE(Looov3 @ Aug 29 2017, 18:19) *

Bad HTTPS, forum uses resources from non-safe websites


The forum does not, but user posts may. The alternative is banning external images, which did not seem like a reasonable tradeoff.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Sep 4 2017, 11:04
Post #244
Rationality



Casual Poster
****
Group: Gold Star Club
Posts: 379
Joined: 29-December 15
Level 467 (Godslayer)


QUOTE(Tenboro @ Aug 30 2017, 11:40) *

The forum does not, but user posts may. The alternative is banning external images, which did not seem like a reasonable tradeoff.

Imgur supports https, perhaps run a script to convert all http links to imgur on the forum to https? Especially the user signatures, for example page 9 of this topic shows mixed content warnings because of 3 user signatures linking to http imgur, and a broken link to imageshack.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Sep 4 2017, 17:11
Post #245
DoctorDove



Casual Poster
***
Group: Members
Posts: 121
Joined: 28-November 13
Level 141 (Ascended)


Is that even a proper security issue?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Sep 4 2017, 21:28
Post #246
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Gold Star Club
Posts: 10,046
Joined: 24-March 12
Level 500 (Godslayer)


QUOTE(DoctorDove @ Sep 4 2017, 16:11) *
Is that even a proper security issue?
Not really. Mixed content warning on images does not hit any viable backdoors/bugs. The forums do not support SVG for example.

For SVG see this: [security.stackexchange.com] https://security.stackexchange.com/question...-img-src-xss-do .

The only thing is that a Referer: header is leaked out of the HTTPS. But, unless you are using DNSSEC (which is still in development), your ISP already has that info. Also, all modern browsers refuse to send a Referer: header to HTTPS on an HTTP connection, so it is a moot point.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Sep 6 2017, 01:19
Post #247
Anonnnnnn



Newcomer
**
Group: Members
Posts: 94
Joined: 21-April 14
Level 360 (Dovahkiin)


QUOTE(Rationality @ Sep 4 2017, 14:04) *
Imgur supports https, perhaps run a script to convert all http links to imgur on the forum to https? Especially the user signatures, for example page 9 of this topic shows mixed content warnings because of 3 user signatures linking to http imgur, and a broken link to imageshack.

You better solve this via browser extension (HTTPS Everywhere, Smart HTTPS, custom rules in Redirector) than ask every site's admin to convert imgur and other external links to https.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Sep 6 2017, 16:01
Post #248
hzqr



Savagely Still
********
Group: Gold Star Club
Posts: 4,672
Joined: 13-May 09
Level 462 (Dovahkiin)


If you're using Chrome/ium or one of its derivatives, you can navigate to chrome://net-internals/#hsts (can't link to it, the invisible broads won't let me) and manually add imgur and its subdomains (imgur.com, i.imgur.com, etc.) to the browser's HSTS list (which should force HTTP requests on said domains to be converted to HTTPS)
The browser may still raise a mixed-content warning in the console, but the requests should be delivered via HTTPS
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Sep 19 2017, 20:40
Post #249
Rationality



Casual Poster
****
Group: Gold Star Club
Posts: 379
Joined: 29-December 15
Level 467 (Godslayer)


[blog.imgur.com] Imgur defaults to https now
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Dec 13 2017, 17:38
Post #250
mewsf



Regular Poster
*****
Group: Gold Star Club
Posts: 564
Joined: 24-June 14
Level 500 (Ponyslayer)


Letsencrypt is going to issue wildcard certificates...Maybe this is useful for h@h network, am I too obsessed with that green lock?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Dec 13 2017, 17:55
Post #251
Maximum_Joe



Legendary Poster
***********
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11
Level 500 (Dovahkiin)


QUOTE(mewsf @ Dec 13 2017, 10:38) *

Letsencrypt is going to issue wildcard certificates...Maybe this is useful for h@h network

It isn't, at least not to anywhere near the same extent as the regular servers.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Dec 18 2017, 05:29
Post #252
@43883




************
Group: Gold Star Club
Posts: 31,481
Joined: 6-March 08
Level 500 (Newbie)


From the wiki (didn't write this so blame whoever did if it's wrong):
QUOTE
Is H@H traffic encrypted?
No.
If people are worried about H@H stuff, might want to not get a client at all. Once you get one, it'll stay even if it dies.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Dec 28 2017, 03:31
Post #253
mixpearl



Newcomer
*
Group: Catgirl Camarilla
Posts: 20
Joined: 16-May 13
Level 289 (Godslayer)


Really great update. Thanks a lot! (IMG:[invalid] style_emoticons/default/biggrin.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Jan 31 2018, 14:06
Post #254
Cepesch



Lurker
Group: Recruits
Posts: 8
Joined: 22-July 12
Level 56 (Expert)


Sorry for stupid question

But what happened with galleries in g.e-hentai.org? All of them redirected to e. or just be deleted?

Coz i cannot find some of doji and think than they was only at g.e-
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Jan 31 2018, 15:17
Post #255
Maximum_Joe



Legendary Poster
***********
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11
Level 500 (Dovahkiin)


Nothing is exclusive to any subdomain.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 3 2018, 12:27
Post #256
Cepesch



Lurker
Group: Recruits
Posts: 8
Joined: 22-July 12
Level 56 (Expert)


Really? But i see many times this answer:

"This gallery has been removed or is unavailable.

You will be redirected to the front page momentarily."

When exist g.e and e. hentai it was mean that these gallery located only at g.e. But right now, if there is no exclusive, where this gallery removed?
In what place???
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 13 2018, 17:42
Post #257
0pera



Lurker
Group: Lurkers
Posts: 1
Joined: 4-September 15
Level 125 (Ascended)


(IMG:[invalid] style_emoticons/default/sad.gif) don't know whether someone mentioned this before, when i view any image of any gallery, the browser got a 307 redirect code to use https connection but the server cannot provide https connection to it. as a result, all the images failed to load.
tried to copy the image link(without using ssl) and open it in a new tab, the image can be loaded.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 13 2018, 19:43
Post #258
Tenboro

Admin




QUOTE(0pera @ Feb 13 2018, 16:42) *

(IMG:[invalid] style_emoticons/default/sad.gif) don't know whether someone mentioned this before, when i view any image of any gallery, the browser got a 307 redirect code to use https connection but the server cannot provide https connection to it. as a result, all the images failed to load.
tried to copy the image link(without using ssl) and open it in a new tab, the image can be loaded.


Galleries will never use a 307 Temporary Redirect. Disable all your extensions and/or use a different browser.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Feb 23 2018, 15:05
Post #259
katashi_sadamu



Lurker
Group: Lurkers
Posts: 2
Joined: 27-July 14


This is probably an issue with Firefox Nightly where it will forcefully upgrade HTTP passive mixed content to HTTPS and doesn't fallback if it fails.
Change security.mixed_content.upgrade_display_content to false in about:config meanwhile.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 24 2018, 01:09
Post #260
thrade



Lurker
Group: Lurkers
Posts: 1
Joined: 12-May 13
Level 12 (Novice)


QUOTE(katashi_sadamu @ Feb 23 2018, 14:05) *

Change security.mixed_content.upgrade_display_content to false in about:config meanwhile.

I can confirm the problem and your fix. Since this happened to me after a regular Firefox nightly update I expect many more reports soon...

This post has been edited by thrade: Feb 24 2018, 01:10
User is offlineProfile CardPM
Go to the top of the page
+Quote Post


14 Pages V « < 11 12 13 14 >
Closed TopicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 


Lo-Fi Version Time is now: 12th March 2025 - 20:15