Welcome Guest ( Log In | Register )

14 Pages V « < 12 13 14  
Closed TopicStart new topic
> HTTPS and URL changes

 
post Feb 24 2018, 02:56
Post #261
Tenboro

Admin




QUOTE(thrade @ Feb 24 2018, 00:09) *

Since this happened to me after a regular Firefox nightly update I expect many more reports soon...


Report it to Mozilla if anywhere.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 04:02
Post #262
katashi_sadamu



Lurker
Group: Lurkers
Posts: 2
Joined: 27-July 14


Chrome might get the same experiment, if Mozilla's "succeeds", though. Might want to plan ahead on how to make H@H work with HTTPS.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 13:04
Post #263
Tenboro

Admin




QUOTE(katashi_sadamu @ Feb 26 2018, 03:02) *

Might want to plan ahead on how to make H@H work with HTTPS.


I have a plan, but a) it's pointless security theater, b) it's busywork I'd rather spend on something worth-while, c) it will require additional (and more fragile) DNS infrastructure, and d) it will add significant additional delay for downloading every single image, both for the DNS lookup and TLS handshake.

If Firefox does push something like this by themselves, all Firefox users will get a nice fat "Firefox is not supported, get a non-retarded browser" message, but obviously, if Chrome does it as well, we will have to. And it will suck. Which is why you should tell Mozilla to cut it the fuck out.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 14:02
Post #264
mundomuñeca



Lo Scimmiotto
********
Group: Members
Posts: 4,198
Joined: 14-July 17
Level 467 (Dovahkiin)


QUOTE(Tenboro @ Feb 26 2018, 14:04) *

I have a plan, but a) it's pointless security theater, (IMG:[invalid] style_emoticons/default/cool.gif) it's pointless busywork, c) it will require additional (and more fragile) DNS infrastructure, and d) it will add significant additional delay for downloading every single image, both for the DNS lookup and TLS handshake.

If Firefox does push something like this by themselves, all Firefox users will get a nice fat "Firefox is not supported, get a non-retarded browser" message, but obviously, if Chrome does it as well, we will have to. And it will suck. Which is why you should tell Mozilla to cut it the fuck out.


And if Firefox users just stop upgrading their browers to every last releashit ?

I have FF three years old now, and I'm still happy with it (don't run H@H thou', bandwidth on mobile is pretty shitty here).

And what about Opera users ? (I have & use it too, thou' FF is still my favorite).
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 14:14
Post #265
Tenboro

Admin




QUOTE(mundomuñeca @ Feb 26 2018, 13:02) *

And if Firefox users just stop upgrading their browers to every last releashit ?


It's generally not recommended, as most releases include a fix for some sort of severe security vulnerability, but technically-minded users would be able to turn off this "feature", and you would be able to use the ESR (extended support release) for a year or two as well.

QUOTE(mundomuñeca @ Feb 26 2018, 13:02) *

And what about Opera users ? (I have & use it too, thou' FF is still my favorite).


Recent versions of Opera is basically an UI on top of Blink (the Chrome rendering engine), so presumably they will do whatever Chrome ends up doing.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 14:24
Post #266
lessfull



Casual Poster
***
Group: Members
Posts: 174
Joined: 9-May 14
Level 367 (Godslayer)


Asking for countries with strict laws:
Is there a way to make hentaiverse-game as subdomain for e-hentai with https? If I know correct, https makes it so only first level domain is visible for providers, but no other. So if country try to say "you visited e-hentai" as a prove, you can say "I just played a game"? (IMG:[invalid] style_emoticons/default/smile.gif)
p.s I didn't know where to ask it. Thread seems eligible for this.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 15:28
Post #267
Tenboro

Admin




QUOTE(lessfull @ Feb 26 2018, 13:24) *

Is there a way to make hentaiverse-game as subdomain for e-hentai with https? If I know correct, https makes it so only first level domain is visible for providers, but no other. So if country try to say "you visited e-hentai" as a prove, you can say "I just played a game"? (IMG:[invalid] style_emoticons/default/smile.gif)


No part of the hostname is revealed in plaintext when using HTTPS, but the DNS lookup would be unless you do some trickery on your end. So this would not actually do what you think it does.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Feb 26 2018, 15:40
Post #268
lessfull



Casual Poster
***
Group: Members
Posts: 174
Joined: 9-May 14
Level 367 (Godslayer)


QUOTE(Tenboro @ Feb 26 2018, 15:28) *

No part of the hostname is revealed in plaintext when using HTTPS, but the DNS lookup would be unless you do some trickery on your end. So this would not actually do what you think it does.

Forgot about that (IMG:[invalid] style_emoticons/default/sad.gif) So there is no way make it looks like requests goes to ip of e-hentai, while actually goes to hentaiverse if looking on it from internet provider side? Feels like simple redirecting on server side will be the same as host both sides on one agent which is nah.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Mar 3 2018, 00:07
Post #269
Ver Greeneyes



Lurker
Group: Recruits
Posts: 9
Joined: 29-October 10
Level 113 (Lord)


QUOTE(katashi_sadamu @ Feb 23 2018, 14:05) *

This is probably an issue with Firefox Nightly where it will forcefully upgrade HTTP passive mixed content to HTTPS and doesn't fallback if it fails.
Change security.mixed_content.upgrade_display_content to false in about:config meanwhile.

Probably worth noting that this pref was turned off again in [bugzilla.mozilla.org] bug 1435733, and was Nightly-only before that. So right now this is just something they're experimenting with, and it looks like it broke a lot of other stuff too.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Mar 13 2018, 21:03
Post #270
Anonnnnnn



Newcomer
*
Group: Members
Posts: 37
Joined: 21-April 14
Level 343 (Dovahkiin)


QUOTE(Tenboro @ Feb 26 2018, 18:28) *

No part of the hostname is revealed in plaintext when using HTTPS, but the DNS lookup would be unless you do some trickery on your end. So this would not actually do what you think it does.

Though modern browsers support SNI and always send it in ClientHello unencrypted, for everyone who bother to look, even in TLS 1.3 drafts.

QUOTE(lessfull @ Feb 26 2018, 17:24) *

If I know correct, https makes it so only first level domain is visible for providers, but no other. So if country try to say "you visited e-hentai" as a prove, you can say "I just played a game"? (IMG:[invalid] style_emoticons/default/smile.gif)

No, any-level domain is visible. What is not visible in HTTPS is a path&arguments after domain (i.e. index.php?showtopic=201800&st=260 in this page) and transmissed data. Your provider can tell that you opened forums.e-hentai.org, and same would be with hentaiverse.e-hentai.org.
The thing that you want is having hentaiverse under e-hentai.org/hentaiverse/. But I doubt Tenboro will do this. I won't list technical things because first of all: nobody can guarantee that in problematic countries you won't go in jail just for visiting front page of this forum.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Mar 20 2018, 17:37
Post #271
KhanJr



Newcomer
*
Group: Recruits
Posts: 11
Joined: 17-June 07


I'm sure the simplest answer is "use a different browser," but does anyone have suggestions on how to get galleries working with Firefox Quantum 59? The setting mentioned above (security.mixed_content.upgrade_display_content) isn't listed in about:config. Instead there's...

security.mixed_content.block_active_content
security.mixed_content.block_display_content
security.mixed_content.block_object_subrequest

I've tried various combinations of true and false for these settings, but gallery images still fail to load.

Mozilla has a [support.mozilla.org] page on this as well, but the button to disable protection that it talks about doesn't appear.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Mar 20 2018, 18:14
Post #272
Maximum_Joe



Legendary Poster
***********
Group: Gold Star Club
Posts: 24,074
Joined: 17-April 11
Level 500 (Dovahkiin)


Pretty sure you can just add that setting in about:config manually.

This post has been edited by Maximum_Joe: Mar 20 2018, 18:14
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
post Mar 20 2018, 22:38
Post #273
Tenboro

Admin




QUOTE(KhanJr @ Mar 20 2018, 16:37) *

I'm sure the simplest answer is "use a different browser," but does anyone have suggestions on how to get galleries working with Firefox Quantum 59?


There shouldn't be any issues with Firefox 59 even with default settings. Most likely your problem lies elsewhere.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

 
post Mar 21 2018, 12:58
Post #274
KhanJr



Newcomer
*
Group: Recruits
Posts: 11
Joined: 17-June 07


OK! I disabled every add-on, saw that galleries were working, and gradually re-enabled them until I found the culprit was Ghostery. Since it wasn't picking up any trackers, I hadn't thought it would be affecting the site.

Thanks for the advice (and for tolerating my ignorance). (IMG:[invalid] style_emoticons/default/blush.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post


14 Pages V « < 12 13 14
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


Lo-Fi Version Time is now: 20th April 2024 - 13:51