Author Topic: Forum IP and HTTPS  (Read 5649 times)

Jorl17

  • Wayfarer
  • *
  • Posts: 5
    • View Profile
Forum IP and HTTPS
« on: December 02, 2017, 06:21:08 am »
Hi!

A long time ago I was a reasonably active player, and I played in two different accounts. Sadly, life made me move on and pursue other things, but I always check in on the project when I can, to see how it is progressing.

However, I am very confused as to why there seems to be no HTTPS support in this modern day and age (where Let's Encrypt is a thing), and the forum is linked to directly through an IP, which seems even more baffling.

HTTPS is important because even if your plain HTTP website has nothing to do with private data, it can be caught in a Man In the Middle attack and used to automatically strip every HTTPS link down to an HTTP link, eventually compromising the users of said site. Since most websites do not implement HSTS to counter this, the only other solution is to progress the web to an HTTPS-only scenario. I believe that it is a social responsibility to keep sites under our control served over HTTPS instead of HTTP, since the alternative is harmful to the users of any site.

As such, I would like to request that the PlaneShift team migrate what they can to HTTPS. I could help in any way that is requested!

Please keep up the good work, and thanks :)
« Last Edit: December 02, 2017, 06:27:36 am by Jorl17 »

LigH

  • Forum Legend
  • *
  • Posts: 7096
    • View Profile
Re: Forum IP and HTTPS
« Reply #1 on: December 04, 2017, 08:16:59 am »
I believe the main issue is still owning a domain name; my browser is still unable to keep me logged in beyond a few minutes, because the cookie is created for a domain not registered to this IP anymore.

Gag Harmond
Knight and Ambassador
The Royal House of Purrty

Emaline

  • Game Masters
  • Hydlaa Citizen
  • *
  • Posts: 247
  • Game Master
    • View Profile
Re: Forum IP and HTTPS
« Reply #2 on: December 04, 2017, 03:18:54 pm »
It only does that to me ligH if I use the log in on the top left. Log out and use the log in on the bar of options. And tick the box. Let me know if that works.


As far as the other issue I think it was moved and supposedly to be moved again but the guy handling it has been very busy and what not. I have no idea for sure however.
I'm very responsible, whenever something goes wrong they always say I'm responsible.

Any Event idea find us on IRC #ps-event
Problem Ingame use IRC: #Planeshift-gmtalk

Jorl17

  • Wayfarer
  • *
  • Posts: 5
    • View Profile
Re: Forum IP and HTTPS
« Reply #3 on: December 04, 2017, 10:55:03 pm »
If there's anything I can help with, do say. I'm a software engineer but I do a bit of everything at my company, and that involves most of the IT stuff: domain registration, gateways, virtual hosts, orchestration, certificate management, etc. So I'd be happy to help in any way possible!
« Last Edit: December 04, 2017, 11:15:29 pm by Jorl17 »

LigH

  • Forum Legend
  • *
  • Posts: 7096
    • View Profile
Re: Forum IP and HTTPS
« Reply #4 on: December 05, 2017, 11:48:59 am »
The forum used to be managed by 'acraig'; but I believe he has more important duties now.

And I still use Opera 12 due to the lack of an adequate substitute. They keep adding polish instead of base material to Vivaldi. Unfortunately, Opera seems to be a bit more picky regarding the handling of cookies. Using the separate login page does not fix it for me.

Gag Harmond
Knight and Ambassador
The Royal House of Purrty