Jump to content

Primary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Secondary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Pattern: Blank Waves Squares Notes Sharp Wood Rockface Leather Honey Vertical Triangles

Amuro Ray

Amuro Ray

Member Since 25 Nov 2011
Offline Last Active Apr 10 2015 11:22 PM

#1278173 Enhancing Batoto Security (Sorta)

Posted by Grumpy on 10 June 2014 - 07:20 PM

Well, with recent case of security outbreak, thought it'd be a good time to make a small change.

 

Short version:

  • SSL logins! Hit forums page first! And then click login. This will allow your login info to be encrypted while it comes to our server.
  • Admin panel! Yeah... doesn't affect you (minus 3 people)...

 

 

Long version:

Definitions:

Core site - This includes forums, members page, mod panel, admin panel, etc. which are included by IPB's most basic forum package.

IPC - IP.Content based - This includes front page, comics, random, groups, chat, etc. This is an addon module made by IPB.

 

Batoto has a lot of non-secure content in the core site. That includes people's signatures, social media crap, etc. So, throughout the core site you'll see either a mixed content warning, broken padlock or missing padlock (depending on browser). So, it's not something that was added to make the entire site encrypted, but mainly to target safer login page and admin panel.

 

As for the IPC pages, I found out it's rather impossible (without large amount of reprogramming ipc) to support https right now due to how ipc is made and how ads work. So, whenever you visit an IPC page, you'll be sent back to http (non encrypted). 

 

If you are one of those odd people that still use IE8 or similar ancient browsers, you're gonna start getting a lot of popups saying this page has mixed content and how it's insecure.... when it's still not any worse than regular page. You can turn that warning off permanently. Here is some random blog I found which gives a tutorial on how to disable that. But this demographic only make up <0.01% of my viewers (percentage counter doesn't go any lower). Multiply that with chance that they actually view the forums, you become <0.001%. So, I've safely nulled them from my loss calculation.

 

 

PS. I finally used the SSL 1 year voucher I got back in 2012.