Mozilla Firefox sees WP as "insecure"

Page 1 of 1 [ 16 posts ] 

AspieUtah
Veteran
Veteran

User avatar

Joined: 20 Jun 2014
Age: 61
Gender: Male
Posts: 6,118
Location: Brigham City, Utah

28 Jan 2017, 8:59 am

https://support.mozilla.org/en-US/kb/in ... =inproduct


_________________
Diagnosed in 2015 with ASD Level 1 by the University of Utah Health Care Autism Spectrum Disorder Clinic using the ADOS-2 Module 4 assessment instrument [11/30] -- Screened in 2014 with ASD by using the University of Cambridge Autism Research Centre AQ (Adult) [43/50]; EQ-60 for adults [11/80]; FQ [43/135]; SQ (Adult) [130/150] self-reported screening inventories -- Assessed since 1978 with an estimated IQ [≈145] by several clinicians -- Contact on WrongPlanet.net by private message (PM)


kraftiekortie
Veteran
Veteran

Joined: 4 Feb 2014
Gender: Male
Posts: 87,510
Location: Queens, NYC

28 Jan 2017, 10:34 am

I'm not surprised.

There's so many bugs....who knows if one of those "bugs" might be sending stuff from WP to somewhere else.



leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 10:58 am

The only actual security issue here at WrongPlanet is related to username and password during site login. WrongPlanet does not need to be a secure (https://) -- https://en.wikipedia.org/wiki/HTTPS -- site since its user database does not contain any sensitive information such as our physical addresses, financial account numbers and so on. The only "danger" here is that it is at least theoretically possible for our usernames and passwords to be harvested during login, but there is no reason to believe anyone would actually bother with trying to do that since there could be no financial gain. However, anyone who might be using the same login credentials (primarily password) here as at any other site should definitely be certain your WrongPlanet password will *not* work anywhere else (such as at a banking site).


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================


Last edited by leejosepho on 28 Jan 2017, 11:07 am, edited 1 time in total.

leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 11:02 am

kraftiekortie wrote:
I'm not surprised.

There's so many bugs....who knows if one of those "bugs" might be sending stuff from WP to somewhere else.

With all due respect: Please try to avoid ill-informed speculation. Everything posted at WP is available virtually everywhere, and there is no "stuff" that even could be sent anywhere that would ever cause any harm to anyone who posts here. This issue is *only* about the possibility of someone harvesting your username and password during login* and has absolutely nothing to do with the WrongPlanet database or site ever being compromised.

*note: I would guess our host has a solid firewall possibly blocking that kind of activity.


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================


kraftiekortie
Veteran
Veteran

Joined: 4 Feb 2014
Gender: Male
Posts: 87,510
Location: Queens, NYC

28 Jan 2017, 11:10 am

I guess I was thinking of a worst-case scenario type of situation.

I didn't mean to shout "fire" in a crowded theater.



leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 11:13 am

kraftiekortie wrote:
I guess I was thinking of a worst-case scenario type of situation.

I didn't mean to shout "fire" in a crowded theater.

No problem, and I hope I did not sound scolding!


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================


SaveFerris
Veteran
Veteran

User avatar

Joined: 3 Sep 2016
Gender: Male
Posts: 14,762
Location: UK

28 Jan 2017, 11:19 am

leejosepho wrote:
The only actual security issue here at WrongPlanet is related to username and password during site login. WrongPlanet does not need to be a secure (https://) -- https://en.wikipedia.org/wiki/HTTPS -- site since its user database does not contain any sensitive information such as our physical addresses, financial account numbers and so on. .


You may not find your email address and the types of password you use as sensitive but I do , your email address and type of password you use in the hands of a wrong-doer can be a PITA


_________________
R Tape loading error, 0:1

Hypocrisy is the greatest luxury. Raise the double standard


leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 11:35 am

SaveFerris wrote:
You may not find your email address and the types of password you use as sensitive but I do , your email address and type of password you use in the hands of a wrong-doer can be a PITA

Understood, but I do not use my e-mail address for login and the chance of someone actually bothering to try to harvest my password (only even possible during login) here is extremely slim since there would be virtually nothing to be gained from having done so.


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================


Jacoby
Veteran
Veteran

Joined: 10 Dec 2007
Age: 32
Gender: Male
Posts: 14,284
Location: Permanently banned by power tripping mods lol this forum is trash

28 Jan 2017, 11:38 am

Is it just me or has Firefox gotten a lot worse in general lately?



AspieUtah
Veteran
Veteran

User avatar

Joined: 20 Jun 2014
Age: 61
Gender: Male
Posts: 6,118
Location: Brigham City, Utah

28 Jan 2017, 11:40 am

Jacoby wrote:
Is it just me or has Firefox gotten a lot worse in general lately?

It is debuting its higher-security measures today. But, I don't believe it is worse. Still, I wish it would better regulate its add-ons. Too many are concerning.


_________________
Diagnosed in 2015 with ASD Level 1 by the University of Utah Health Care Autism Spectrum Disorder Clinic using the ADOS-2 Module 4 assessment instrument [11/30] -- Screened in 2014 with ASD by using the University of Cambridge Autism Research Centre AQ (Adult) [43/50]; EQ-60 for adults [11/80]; FQ [43/135]; SQ (Adult) [130/150] self-reported screening inventories -- Assessed since 1978 with an estimated IQ [≈145] by several clinicians -- Contact on WrongPlanet.net by private message (PM)


Jacoby
Veteran
Veteran

Joined: 10 Dec 2007
Age: 32
Gender: Male
Posts: 14,284
Location: Permanently banned by power tripping mods lol this forum is trash

28 Jan 2017, 11:46 am

AspieUtah wrote:
Jacoby wrote:
Is it just me or has Firefox gotten a lot worse in general lately?

It is debuting its higher-security measures today. But, I don't believe it is worse. Still, I wish it would better regulate its add-ons. Too many are concerning.


Longer than today, it's just been really slow and sucking up a lot of resources. Maybe it's the combination of add-ons I'm using? Probably is just my computer but I dunno what the issue is.



leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 12:13 pm

I sometimes play around with these a bit: https://www.google.com/search?q=firefox+about%3Aconfig


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================


SaveFerris
Veteran
Veteran

User avatar

Joined: 3 Sep 2016
Gender: Male
Posts: 14,762
Location: UK

28 Jan 2017, 1:09 pm

leejosepho wrote:
SaveFerris wrote:
You may not find your email address and the types of password you use as sensitive but I do , your email address and type of password you use in the hands of a wrong-doer can be a PITA

Understood, but I do not use my e-mail address for login and the chance of someone actually bothering to try to harvest my password (only even possible during login) here is extremely slim since there would be virtually nothing to be gained from having done so.


If I had you WP password I could get your email address , but I agree there's a slim chance of this happening but on a forum of Aspie's I would say the chances are higher. Bored Aspie hackers could bring down governments if they were social and got together :lol:


_________________
R Tape loading error, 0:1

Hypocrisy is the greatest luxury. Raise the double standard


smudge
Veteran
Veteran

User avatar

Joined: 6 Sep 2006
Age: 36
Gender: Female
Posts: 7,716
Location: Moved on

28 Jan 2017, 3:12 pm

I think technology is getting increasingly worse and slower so that it makes people want to throw tantrums and punch the person next to them.

The more in depair everyone is, the more exhausted everyone will be, and the more they can get away with!!

I wonder if there is some truth to that.

The internet is crammed full of sh!t. So is technology in general. Nothing works properly, it's sh!t.


_________________
I've left WP.


mr_bigmouth_502
Veteran
Veteran

User avatar

Joined: 12 Dec 2013
Age: 30
Gender: Non-binary
Posts: 7,028
Location: Alberta, Canada

28 Jan 2017, 3:26 pm

HTTPS Everywhere lists Wrong Planet as being "broken MCB, partial". I'll be honest, I'm really not sure what this means.


_________________
Every day is exactly the same...


leejosepho
Veteran
Veteran

User avatar

Joined: 14 Sep 2009
Gender: Male
Posts: 9,011
Location: 200 miles south of Little Rock

28 Jan 2017, 8:19 pm

mr_bigmouth_502 wrote:
HTTPS Everywhere lists Wrong Planet as being "broken MCB, partial". I'll be honest, I'm really not sure what this means.

Me neither, but it does look like "HTTPS Everywhere" might be helpful for anyone concerned:
https://www.eff.org/https-everywhere/at ... t.net.html

Somewhere else I have seen mention of the idea of a developer making a secure (https://) page for login while letting the remainder of the site run without encryption, but I think it would be easier to just add an SSL certificate for the entire site. Also, it is at least possible that WrongPlanet actually might have a self-signed certificate making encryption possible. I had that at my own sites for a while until my certificate expired.

Update: I just logged out and then used https://wrongplanet.net/forums/ to log back in again, so it does appear encryption actually is available here.


_________________
I began looking for someone like me when I was five ...
My search ended at 59 ... right here on WrongPlanet.
==================================