News:

This is the TEST SITE - feel free to post but content will be deleted

Main Menu

enabling SSL

Started by pdw1, April 18, 2022, 04:45:02 PM

Previous topic - Next topic

pdw1

Hi Slim,
People who know better then me suggest you enable SSL as a default. Are we a security risk?

Slim

Interesting point. I don't see it as necessary for a site like this, which is not entrusted with sensitive information.

pdw1

Quote from: Slim on April 18, 2022, 05:48:22 PMInteresting point. I don't see it as necessary for a site like this, which is not entrusted with sensitive information.
re-used passwords are always a risk. I know we should all use a different password for each site but someone wont.

Jonners

Nearly got dragged into an argument on FB about this with Dodds, then decided I couldnt be arsed. Arguing Rush with him was painful enough....

Slim

For perspective - over the nearly 20 years of its existence, TNMS never had an SSL cert. Neither do other similar fora I can think of, with considerably more traffic than this one. I can probably get a free certificate from Amazon so it wouldn't cost anything except my time, but I honestly don't think it's worth it.

Jonners

Agreed, and if anyone is ever worried about their email addresses, passwords, I wil be more than happy to do a pro Dark Web Search for them and see what is out there

Fishy

Quote from: Jonners on April 20, 2022, 01:08:22 PMAgreed, and if anyone is ever worried about their email addresses, passwords, I wil be more than happy to do a pro Dark Web Search for them and see what is out there


Any of the parodies found their  way to the dark side.........smiles....
From The Land of Honest Men

Slim

Well: I'm revisiting this old thread three years later to announce that SSL has now been set up for the site, so that security-minded individuals can now visit from the URL https://betweenthewheels.net (note the 'https' rather than 'http') and click around happily under the cover of an SSL certificate.

I still don't think this was worth doing for the 'usual reasons' as I commented in my previous post, but - there's a good chance that doing this will help me to get Cloudflare working as an anti-bot measure. Please see this thread.

Slim

I've set a redirect up in Cloudflare now so that any references to the http:// flavour of the site will redirect to the SSL-enabled site.

Apart from being slightly more secure, although as indicated above I wasnt really bothered about that - this has allowed me to set up some caching rules to save bandwidth. Shouldn't affect usability in any way.