Results 1 to 4 of 4
Like Tree3Likes
  • 1 Post By Swarup
  • 2 Post By Raymond

Thread: Raymond.cc Forum is now more secure - SSL Encryption in Forum Registration and Phone

  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Jul 2009
    Location
    Kolkata , West Bengal , India
    Posts
    1,559
    Liked
    54 times
    Points
    18,175

    Nominated Star Raymond.cc Forum is now more secure - SSL Encryption in Forum Registration and Phone

    Secured websites such as PayPal or online banking websites uses SSL encryption to ensure secure transactions between web servers and browsers. The difference between a normal and an encrypted webpage is the additional S after HTTP which becomes HTTPS. Current version of web browsers has made a change where by when you visit a normal unencrypted webpage, it no longer shows the HTTP. Only when you visit a SSL encrypted page, the web browser will display the HTTPS together with either the lock icon (Internet Explorer and Google Chrome), or Site Identity Button (Firefox) or Security Badge (Opera).

    It doesn’t mean that entering your login information on a SSL encrypted page is 100% safe because there is a technique called WEBMITM (web man-in-the-middle) where the attacker is able to steal your sensitive information. Basically the attack will only work if the attacker manage to connect to the same network as you either through wireless or LAN. So make sure you’ve set your wireless router to use WPA2 encryption with a non-dictionary word as password and use a VPN when you have to connect to public Wi-Fi. ...................................

    I wouldn’t want to use HTTPS on the whole site because it is slower, consume more bandwidth and puts more load on the server. So the best option is to only use HTTPS on certain important pages such as the registration and phone verification page. This is easily done with a custom vBulletin plugin that hooks a couple of location.

    The biggest problem that I went through was the mixed-content of HTTP and HTTPS on a secured page. Although that shouldn’t cause any problems but it triggers a warning message “Internet Explorer blocked this website from displaying content with security certificate error” without a pad lock icon. Opening the secure page with mixed content in Chrome shows a red crossed out HTTPS. Instead of giving people confidence with the SSL encryption, the errors may end up scaring the visitors away.


    Phone verification page is secured with 2048 bit RSA/SHA encryption


    Forum registration page is also secured and encrypted


    ................. I hope this update will provide everyone a more peace of mind when registering a new account in forum and performing a one-time phone verification. X-Ray will finally be released soon and am looking into code signing to guarantee to users that they are, in fact, running the code they believe they are running, and that the code was written by the individual or organization that the certificate was issued to. It is a good way to verify that the code being run has not been altered or corrupted, but the code signing process is pretty long and also expensive.


    Read the full post here - http://www.raymond.cc/blog/archives/2011/11/08/ssl-encryption-in-forum-registration-and-phone-verification/

    I think is a great move and it will keep your personal info mode secure. Guys what do you think about it ?

    Thanks Ray.

  2. #2
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    I've thought of this before but didn't really put an effort into it.
    Thanks to leofelix for his suggestion which made me implement this.
    Now I just have to think of where should I insert the seal on the forum and blog.

  3. #3
    Verified Member
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    India
    Posts
    43
    Liked
    1 times
    Points
    1,659
    I thought I would give a try and see if https://www.raymond.cc/blog would work... and yes it did but the lay out was not normal and I got a prompt that said that I can always revert back to the non-secure version, i.e., the http://www.raymond.cc/blog version

    I was just curious...

    PS. I hate that Zombify yourself ad on this blog... It scares me...

    Just kiddin...
    Last edited by tejaswi; 11-10-2011 at 01:38 AM.

  4. #4
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    There is no point to use HTTPS on the blog as most of the time you'll be viewing content and not sending any sensitive information such as login/password.

 

 

Similar Threads

  1. A new section in Raymond.CC Forum
    By Murphy in forum Chat
    Replies: 24
    Last Post: 08-25-2011, 03:33 AM
  2. 1 year in Raymond.cc forum
    By INDRANIL in forum Chat
    Replies: 18
    Last Post: 05-12-2011, 01:04 AM
  3. Raymond.cc Forum Archive
    By safeguy in forum General Forum
    Replies: 2
    Last Post: 01-14-2010, 01:32 AM
  4. Bye Raymond.cc Forum (for 7 weeks)
    By bahirzaheri8 in forum Chat
    Replies: 6
    Last Post: 07-14-2008, 03:51 PM
All times are GMT +8. The time now is 01:02 AM.