Results 1 to 4 of 4
  1. #1
    Senior Member
    Join Date
    Nov 2014
    Location
    Canada BC
    Posts
    238

    Outdated cryptography

    When using google chrome i get a message that this site is using obsolete cryptographyCapture.PNG.

  2. #2
    Member
    Join Date
    Mar 2015
    Location
    Kansas City, MO
    Hammock
    Warbonnet Blackbird
    Tarp
    Warbonnet Superfly
    Insulation
    JRB GL & SS
    Posts
    75
    Quote Originally Posted by hanginyaker View Post
    When using google chrome i get a message that this site is using obsolete cryptographyCapture.PNG.
    On bleeding edge Chromium (the browser that Chrome is based on and updated less frequently), I show that the SSL certificate is valid, signed and uses TLS 1.0 and AES 256. While this is not the be all and end all of server-client encryption, it's plenty for a forum site. Of course, the encryption almost shouldn't matter since you're not using a forum password that matches your email or banking passwords. Which everyone is avoiding, right? We're not using our super-secure credentials to authenticate on potentially less-secure portals like forum sites and cottage vendor sites. We would never do that, because we're educated modern people. So if you're doing that, stop it immediately.

    Also, that warning on that specific thread might be caused by a non-secure CDN (content delivery network). If so, you have little to worry about as there's only basic header negotiation happening there, so it's effectively one-way. As long as you're not getting scripts delivered via that CDN your risk is minimal (it's never zero).

  3. #3
    Senior Member muckypops's Avatar
    Join Date
    Feb 2015
    Location
    Wilmington, IL
    Hammock
    Hammeck Netty, Dutch PolyD
    Tarp
    WB Edge, Noah 12
    Insulation
    AHE Jarbridge
    Suspension
    Straps / Whoopies
    Posts
    147
    Quote Originally Posted by seanhogge View Post
    On bleeding edge Chromium (the browser that Chrome is based on and updated less frequently), I show that the SSL certificate is valid, signed and uses TLS 1.0 and AES 256. While this is not the be all and end all of server-client encryption, it's plenty for a forum site. Of course, the encryption almost shouldn't matter since you're not using a forum password that matches your email or banking passwords. Which everyone is avoiding, right? We're not using our super-secure credentials to authenticate on potentially less-secure portals like forum sites and cottage vendor sites. We would never do that, because we're educated modern people. So if you're doing that, stop it immediately.

    Also, that warning on that specific thread might be caused by a non-secure CDN (content delivery network). If so, you have little to worry about as there's only basic header negotiation happening there, so it's effectively one-way. As long as you're not getting scripts delivered via that CDN your risk is minimal (it's never zero).
    What he said.... thanks for handling that. I was just composing my reply when yours popped up. Great work.
    "Everything works if you let it." - Corpus C. Redfish

  4. #4
    Member
    Join Date
    Mar 2015
    Location
    Kansas City, MO
    Hammock
    Warbonnet Blackbird
    Tarp
    Warbonnet Superfly
    Insulation
    JRB GL & SS
    Posts
    75
    Quote Originally Posted by muckypops View Post
    What he said.... thanks for handling that. I was just composing my reply when yours popped up. Great work.
    'Tweren't no trouble, sir. Glad to see another techhead 'round here.

  • + New Posts
  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •