PDA

View Full Version : Big problem with this site


AZKen
July 21st, 2020, 04:27 AM
Had to get in< in an unsafe manner> the site is using old tls versions>needs to update to tls 1.2 or newer> i will not be back>

Jeannie
July 21st, 2020, 07:41 AM
Had to get in< in an unsafe manner> the site is using old tls versions>needs to update to tls 1.2 or newer> i will not be back>

AZKen,

This is referring to our method of encryption and has nothing at all to do with the site being "unsafe".

History:
This is part of Google's push for ever newer encryption for site certificates (which they sell). This is how a website talks in code to your browser. Previously, websites talked to your browser straight through. Remember when the internet was fast? Things slowed down after Google demanded that sites visited by users with it's browser add encryption, regardless of if they handle credit card information. As Google goes, so goes the rest of the pack. Other browsers started notifying users that sites may be "unsafe" if they don't encrypt their site. Again, encryption of non-transactional sites (places that aren't selling you things) does nothing for the end user and adds unnecessary burden on the server and the site owner.

This threw Mom and Pop sites in chaos for a few months as they scrambled to find and implement certification. Once the turmoil died down and everyone had bowed to the mighty Google, Google again said, That is not good enough. We demand that you change your configuration or we'll label you as "unsafe" once more.

Why should this matter? It didn't until this year. When Google demanded that websites use the new encryption method, they didn't take into account that many sites are running on software that won't accept the newer "language". And that is where we will be at the next hop.

I believe we will be able to jump the current "unsafe" notification after we hire a coder to effectively jam the new encryption into our setup, but the next google-forced update will require that we abandon our current software and move to the new format, which is full of bugs and security leaks that I have been studying and following for over a year in preparation. This will, and I can't overstate this, be a nightmare for me and a big change for our users. Sadly our current software, while extremely stable and secure, will not operate with the newer backend that we will be forced to implement at that time.

For now, the notification does not appear for all browsers. Rest assured that the site is not "unsafe". For reference, over 2/3 of the internet is using our current encryption level or less.

We have been putting this off due to cost and the lack of necessity, but with the current clout Google has it was only a matter of time before this became an issue.

I will be working on the issue this week.

AZKen
July 21st, 2020, 08:57 AM
Thank you Jeannie. It's so weird. I just got in without seeing the message. Otherwise, after clicking the "ADVANCE" button on the message, it will allow you in, in what they call "unsafe" mode. As you say, it's safe. I understand now. Very sorry for all of us, but mostly for you. Thank you for what you do and how savvy you are about all this crazy Google crap. I have changed my heading to non dramatic. :notworthy:

Funky61
July 21st, 2020, 05:21 PM
Thanks Jeannie for explaining the Google backstory and certificates and all that. it was interesting.
Happy to say I had no problem being directed to the site directly minus the "Warning Wall"

Thanks for all you do, Henry aka Funky61.

jbgroby
July 22nd, 2020, 01:38 PM
I too have been getting the message through our server and our firewall simply won't let me go around (IT does get upset) so for the past 6 months or so I dont post. I'm posting this from my phone now, which is a hassle.

Jeannie
July 22nd, 2020, 04:16 PM
I too have been getting the message through our server and our firewall simply won't let me go around (IT does get upset) so for the past 6 months or so I dont post. I'm posting this from my phone now, which is a hassle.

Hi JbGroby,

From previous conversations, we had determined that your issue at work was that your IT department had blocked any sites located in France. Unfortunately, I have no control over this at this time.

Have a great day,

-Jeannie
6066 GMC Club

jbgroby
July 23rd, 2020, 01:28 PM
I understand, not y'all problem. I'll try to keep posting from my phone.