SIGforum
SigForum Security Threat??

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/320601935/m/4630054134

October 07, 2017, 08:41 PM
Scoutmaster
SigForum Security Threat??
I have used Firefox for many years. A few months ago Firefox started warning me of a security threat (I believe it said unsecured site or something) when I logged in. I logged in anyway.

A few minutes ago I tried to log in with Firefox, Norton came up in a big window, told me the site was blocked as it was a security threat.

Anyone else have such problems? It wouldn't surprise me that the liberal mindsets in these firms would take exception to a gun forum merely for political reasons.

(I am using Google which doesn't seem to have any problems).




"Liberty lies in the hearts of men and women. When it dies there, no constitution, no law, no court can save it....While it lies there, it needs no constitution, no law, no court to save it"
- Judge Learned Hand, May 1944
October 07, 2017, 08:45 PM
H&K-Guy
Hmmmm. I can't seem to duplicate your problem. It's all good, at least on my end.

Make a pass with Malwarebytes and your favorite AV software, toss your cookies, kill all errant processes and progies, etc., et all, ad nausium, ad infinitum, 'n' stuff.

Reboot, rinse, repeat. You know the drill.

H&K-Guy
October 07, 2017, 08:56 PM
RichN
The issue is that the login page does not use encryption. Someone in the middle could theoretically grab your username and password.


------------------------------
"They who would give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
- Benjamin Franklin

"So this is how liberty dies; with thunderous applause."
- Senator Amidala (Star Wars III: Revenge of the Sith)
October 07, 2017, 08:57 PM
sdy
I saw the same thing. Posted in the SIGforum Office section.

Showed pics of the display.

Looks like Norton Safe Web has tagged SIGforum as unsafe.
October 07, 2017, 08:59 PM
Scoutmaster
I just logged in using Chrome, got the Norton block (for the first time)




"Liberty lies in the hearts of men and women. When it dies there, no constitution, no law, no court can save it....While it lies there, it needs no constitution, no law, no court to save it"
- Judge Learned Hand, May 1944
October 07, 2017, 08:59 PM
Scoutmaster
quote:
Originally posted by RichN:
The issue is that the login page does not use encryption. Someone in the middle could theoretically grab your username and password.


Thanks for the info.




"Liberty lies in the hearts of men and women. When it dies there, no constitution, no law, no court can save it....While it lies there, it needs no constitution, no law, no court to save it"
- Judge Learned Hand, May 1944
October 07, 2017, 09:06 PM
parabellum
How can I disable Insecure password warning in Firefox?
October 07, 2017, 09:06 PM
ensigmatic
quote:
Originally posted by Scoutmaster:
It wouldn't surprise me that the liberal mindsets in these firms would take exception to a gun forum merely for political reasons.

Loosen-up that tinfoil at bit, there, Scoutmaster Smile

All it's doing is warning you that you're supplying authentication credentials (username + password) over an unencrypted link.

There are two problems attendant with doing so: 1. Somebody sniffing traffic to/from Sigforum can snag username/password credentials as they fly by. 2. DNS hijacking can lead you to a Sigforum look-alike, you "log in": Bang: Your credentials are stolen.

For a site like Sigforum, where no commerce is done (e.g.: CC info, etc. passed): The threat is not so great. But your browser has no way of knowing that, so it warns whenever login credentials are passed over an insecure circuit.

No offence to our host: But there's really no reason SF can't be using HTTPS. With the successful launch of Let's Encrypt, which provides free non-validated SSL certs for all comers, every site on the 'net can easily have SSL/TLS encryption.

There's even a set of tools to make it easy-peasy to do, and have the cert automatically renewed. (The automatically expire every 90 days. Saves having to deal with the complexities of Certificate Revocation Lists [CRLs].)

quote:

With all due respect: In my opinion that is unwise.



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
October 07, 2017, 09:11 PM
parabellum
There's nothing to worry about in any of this but be my guest.
October 07, 2017, 09:14 PM
sigmonkey
Equifax and all their really super duper double naught spy cipherin' worry me.

Here. Nope. Not worried.




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא שוב!
October 07, 2017, 09:20 PM
sdy
para,

I got the same kind of warnings. I posted in the SIGforum Office section.

Norton Safe Web is tagging sigforum. I posted pics of the displays.

I am in SIGforum a lot. I don't have any concerns on this. Just letting you know of the issue.
October 07, 2017, 09:20 PM
Scoutmaster
quote:
Originally posted by ensigmatic:...
Loosen-up that tinfoil at bit, there, Scoutmaster....


Thanks for the advice, you don't know my neighbors, sometimes tinfoil might come in handy. Smile

Most neighbors are propeller-heads (techies) of the Hillary persuasion. One told me they have a hard time sleeping at night, they fear for their safety, knowing I might have a gun in the home (they know I am a white male Christian conservative so I must have a gun).

My surrounds include techies from Apple, Google, Facebook, Intel, nVidia, Symantec, Mozilla, various communications firms, they all drink the same political kool-aid.




"Liberty lies in the hearts of men and women. When it dies there, no constitution, no law, no court can save it....While it lies there, it needs no constitution, no law, no court to save it"
- Judge Learned Hand, May 1944
October 07, 2017, 09:23 PM
sdy
Scoutmaster,

Your "tin foil" concern was exactly the same as my first reaction on seeing the warning.

sdy
October 07, 2017, 09:31 PM
ensigmatic
quote:
Originally posted by Scoutmaster:
quote:
Originally posted by ensigmatic:...
Loosen-up that tinfoil at bit, there, Scoutmaster....


Thanks for the advice, you don't know my neighbors, sometimes tinfoil might come in handy. Smile

Sorry, meant to put a smiley on that comment. Thanks for reading it as implied Smile



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
October 07, 2017, 10:01 PM
logrusmaster
You're connecting to a website that doesn't use HTTPS (SSL) for authentication.

It's pretty much a 'standard' around the world now. Personally I use a different password for every website so. I really couldn't care less if someone managed to sniff my password for the forum.

Firefox just thinks they are 'helping' most of the normal users and saving them from themselves.


-------------------------
If not me then who? If not now then when?
October 07, 2017, 10:08 PM
preten2b
I just got the Dangerous Website Blocked message on Google Chrome. 1st time, and I was already logged in, just changing page to a different topic from this morning.

I do not like to think it's more than coincidence. Is it possible somebody does not like our favorite topics.


------------------
The plural of anecdote is not data. -Frank Kotsonis
October 08, 2017, 12:38 AM
CPD SIG
Same here...
Logged on with Google, got the Norton Security threat. Logged on again, same thing happened again...


______________________________________________________________________
"When its time to shoot, shoot. Dont talk!"

“What the government is good at is collecting taxes, taking away your freedoms and killing people. It’s not good at much else.” —Author Tom Clancy
October 08, 2017, 04:38 AM
egregore
It doesn't surprise me that Norton figures into this. I swear, that thing is itself a virus. Roll Eyes
October 08, 2017, 05:34 AM
Paten
I use Norton and Firefox. I get the insecure login message but not the unsafe site message. It's been this way for months. No big deal.
October 08, 2017, 06:04 AM
ensigmatic
quote:
Originally posted by preten2b:
I just got the Dangerous Website Blocked message on Google Chrome. 1st time, and I was already logged in, just changing page to a different topic from this morning.

Google's Safe Browsing tech. doesn't have Sigforum listed. You're welcome to check it, yourself, at https://transparencyreport.goo...safe-browsing/search

quote:
Originally posted by preten2b:
I do not like to think it's more than coincidence.

Then don't.

Of course: If you want to believe the maker of one of the world's most popular browsers has decided to commit Internet suicide over politics, you're free to do so.

(N.B.: I don't use Google Chrome/Chromium, but not because I think they're trying to control what I browse.)

quote:
Originally posted by CPD SIG:
Same here...
Logged on with Google, got the Norton Security threat. Logged on again, same thing happened again...

See emphasis, above. Solution: Don't use dodgy anti-malware tools. (N.B.: They're all dodgy, IMO.)



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher