Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: LesbianThespianGymnasticMidget; rarestia
> SHA 256 recently implemented. Change your bookmark to HTTPS rather than HTTP. It is no longer clear text.

Excellent -- bookmarks to the login page are changed.

However, of necessity, the regular site pages -- including the forum main page "Latest Articles" -- are still using the insecure (HTTP) URL and link refs. So if I click a link to the forum main page, it's an insecure link. Then the question is, during the login negotiation where my browser (which saves my password) is queried by the server, and responds with my (saved) password, is -that- exchange done with SSL encryption. I'm guessing it is NOT.

Same for any URLs to threads that I copy from the address bar and paste into email to a friend.

Any insight?

80 posted on 06/05/2017 6:02:20 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 69 | View Replies ]


To: dayglored

Add the S. It is sitewide. Start from https://freerepublic.com/tag/*/index

Everything is SHA 256.


83 posted on 06/05/2017 6:20:43 PM PDT by LesbianThespianGymnasticMidget (God punishes Conservatives by making them argue with fools. Go Trump!)
[ Post Reply | Private Reply | To 80 | View Replies ]

To: dayglored

The site connection over HTTPS (TCP 443) is secure. This ensures traffic (your whereabouts, post texts, etc.) are encrypted in transit. They’re viewable on the site, but the transmission cannot be tampered with.

The login FORM on https://freerepublic.com/perl/login is NOT secure. If I check the debugger on the site, I see three warnings:

http://freerepublic.com/l/common.css
http://freerepublic.com/l/common.js
Password field form action insecure

These three items need to be fixed in the HTML code in order to resolve this issue. Not sure if anyone has a line to Jim or John, but these are the only pieces left insecure that I can find.


94 posted on 06/06/2017 10:47:20 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 80 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson