Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

*VANITY* I was hacked and I'm no longer secure on FR *VANITY*
self ^ | March 3, 2017 | knarf

Posted on 03/03/2017 2:32:11 AM PST by knarf

A couple of months ago, my card was hacked, not my account, so I waited for a new one to re-submit my FR donation.


TOPICS: Crime/Corruption; Culture/Society; Unclassified; Your Opinion/Questions
KEYWORDS: cybersecurity; donate; ecommerce; faq; hacking
Navigation: use the links below to view more comments.
first 1-2021-4041-53 next last
So I got my new card and waited until SS day to re-up my donation and I got THIS message; .

Your connection is not secure

The owner of secure.freerepublic.com has configured their website improperly. To protect your information from being stolen, Firefox has not connected to this website.

Learn more…

Report errors like this to help Mozilla identify and block malicious sites.

.

After the hack, I was having trouble with CHROME (I started a thread about it) and decided to download FIREFOX>

FIREFOX sometimes sounds like a geiger counter (desktop PC) when there is no activity and it has frozen up three or four times a day in the last two days.

So once again I appeal to my FReeper FRiends.

Is the FBI on to me and I'm screwed, or is Firefox not as good as I thought, or what ?

I e-mailed JimRob but it's too early for him and I'm anxious about this.

?Anyone ?

Thanx.

1 posted on 03/03/2017 2:32:11 AM PST by knarf
[ Post Reply | Private Reply | View Replies]

To: knarf
My card hasn't been hacked but I've been getting similar messages from Chrome for some time - pinged Jim and was told that FR was secure but there was something going on with Chrome.

Chrome still gives me the message that I'm not secure but I just tried Firefox and it showed secure.

2 posted on 03/03/2017 2:39:18 AM PST by trebb (Where in the the hell has my country gone?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knarf; Drumbo

Are you logged in?

Is your beeber stuned?

Sorry to make light of your trouble. In lots of pain & in a bitchy mood.

“As if she needs a reason,” mutters my better half.


3 posted on 03/03/2017 2:44:07 AM PST by Titan Magroyne (What one person receives without working for, another person must work for without receiving.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: trebb
Maybe a combined effort by browsers to keep people from donating to FR ?

Wait a minute ... I need to re-new my tinfoil

Seriously though ... THAT is weird.

4 posted on 03/03/2017 2:44:08 AM PST by knarf
[ Post Reply | Private Reply | To 2 | View Replies]

To: Titan Magroyne; trebb

Check out trebb above .... same thing only different


5 posted on 03/03/2017 2:45:27 AM PST by knarf
[ Post Reply | Private Reply | To 3 | View Replies]

To: trebb
I just tried the hyperlink above and got the same insecure message

I have no problem with donating beyond the popup (especially after you said you got a Chrome one but now your Firefox is secure) ... I just think it's weird and if there IS something out there ... we should know about it.

FReepers use the net every day all over the place and we could be spreading disease or something

6 posted on 03/03/2017 2:49:11 AM PST by knarf
[ Post Reply | Private Reply | To 2 | View Replies]

To: knarf; Jim Robinson; John Robinson; Sidebar Moderator

The problem is likely that FR’s using a compromised security certificate. A lot of sites got hit by this problem.

Additional details of the problem:
“secure.freerepublic.com uses an invalid security certificate. The certificate is not trusted because it was signed using a signature algorithm that was disabled because that algorithm is not secure. Error code: SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED”

https://secure.freerepublic.com/donate/

The certificate was signed using a signature algorithm that is disabled because it is not secure.

HTTP Strict Transport Security: false
HTTP Public Key Pinning: false”

I deleted the certificate chain as it wasn’t needed.

This is related to the SHA-1 vulnerability; several years ago, the phaseout of that algorithm began, but it was only recently that it began being enforced by browsers like Chrome, Firefox, etc.

More info here: https://www.godaddy.com/garage/webpro/security/google-chrome-phasing-ssl-certs-using-sha-1/

Modern browsers like Chrome (since 2015) and now Firefox and others will by default now block (not just warn!) any SSL/security certificate that meets the following criteria:

1. The cert uses the SHA1 hashing algorithm

2. The cert expires on or after 2017-01-01

If both these are met, the site is blocked by default.

Need to go back to the authority issuing the certificate and get them to issue a new one.


7 posted on 03/03/2017 3:00:11 AM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spktyr

So even if I tried to donate, Firefox would black it anyway ?


8 posted on 03/03/2017 3:03:45 AM PST by knarf
[ Post Reply | Private Reply | To 7 | View Replies]

To: knarf; Jim Robinson; John Robinson; Sidebar Moderator

Follow-up with more information - yes, SHA1 *has* been broken.

http://www.theverge.com/2017/2/23/14712118/google-sha1-collision-broken-web-encryption-shattered

“As a result, most sites have already dropped SHA-1. As recently as 2014 it was being used for as much as 90 percent of the encryption on the web, but it’s been mostly abandoned in the years since. As of January 1st, every major browser will show you a big red warning when you visit a site secured by SHA-1. It’s hard to say how many of those sites are left, but anyone with a halfway decent certificate provider is already safe.”


9 posted on 03/03/2017 3:04:47 AM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: knarf

Firefox and most recently updated browsers will either block you or will force you to manually override the security measure to proceed. You can in fact tell Firefox to proceed anyway (it’s under the Advanced button that pops up in the warning dialog) but that’s not a good idea. Conceptually, you would only be slightly less secure if you wrote your credit card and personal information on the outside of a package and sent it through the US Postal Service to a public mail room.


10 posted on 03/03/2017 3:10:56 AM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Spktyr

Thanx ... I’ll wait for the left coast to awaken.


11 posted on 03/03/2017 3:14:53 AM PST by knarf
[ Post Reply | Private Reply | To 10 | View Replies]

To: knarf; Jim Robinson; John Robinson; Sidebar Moderator
I would also point out that failing to fix this will get FR automatically reported to Google, Mozilla and other browser makers as a malicious site, which could mean that FR would eventually be placed on a site block list. Many people configure their browsers to report issues like this automatically to help the overall security of the web:


12 posted on 03/03/2017 3:21:18 AM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: knarf

The FR donation website is secure by DoD IT standards.


13 posted on 03/03/2017 3:29:51 AM PST by Justa
[ Post Reply | Private Reply | To 1 | View Replies]

To: knarf

"....sa sa some fox has a disease?"

14 posted on 03/03/2017 3:36:11 AM PST by Doogle (( USAF.68-73..8th TFW Ubon Thailand..never store a threat you should have eliminated)))
[ Post Reply | Private Reply | To 11 | View Replies]

To: knarf; Lazamataz

Laz is a web genius. He is a pro, I think. Maybe he’s feeling generous and can give some free assistance.

Laz?


15 posted on 03/03/2017 4:08:15 AM PST by Jemian (War Eagle!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knarf
You are likely just fine.

Talks in this thread about SHA-1 are overblown. Google Chrome is taking a super cautious, preemptive step because it is now shown a code can be broken if you have thousands of years of computer time available.

16 posted on 03/03/2017 4:10:39 AM PST by ConservativeMind ("Humane" = "Don't pen up pets or eat meat, but allow infanticides, abortion, and euthanasia.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: knarf

I’m using Firefox and I do not get that message, however, with chrome I do get the following warning: Your connection is not private.


17 posted on 03/03/2017 4:14:44 AM PST by Robert DeLong
[ Post Reply | Private Reply | To 1 | View Replies]

To: Doogle

"....sa sa some fox has a disease?"

NOooooooooooo

18 posted on 03/03/2017 4:34:00 AM PST by mountn man (The Pleasure You Get From Life, Is Equal To The Attitude You Put Into It)
[ Post Reply | Private Reply | To 14 | View Replies]

To: knarf

I use Chrome with no ill effects.

I have had credit cards hacked several times with no ill effects. One time I missed FR payment and another time I made a double payment. Both hacks were attributed to medical payments


19 posted on 03/03/2017 4:37:21 AM PST by bert (K.E.; N.P.; GOPc;WASP .... Hillary is Ameritrash, pass it on)
[ Post Reply | Private Reply | To 1 | View Replies]

To: trebb

Chrome is Google. Google is censorship. Don’t use Google. Delete all Chrome software from your computer. I did.


20 posted on 03/03/2017 4:59:11 AM PST by Gaffer
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-53 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson