HTTPS for 6502.org?
Re: HTTPS for 6502.org?
Thanks Alex - already mentioned upthread.
BigEd wrote:
(I know Mike is aware of a need, eventually, to go to HTTPS, and is aware of LetsEncrypt and similar, but it's evidently not a priority. I've offered to help, too. It feels best not to keep bugging him about it!)
Re: HTTPS for 6502.org?
Here's a funny story about HTTPS.
I was at a hotel in Washington yesterday and tried to use their WiFi. I could connect, but when I went to Google I got an error that the browser wouldn't let me proceed due to a broken SSL connection and Googles HSTS policy. I was completely baffled as previously I would just hit the proceed link at the bottom and the captive portal would authenticate.
So what do you do when you have a baffling error and can't Google it? I popped out my phone and used the wireless network to Google it, and went down the HTTP Strict Transport Security (HSTS) headers and captive portal authentication gotcha rabbit hole.
The bottom line is that the only workaround is to go to a HTTP site first, allow the captive portal to authenticate, then go to HTTPS sites afterwards. But what sites are using HTTP now? I tried all manner of sites and kept getting hit with the bug.
Then a solution hit me, a site that is steadfastly using HTTP! I went to this forum and the problem was solved. But quite honestly this is a huge flaw that Google is ignoring and they need to work with the captive portal venders to fix it.
I was at a hotel in Washington yesterday and tried to use their WiFi. I could connect, but when I went to Google I got an error that the browser wouldn't let me proceed due to a broken SSL connection and Googles HSTS policy. I was completely baffled as previously I would just hit the proceed link at the bottom and the captive portal would authenticate.
So what do you do when you have a baffling error and can't Google it? I popped out my phone and used the wireless network to Google it, and went down the HTTP Strict Transport Security (HSTS) headers and captive portal authentication gotcha rabbit hole.
The bottom line is that the only workaround is to go to a HTTP site first, allow the captive portal to authenticate, then go to HTTPS sites afterwards. But what sites are using HTTP now? I tried all manner of sites and kept getting hit with the bug.
Then a solution hit me, a site that is steadfastly using HTTP! I went to this forum and the problem was solved. But quite honestly this is a huge flaw that Google is ignoring and they need to work with the captive portal venders to fix it.
Re: HTTPS for 6502.org?
Martin_H wrote:
The bottom line is that the only workaround is to go to a HTTP site first, allow the captive portal to authenticate, then go to HTTPS sites afterwards. But what sites are using HTTP now?
As for the security stuff; it's easy to fabricate excuses for why bad actors shouldn't be interested in attacking your system. But that's generally a good way to have a security issue in the future, because the attackers are far more motivated than you are to find some way to make use of your system for nefarious purposes.
Curt J. Sampson - github.com/0cjs
Re: HTTPS for 6502.org?
cjs wrote:
example.com. And it always will be, because that's the IETF standard test site for HTTP.
As for the captive portal issue. I have noticed a number of hotels getting rid of the authentication screen, and I wondered why. My guess is explaining this issue to random guests isn't possible. Telling them to type in example.com first is a lost cause.
- Mike Naberezny
- Site Admin
- Posts: 293
- Joined: 30 Aug 2002
- Location: Northern California
- Contact:
Re: HTTPS for 6502.org?
Martin_H wrote:
Then a solution hit me, a site that is steadfastly using HTTP! I went to this forum and the problem was solved.
- Mike Naberezny (mike@naberezny.com) http://6502.org
Re: HTTPS for 6502.org?
Mike Naberezny wrote:
There's nothing steadfast about it, there's an active effort to migrate, which has already been talked about on the forum.
- Alarm Siren
- Posts: 363
- Joined: 25 Oct 2016
Re: HTTPS for 6502.org?
Yeah, I can confirm that it is in-progress. Mike actually showed me the new HTTPS enabled version of the site, as-was at the time. Though the link appears to be dead now 
Want to design a PCB for your project? I strongly recommend KiCad. Its free, its multiplatform, and its easy to learn!
Also, I maintain KiCad libraries of Retro Computing and Arduino components you might find useful.
Also, I maintain KiCad libraries of Retro Computing and Arduino components you might find useful.
Re: HTTPS for 6502.org?
Let me necropost this.
I was sitting in Edinburgh in a cafe and no Internet except unencrypted WIFI...
Even though I was using a VPN home ...
This site should indeed have TLS
André
I was sitting in Edinburgh in a cafe and no Internet except unencrypted WIFI...
Even though I was using a VPN home ...
This site should indeed have TLS
André
Author of the GeckOS multitasking operating system, the usb65 stack, designer of the Micro-PET and many more 6502 content: http://6502.org/users/andre/
Re: HTTPS for 6502.org?
But then how will I browse it from my early 2000's iMac? 
Re: HTTPS for 6502.org?
Agumander wrote:
But then how will I browse it from my early 2000's iMac? 
Author of the GeckOS multitasking operating system, the usb65 stack, designer of the Micro-PET and many more 6502 content: http://6502.org/users/andre/
-
6502inside
- Posts: 101
- Joined: 03 Jan 2007
- Location: Sunny So Cal
- Contact:
Re: HTTPS for 6502.org?
Agumander wrote:
But then how will I browse it from my early 2000's iMac? 
Well, you asked.
Machine room: http://www.floodgap.com/etc/machines.html
Re: HTTPS for 6502.org?
6502inside wrote:
Agumander wrote:
But then how will I browse it from my early 2000's iMac? 
Well, you asked.
-
6502inside
- Posts: 101
- Joined: 03 Jan 2007
- Location: Sunny So Cal
- Contact:
Re: HTTPS for 6502.org?
Yes, Crypto Ancienne can be run as an HTTP-to-HTTPS proxy, or browsers that can be tricked/altered to offloading the cryptography to it can "upgrade" their SSL support through it.
Machine room: http://www.floodgap.com/etc/machines.html
- GARTHWILSON
- Forum Moderator
- Posts: 8773
- Joined: 30 Aug 2002
- Location: Southern California
- Contact:
Re: HTTPS for 6502.org?
I'm using the firefox browser, and one of the bazillion settings options is to allow only https: sites. I keep it off. Maybe your browser is set to not allow http: sites, and maybe you can change that setting.
http://WilsonMinesCo.com/ lots of 6502 resources
The "second front page" is http://wilsonminesco.com/links.html .
What's an additional VIA among friends, anyhow?
The "second front page" is http://wilsonminesco.com/links.html .
What's an additional VIA among friends, anyhow?
Re: HTTPS for 6502.org?
I keep the setting on; whenever I come here it offers me the option, after warning about it, to connect to the http site.
Neil
Neil