FAS has upgraded our forum security. Some members may need to log in again. If you are unable to remember your login information, please email food.allergy.supt@flash.net and we will help you get back in. Thanks for your patience!

Author Topic: FAS "Not Secure" in browser  (Read 20807 times)

Description:

Offline nameless

  • Member
  • ***
  • Posts: 4,000
FAS "Not Secure" in browser
« on: January 01, 2019, 09:39:39 PM »
hi all admin-types --- I just noticed that in my browser bar FAS is showing as "Not Secure" which means it's no longer an https connection. When did that happen? In my browser it's bookmarked/saved as Https which it used to be, right?

I just want to put out a warning to folks to not use a password for their FAS account they use anywhere else, particularly if it's attached to the email address they use for FAS.

thoughts?
40+ years dealing with:
Allergies: peanut, most treenuts, shrimp
New England

Offline SilverLining

  • Member
  • Member
  • ***
  • Posts: 14,024
Re: FAS "Not Secure" in browser
« Reply #1 on: January 02, 2019, 07:00:06 AM »
I’m not seeing that, but I don’t have to sign in each visit. Would that be why?

I did suddenly start seeing that message on a different forum though.

Rebekah

  • Guest
Re: FAS "Not Secure" in browser
« Reply #2 on: January 02, 2019, 09:27:34 AM »
Looks like I need to install an update, but it’s not working right.

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #3 on: January 02, 2019, 09:30:16 AM »
Wow, that was weird - not sure if it was my computer or the site, but I logged out and then couldn't get logged in again.  My user name and password kept disappearing as soon as I hit the login button.
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #4 on: January 02, 2019, 12:25:56 PM »
After working with tech support on making sure the updates went through correctly, I asked again about securing the site.  I would need to pay for an SSL certificate each year - it must have stopped being included in my annual costs at the end of November when the contract renewed.  Adding it will double my cost.  :-/
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #5 on: January 02, 2019, 02:39:45 PM »
Okay, I've been working with our provider and we should be good to go with https now.  Some members may need to enter their password again.  If anyone has trouble remembering your password and no longer has access to the email address linked with your account, please get in touch with me and I can either update your email address in your profile and then you can use password recovery or I can just assign you a new temporary password to gain access and you can set a new one in your profile.
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline Stinky10

  • Member
  • ***
  • Posts: 259
Re: FAS "Not Secure" in browser
« Reply #6 on: January 02, 2019, 06:26:38 PM »
I'd be happy to contribute some $$$

also the site is really slow today
Spanking cats for 40 years!

Offline Stinky10

  • Member
  • ***
  • Posts: 259
Re: FAS "Not Secure" in browser
« Reply #7 on: January 02, 2019, 06:28:19 PM »
Spanking cats for 40 years!

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #8 on: January 02, 2019, 06:45:21 PM »
Stinky, thanks for offering to contribute.  :smooch:  We’re looking at how to work the logistics of that, now.  Once we have a plan in place, we’ll post about it.

I’m getting the https on everything I see and Firefox no longer shows the lock with the red line through it. Maybe if you log out and log back in?
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline nameless

  • Member
  • ***
  • Posts: 4,000
Re: FAS "Not Secure" in browser
« Reply #9 on: January 02, 2019, 07:30:08 PM »
Thanks! It shows as secure https to me now, which is good.

It still might warrant a warning to folks to change their password and if they used the same password elsewhere to change that as well. Not sure ya'lls background, and I don't want to come off as "mansplainy" (not sure what the female equivalent of that is?) It's not  my intention...OK -- so if a website isn't https and just http that means that if a user logs in then anyone on their wifi network (like it's a public one, Xfinity, Starbucks, etc.) or sniffing around cell tower traffic will be able to read that login information. It's not protected or encrypted very well. Then, if the email is sniffable, the bad-person will go around and try various websites (usually with a script or bot) trying to log in with that email address and password combo.

Not sure what the risk is for OLICentral sites and if they use a different layer/protocol that would help protect, but I'm guessing it doesn't.

I think setting up a Go Fund Me or something to get the funds needed, folks would do it :)
40+ years dealing with:
Allergies: peanut, most treenuts, shrimp
New England

Offline Macabre

  • Global Moderator
  • Member
  • ****
  • Posts: 29,976
  • Don't Blink!
Re: FAS "Not Secure" in browser
« Reply #10 on: January 02, 2019, 08:43:48 PM »
Thanks, nameless. I didn’t realize the url wasn’t SSL, since I only use my phone to come here. I’m glad you noticed. I should have.
Me: Sesame, shellfish, chamomile, sage
DS: Peanuts

Offline Stinky10

  • Member
  • ***
  • Posts: 259
Re: FAS "Not Secure" in browser
« Reply #11 on: January 03, 2019, 02:16:14 PM »
I logged in and out and still see Not Secure at the top - but only in the forums - not on the index

also the site is slow - feels like there is a redirect going on
Spanking cats for 40 years!

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #12 on: January 03, 2019, 02:30:17 PM »
We have two domain names that redirect to our actual site.  foodallergysupport.com and .org both redirect to foodallergysupport.olicentral.com  I haven't noticed any unusual slowness and all my pages show https.  Not sure what could be going on with yours, perhaps Nameless (who is not womansplaining because she actually has much more knowledge than I do ;) ) would have some ideas?
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline Stinky10

  • Member
  • ***
  • Posts: 259
Re: FAS "Not Secure" in browser
« Reply #13 on: January 03, 2019, 02:43:25 PM »
I'll reboot later and try different browsers
but every click on this site - has a pause - pause - then go
just started
and still says not secure - in lots of pages - I see it now. 

anyway my password is BringonSummer2019!**12# 

hahahahaaa….kidding...
Spanking cats for 40 years!

Offline rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,429
Re: FAS "Not Secure" in browser
« Reply #14 on: January 03, 2019, 02:48:24 PM »
Okay, I read up on it a bit.  It seems our site is transmitted in https, but some of our content may still be in http.  Just on a cursory check, it appears the image for our banner at the top is in http, but so far everything else I see is https.  The banner is hosted at photobucket and I'm scared to mess with it right now since photobucket now wants to be paid for what used to be free.  Once I can find a way to either get a new banner or transfer what we have to another image hosting site, I'll see if that fixes the mixed http/https issue.
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.