Food Allergy Support is now on Twitter. Follow us @FASupport. You may also follow our Tweets in our new global footer at the bottom of the page here at FAS!

FAS has upgraded our forum security. Some members may need to log in again. If you are unable to remember your login information, please email food.allergy.supt@flash.net and we will help you get back in. Thanks for your patience!

Author Topic: FAS "Not Secure" in browser  (Read 331 times)

Description:

Offline Macabre

  • Global Moderator
  • Member
  • ****
  • Posts: 29,856
  • Don't Blink!
Re: FAS "Not Secure" in browser
« Reply #30 on: January 06, 2019, 10:15:25 AM »
So RC do you think the security warning could go away once we’ve replaced the banner (which will happen very soon—we have a new banner). Or do you think all the profile pics will be a problem if they’re at Photobucket?
Me: Sesame, shellfish, chamomile, sage
DS: Peanuts

Online rebekahc

  • Global Moderator
  • Member
  • ****
  • Posts: 3,250
Re: FAS "Not Secure" in browser
« Reply #31 on: January 06, 2019, 12:10:10 PM »
I think images from photobucket (and maybe other places) could cause issues - any image hosted as http will. However, the warning shouldn’t be for every page once the banner is fixed and that’s the easist for me to fix without having members re-do avatars and searching through years of posts for any vulnerable images.  The likelihood of a hacker trying to use an image vulnerability is pretty low so by fixing the easily found banner I think it will be fine. Some of the avatars are stored on site, so those won’t be an issue. I could load the others to our site and prevent new users from uploading their own, but I don’t think there would be a way to prevent someone else from using your avatar if I upload it to the site. I can also look at the settings for members posting pictures and see if I can restrict future images to https.
TX - USA
DS - peanut, tree nut, milk, eggs, corn, soy, several meds, many environmentals. Finally back on Xolair!
DD - mystery anaphylaxis, shellfish.
DH - banana/avocado, aspirin.  Asthma.
Me - peanut, tree nut, shellfish, banana/avocado/latex,  some meds.

Offline Macabre

  • Global Moderator
  • Member
  • ****
  • Posts: 29,856
  • Don't Blink!
Re: FAS "Not Secure" in browser
« Reply #32 on: January 06, 2019, 02:21:46 PM »
I think the last thing is the only thing that really makes sense from a time investment perspective.
Me: Sesame, shellfish, chamomile, sage
DS: Peanuts

Offline nameless

  • Member
  • ***
  • Posts: 3,990
Re: FAS "Not Secure" in browser
« Reply #33 on: January 06, 2019, 02:51:32 PM »
...re: images

On the site/forum settings that admins can see, there might be a check box for only allowing https embedding. It's a pretty typical setting, but not sure if you have it on your dashboard.

If not - I also agree that it's not worth the time to cull avatar images and such vs the actual risk of bad behavior by someone intending to do something bad.
40+ years dealing with:
Allergies: peanut, most treenuts, shrimp
New England

Offline Stinky10

  • Member
  • ***
  • Posts: 254
Re: FAS "Not Secure" in browser
« Reply #34 on: January 07, 2019, 01:51:25 PM »
I'm not seeing the not secure warning anymore and seems to be running a bit faster

Offline PurpleCat

  • Member
  • ***
  • Posts: 2,520
Re: FAS "Not Secure" in browser
« Reply #35 on: January 07, 2019, 05:01:50 PM »
Still have it here.

Love the new banner but why does it go back to the old one when I log in?

Offline Macabre

  • Global Moderator
  • Member
  • ****
  • Posts: 29,856
  • Don't Blink!
Re: FAS "Not Secure" in browser
« Reply #36 on: January 07, 2019, 05:23:10 PM »
Try clearing your cache.
Me: Sesame, shellfish, chamomile, sage
DS: Peanuts