Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: June 26, 2025, 9:33 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security Updates
#1
Security Updates
As a computer security professional, I know that security on the internet is very important. This applies even more so today, with the disclosure of programs like PRISM and the UK's apparent wire-tapping of international fibre-optic cables.

For the last year, Atheist Forums has supported encrypted SSL connections. Whilst using this connection, all content that travels between your computer and the Atheist Forums server is encrypted and should be secret.

To use this connection, all you have to do is change the http:// at the start of the URL to https:// or simply click this link. I have written a script which should automatically detect whether you are using this connection, and alter all forum links accordingly (so you don't click on a forum link which takes you back to the regular connection). There are some limitations to this script, but I'm working them out.

That said, SSL is a nightmare to set up correctly. There are a number of configuration options that are subject to various security weaknesses, and a lot of sites will just use the insecure default settings, leaving their users with some level of security, but not a decent level of security. Since I understand SSL quite well, I've spent a number of hours configuring it so that we have an almost perfect score on Qualys SSL Labs (very good automated testing tool).

One thing that I have configured recently is Forward Secrecy. With our old SSL configuration, communication between a user and the server was secure, but if someone intercepted the encrypted data and managed to compromise the server, they could decrypt the data very easily. Of course, we don't expect someone to compromise the server, but with Forward Secrecy enabled, your encrypted communications will be protected even if at some point in the future, the server is compromised.

I have tested the connection in all major modern browsers and it seems to work fine, but please report any issues if you see them.

- Tiberius
Reply



Messages In This Thread
Security Updates - by Tiberius - July 10, 2013 at 6:24 pm
RE: Security Updates - by Rayaan - July 10, 2013 at 6:34 pm
RE: Security Updates - by Minimalist - July 10, 2013 at 7:06 pm
RE: Security Updates - by Tiberius - July 10, 2013 at 7:12 pm
RE: Security Updates - by Minimalist - July 10, 2013 at 11:42 pm
RE: Security Updates - by pocaracas - July 11, 2013 at 5:54 am
RE: Security Updates - by Jackalope - July 11, 2013 at 9:19 pm
RE: Security Updates - by Tiberius - July 11, 2013 at 7:02 am
RE: Security Updates - by Tiberius - July 13, 2013 at 7:52 pm
RE: Security Updates - by Jackalope - July 13, 2013 at 9:37 pm

Possibly Related Threads...
Thread Author Replies Views Last Post
  Two Rule Updates Tiberius 124 22243 October 29, 2016 at 5:49 pm
Last Post: Edwardo Piet
  Preaching Rule Changes & Punishment Updates Tiberius 15 8236 October 25, 2012 at 5:34 pm
Last Post: Creed of Heresy
  SSL Updates Tiberius 1 1770 August 15, 2012 at 12:04 pm
Last Post: Napoléon
  Donation Updates Tiberius 14 7618 March 30, 2012 at 6:00 pm
Last Post: Tiberius
  Domain Name Updates Tiberius 4 2422 March 6, 2012 at 4:44 pm
Last Post: Minimalist
  Important Updates Tiberius 28 32508 January 29, 2012 at 3:06 pm
Last Post: Tiberius
  Donation Updates Tiberius 5 5211 January 17, 2012 at 1:05 pm
Last Post: popeyespappy
  Forum Layout Updates & Debate Motions Tiberius 6 3654 November 22, 2010 at 2:07 am
Last Post: Ryft
  Server Updates Tiberius 0 1898 May 13, 2010 at 6:59 pm
Last Post: Tiberius



Users browsing this thread: 1 Guest(s)