• Hello Guest, welcome to the initial stages of our new platform!
    You can find some additional information about where we are in the process of migrating the board and setting up our new software here

    Thank you for being a part of our community!

Forum is NOT secure

iVHfwLc.gif

tumblr_inline_o0nik868KM1shaw23_500.gif
 
I just think you have a jaded expectation of privacy for a silly little car forum like this.

It's not necessarily about privacy so much as it is about security.

An example would be that the website could be potentially used as a platform to deliver malicious content to end users. That content could then be used to capture their data, even important data not used on this site, such as credit card information. That is possible because the website was used as a vector to deliver the malicious content on to their computer. Not everyone is educated to the point where they would be informed as to what to look for and therefore have almost no idea it was occurring to them.

That's important, and I've seen insecure forums, even small ones, targeted to such a degree where the example scenario was a real problem.

The degree in which this site in particular operates is up for debate, but the responsible and mature thing to do would be to implement a solution so that the example scenario, and other scenarios like it, may not have a chance to occur.

However, if the administrators (Garrett Kirkland, in particular) deem it completely unnecessary for their reason of choice, the post can simply be deleted.
 
Last edited:
You gonna help pay for one?
I've been raffling off my own personal crap and paying the rest from my bank account for the last 8 months.
 
You gonna help pay for one?
I've been raffling off my own personal crap and paying the rest from my bank account for the last 8 months.

Well your shameless guilt trip worked on me yet again! However, I can't find your PayPal email nor can I find a donate link anywhere on the site. Pm me your PayPal please. We should stop blaming the cheap ass grandpa series owners and get an easy to see but unassuming donate button at the top and bottom of every page.
 
^ you're a contributor already though... multiple times over if i remember correctly.
http://www.turbobricks.com/donate.php for all you grey users.

The other issue is that we redirect turbobricks.com to tbforums.com because i don't own the domain. I've been trying to get it from Garrett for the better part of a decade but it hasnt happened. We would either need a very expensive SAN cert, or buy multiple certs because we actually redirect 6 domains here. Then you have other issues with forums using ssl... like getting pop-up warnings for things like off-site images in the posts.
 
^ you're a contributor already though... multiple times over if i remember correctly.
http://www.turbobricks.com/donate.php for all you grey users.

The other issue is that we redirect turbobricks.com to tbforums.com because i don't own the domain. I've been trying to get it from Garrett for the better part of a decade but it hasnt happened. We would either need a very expensive SAN cert, or buy multiple certs because we actually redirect 6 domains here. Then you have other issues with forums using ssl... like getting pop-up warnings for things like off-site images in the posts.

I'm willing to work with you to meet the goal.

Sounds like you can get away with a single cert for tbforums.com. If you can do a 301 redirect to that domain for all the other domains then you'll be good with just the one. Getting all the images and such properly behind https is a trivial matter.

You don't necessarily need to run subdomains (negating the need for a wildcard cert). We could just run the main site from the root and then the forum out of a subdirectory. If you can get away with that (common) setup then one cert will work, and I will pay for it early as this week.

You may understand all that already, just pointing it out. Depending on your ambition we could do a lot of web upgrades. There is opportunity to grow the site from a "silly car forum" as stated previously by another user, to something more professional. And yes, I realize there are other Volvo forums but I like this one because it's specific (outside of Russian women).

Those are my thoughts and I don't expect people to see things like I do. However, this is my job in real life so that's the way I work!
 
I'm always open to assistance and advice. I don't have an ego about running this place... I'm ALWAYS begging for people to lend a hand. There are however many factors involved with doing things the way we do. Sometimes people dont realize that.

Getting a basic $50 cert for tbforums.com and then 301 redirecting everyone to that domain from the others would work but then your browser wouldn't be turbobricks.com... or anything else for that matter if we wanted to treat those separately. And maybe thats what we go with when the site and forums are redesigned this summer. Otherwise, if we wanted to leave it 302 and just grab a $150 wildcard cert for *.turbobricks.com we could do that too. Ideally i'd want turbobricks.com control, 301 redirecting everyone to that domain... and use vb4 to manage the site and board and anything else through the cms so that way its only a $50 cert.



But ya know... its just a 'silly' 'unprofessional' car forum.
 
^ you're a contributor already though... multiple times over if i remember correctly.
http://www.turbobricks.com/donate.php for all you grey users.

The other issue is that we redirect turbobricks.com to tbforums.com because i don't own the domain. I've been trying to get it from Garrett for the better part of a decade but it hasnt happened. We would either need a very expensive SAN cert, or buy multiple certs because we actually redirect 6 domains here. Then you have other issues with forums using ssl... like getting pop-up warnings for things like off-site images in the posts.

I got money, just make Jack love me and we are good here.
 
I think I have a running 740 in contributions to this forum and its members, the last thing I am worried about is my security being breached here.

TB rules :zeeall:
 
Back
Top