[ IMAGES: Images ON turn off | ACCOUNT: User Status is LOCKED why? ]

Dear Mods: site security issue
Author Thread
Panos
Posts: 29294
Alba Posts: 3
Joined: 1/6/2004
Member: #520
12/14/2022  9:49 AM
Dear Andrew and Martin, for the past few months my anti-virus has been complaining about your site certificate. Are you aware of this issue?

Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for www.ultimateknicks.com. The certificate is only valid for the following names: *.adakie.com, adakie.com

Error code: SSL_ERROR_BAD_CERT_DOMAIN
AUTOADVERT
martin
Posts: 68745
Alba Posts: 108
Joined: 7/24/2001
Member: #2
USA
12/14/2022  10:03 AM
Panos wrote:Dear Andrew and Martin, for the past few months my anti-virus has been complaining about your site certificate. Are you aware of this issue?

Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for www.ultimateknicks.com. The certificate is only valid for the following names: *.adakie.com, adakie.com

Error code: SSL_ERROR_BAD_CERT_DOMAIN

Yes, thanks. I am working on a different solution.

Official sponsor of the PURE KNICKS LOVE Program
Panos
Posts: 29294
Alba Posts: 3
Joined: 1/6/2004
Member: #520
12/14/2022  10:08 AM
Ok! Just checking! Feel free to delete thread!
SupremeCommander
Posts: 33788
Alba Posts: 35
Joined: 4/28/2006
Member: #1127

12/15/2022  10:04 AM    LAST EDITED: 12/15/2022  10:06 AM
They don't have an SSL certificate installed, meaning they don't have a third party vouching for them. They don't have the internet version of a driver's license. More and more stuff cares about that now.

It is somewhat silly to expect an SSL cert here though. There are no credit card details and no place for me to upload my Gallo pics. I think http://www.ultimateknicks.com is okay though.

I will say the one place it matters is with passwords. Your password is not encrypted at ultimateknicks.com. So, if you are reusing username, password info on different sites, like your email or at a bank, that could be a big problem for you. if it is not https://www.ultimateknicks.com, I can intercept the traffic and read it. If it is https://, I effectively get carded before I can actually read what's being sent through the interwebs

martin, andrew, please just install the SSL cert, redirect port 80 to 443, and then this all just goes away. Let's Encrypt offers FREE SSL certs, and there's an agent that automatically renew it for you so you do it once and never do it again... here's an example guide:
https://www.nginx.com/blog/using-free-ssltls-certificates-from-lets-encrypt-with-nginx/

please guys, I do think this puts people that don't know any better at risk

Sambakick wrote: Gives a whole new meaning to "Jazz Hands"
martin
Posts: 68745
Alba Posts: 108
Joined: 7/24/2001
Member: #2
USA
12/15/2022  11:17 AM    LAST EDITED: 12/15/2022  11:18 AM
SupremeCommander wrote:They don't have an SSL certificate installed, meaning they don't have a third party vouching for them. They don't have the internet version of a driver's license. More and more stuff cares about that now.

It is somewhat silly to expect an SSL cert here though. There are no credit card details and no place for me to upload my Gallo pics. I think http://www.ultimateknicks.com is okay though.

I will say the one place it matters is with passwords. Your password is not encrypted at ultimateknicks.com. So, if you are reusing username, password info on different sites, like your email or at a bank, that could be a big problem for you. if it is not https://www.ultimateknicks.com, I can intercept the traffic and read it. If it is https://, I effectively get carded before I can actually read what's being sent through the interwebs

martin, andrew, please just install the SSL cert, redirect port 80 to 443, and then this all just goes away. Let's Encrypt offers FREE SSL certs, and there's an agent that automatically renew it for you so you do it once and never do it again... here's an example guide:
https://www.nginx.com/blog/using-free-ssltls-certificates-from-lets-encrypt-with-nginx/

please guys, I do think this puts people that don't know any better at risk

100% and thank you for all of this, really good explanation.

Andrew and I have been caught up in life but I'm on it, been on my high level To-Do list for waaaaayyyy to long.

Official sponsor of the PURE KNICKS LOVE Program
ekstarks94
Posts: 21011
Alba Posts: 0
Joined: 7/5/2015
Member: #6104

5/10/2023  6:06 PM
Also my security software tied to my mesh network when I use my ipad will not even let me log on. It is saying something about sharing unencrypted data from my ipad.
Dear Mods: site security issue

©2001-2012 ultimateknicks.comm All rights reserved. About Us.
This site is not affiliated with the NY Knicks or the National Basketball Association in any way.
You may visit the official NY Knicks web site by clicking here.

All times (GMT-05:00) Eastern Time.

Terms of Use and Privacy Policy