There is a topic in the Dismissed Reports regarding this issue, since it was mostly resolved a few months ago, but I've found at least a few pages still have a "Connection Not Secure" warning in the address bar (at least for me, using the most updated version of Firefox). This issue was previously linked to an old image on site (I believe it was something to do with the Hustler?) that has since been removed, so I'm not sure if this is the same issue as before that wasn't caught on every page, or if there's a new security issue.
The biggest issue is the new wardrobe - I reported that it is 'not secure' on the main wardrobe bugs thread a couple of months ago but it hasn't been addressed yet. I also noticed that the Forum Groups pages also have this warning. I'll edit this post if I stumble on more pages.
Thank you so much for your report! Could you please list the specific URLs that are having this issue?
🐝 ☕ bug (he/him) | your friendly neighborhood code wrangler. stay in the loop! join and check out the latest admin post highlights
No problem! These are the pages I've noticed so far:
https://subeta.net/forums.php/groups/#/home
https://subeta.net/forums.php/groups/#/your
https://subeta.net/forums.php/groups/#/new
https://new.subeta.net/wardrobe
Thank you! :)
These should all be fixed now!
🐝 ☕ bug (he/him) | your friendly neighborhood code wrangler. stay in the loop! join and check out the latest admin post highlights
I haven't found any more insecure pages, so this looks pretty resolved to me. :) Thank you!
I ran an SSL compliance scan found the server, for whatever reason, is not providing HSTS.
Okay, I'll let know, thanks! It looks like it should be pretty simple to enable that on Cloudflare. Will keep you updated.
🐝 ☕ bug (he/him) | your friendly neighborhood code wrangler. stay in the loop! join and check out the latest admin post highlights
Does it matter if a forum page shows not secure? It starts from page 221 to 225
https://subeta.net/forums.php/read/911180/Ping-the-Person-Above-You-V20/225
That notice is triggered by external images in forum posts, which don't exist on Subeta and thus we don't have control over them. So like, you can use the img sCode to put any image you want in a forum post, even if that image is on an unsecure image host. This goes for everywhere that we allow you to put images of your choosing - like the forum image, forum signatures, pet profiles and user profiles.
The reason we secure things with HTTPS is that an attacker could read and potentially even modify anything that isn't HTTPS. This is why things like credit card info and passwords must be transmitted over HTTPS. If your image contains sensitive info like a scan of your driver's license, you should make sure that image is secure. But the images people post on Subeta forums should not contain sensitive personal information (I hope everyone uses common sense with what they post here), plus these forums are somewhat public to begin with since anyone can make a Subeta account and read them.
So, these images don't pose a high risk, but if you'd like to block them anyway, there should be a "Block unsecured images" setting in your browser. I definitely encourage blocking them if they at all make you uncomfortable. I block various content on websites myself for my own peace of mind. Anyway I hope all this helps with any potential concerns :)
Just want to let you know the HSTS thing has not been forgotten.
🐝 ☕ bug (he/him) | your friendly neighborhood code wrangler. stay in the loop! join and check out the latest admin post highlights
I'm using HTTPS Everywhere to force it on all my browsers, but I thought maybe the server not enforcing it may be why the issue keeps cropping back up.
If you're talking about the notice that our server doesn't use HSTS, you're seeing that because it's true, we don't use it at the moment. If you are enforcing HTTPS through your HTTPS Everywhere then us not using HSTS does not pose any risk to you as long as you have the "Block all unencrypted requests" setting turned on.
🐝 ☕ bug (he/him) | your friendly neighborhood code wrangler. stay in the loop! join and check out the latest admin post highlights