4 ms·
There's a piece of animation software that I use in my game development called Spine, and it's truly fantastic and the developers and staff are great... but the
by DizzyDoo 4y ago
There's a piece of animation software that I use in my game development called Spine, and it's truly fantastic and the developers and staff are great... but the PHPBB forums don't have https enabled. I've brought it up on these same forums[0] but I don't think they get why https is an important thing to turn on, even in 2022.
Turning on https mode in my browser brings up, as it should, a large error message saying that the site is insecure. I can't imagine that's a terribly good first impression, even though, again, Spine is one of the best animation packages out there.
[0] - http://esotericsoftware.com/forum/HTTPS-for-EsotericSoftware-com-17472 http://esotericsoftware.com/forum/HTTPS-for-EsotericSoftware...
- cmeacham98 4y agoNot only do the forums have HTTPS disabled, but they expect you to download executables to run on your computer over HTTP. And, the kicker: they already have a legit HTTPS cert for the entire site: visiting on HTTPS redirects you to HTTP _facepalm_. Never heard of Spine before your comment, but if I found this in the wild I'd assume it was amateur hour and turn back immediately.
- DizzyDoo 4y agoA slight correction here, the download of the exe does take place over https. As does buying the software, and signing up to the forums. But everything else doesn't? The software itself is some of the smoothest and most stable I've ever used. And when there's an update within the software that, as far as I'm aware, takes place over https too. But the rest of the site and forums, even when signed in, is http, and I don't really know why.
- wlesieutre 4y agoThe download itself is over https, but the page where you click the download link is http. If someone were going to MITM the executable, they can just MITM the download page instead and point the download button to their own server with the bad executable.
- chrisweekly 4y agoExactly; this is why mixed content is problematic, and the r'aison d'etre for HTTPS Everywhere.
- my69thaccount 4y ago> Turning on https mode in my browser brings up, as it should, a large error message saying that the site is insecure. I can't imagine that's a terribly good first impression, even though, again, Spine is one of the best animation packages out there. A site being on HTTP isn't necessarily insecure. That warning is inaccurate. It's more about creating censors and gatekeepers in the form of certificate authorities. (Debian packages are still served over HTTP and are secure with no certificate authority. Try to figure that out!)
- aaronmdjones 4y agoDebian ships with its own signing keys to authenticate the packages that it downloads. They are acting as their own CA. This isn't scalable to the web.
- my69thaccount 4y agoWhether or not it's scalable is orthogonal to the question. A browser would call Debian's repos insecure despite the fact that they are secure by other means. vv: whether it's authenticated by TLS or PGP is literally isomorphic except one is centralized to CAs and one is decentralized with web of trust. That's the only difference.
- aaronmdjones 4y agoBecause they are. Your web browser has no way to validate the authenticity of any content served by a Debian mirror. This is very much done that way because anyone can run a Debian mirror (or indeed a mirror for almost any distribution, which all authenticate their packages in a similar manner). Nothing stops an admin running a repository mirror from choosing to make it serve malicious content, so the downloads need to be authenticated out of band. This is the very definition of insecure.
- stonemetal12 4y agoA web browser would be correct. It is insecure, because the browser could not secure it. Therefore it could be showing data that has been compromised. Just because it is secure when apt pulls the package doesn't magically make the web browser's view of the data secure. TLS and PGP maybe isomorphic, but the browser only has access to TLS. Therefore things secured by PGP are not secure in a browser, not because there is anything wrong with PGP but because the browser is incapable of checking it.