Turn on HTTPS/SSL by default?

Bryan
Bryan
Joined: 27 Apr 05
Posts: 3
Credit: 11,249,289
RAC: 379
Topic 197757

I'd like to see HTTPS for the website and for the project scheduler/downloading [1].

Seems like a really imporant thing to do security wise. Could someone hijack the schduler and have E@H users do arbitary work?

I'm happy to help with the infrastructure side (I work in Linux tech support), if there is anything I can do..

Thanks!
Bryan

[1] https://boinc.berkeley.edu/trac/wiki/SecureHttp
[2] https://www.ssllabs.com/ssltest/analyze.html?d=einstein.phys.uwm.edu

Logforme
Logforme
Joined: 13 Aug 10
Posts: 332
Credit: 1,714,373,961
RAC: 5,891

Turn on HTTPS/SSL by default?

Quote:
I'd like to see HTTPS for the website and for the project scheduler/downloading


I like this suggestion. All sites should default to encryption. Especially if the site handles user information.

Quote:
Could someone hijack the schduler and have E@H users do arbitary work?


Or make users download binaries infected with trojans?

https://www.eff.org/https-everywhere/deploying-https

Logforme
Logforme
Joined: 13 Aug 10
Posts: 332
Credit: 1,714,373,961
RAC: 5,891

Just noticed the site is now

Just noticed the site is now HTTPS, very nice!
One thing I noticed was that I got a warning when pressing the login button saying that the page is encrypted but the information sent to the server is not.

Anyway, great work guys. Definitely a big step forward. Thank you.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.