Plusnet Member Centre not secure!
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Feedback
- :
- Plusnet Feedback
- :
- Re: Plusnet Member Centre not secure!
Plusnet Member Centre not secure!
10-11-2015 5:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Plusnet Member Centre not secure!
10-11-2015 6:10 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine
Re: Plusnet Member Centre not secure!
10-11-2015 6:24 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote 18:15:50.662 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online.gif" on a secure page[Learn More] mTag.js:1:0
18:15:50.665 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online-9-9.gif" on a secure page[Learn More] mTag.js:1:0
18:15:50.667 Loading mixed (insecure) display content "http://www.plus.net/bundles/plusnetplusnetassets/images/liveperson/invites/mc-chat-online-busy.gif" on a secure page[Learn More] mTag.js:1:0
18:15:50.669 Loading mixed (insecure) display content "http://sales.liveperson.net/visitor/liveperson/chat-button/transparent.gif" on a secure page[Learn More]
i.e. images related to live chat
Re: Plusnet Member Centre not secure!
10-11-2015 7:34 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Plusnet Member Centre not secure!
10-11-2015 8:01 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Unlike the google analytics javascript that Firefox blocks if you browse these forums over https.
The padlock status colour does look worse for the mixed content allowed case though.
Re: Plusnet Member Centre not secure!
10-11-2015 8:33 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote What is mixed content?
HTTP is a system for transmitting information from a web server to your browser. HTTP is not secure, so when you visit a page served over HTTP, your connection is open for eavesdropping and man-in-the-middle attacks. Most websites are served over HTTP because they don't involve passing sensitive information back and forth and do not need to be secured.
When you visit a page fully transmitted over HTTPS (green padlock in the address bar), like your bank, your connection is authenticated and encrypted and hence safeguarded from eavesdroppers and man-in-the-middle attacks.
However, if the HTTPS page you visit includes HTTP content, the HTTP portion can be read or modified by attackers, even though the main page is served over HTTPS. When an HTTPS page has HTTP content, we call that content “mixed”. The page you are visiting is only partially encrypted and even though it appears to be secure, it isn't.
What are the risks of mixed content?
An attacker can replace the HTTP content on the page you're visiting in order to steal your credentials, take over your account, acquire sensitive data about you, or attempt to install malware on your computer.
jelv (a.k.a Spoon Whittler) Why I have left Plusnet (warning: long post!) Broadband: Andrews & Arnold Home::1 (FTTC 80/20) Line rental: Pulse 8 Home Line Rental (£14.40/month) Mobile: iD mobile (£4/month) |
Re: Plusnet Member Centre not secure!
10-11-2015 9:15 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
https://www.ssllabs.com/ssltest/analyze.html?d=portal.plus.net&s=212.159.8.2&hideResults=on
They still support RC4 (broken), are only using TLS 1.0, use common 1024 primes (logjam) and don’t support the modern cipher suites. If plusnet are running the latest apache and openssl then it’s a easy fix.
https://mozilla.github.io/server-side-tls/ssl-config-generator/
https://weakdh.org/sysadmin.html
Re: Plusnet Member Centre not secure!
12-11-2015 4:00 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Plusnet Member Centre not secure!
12-11-2015 8:58 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
So yes, if security of ISP systems is a major concern I'd say moving to TalkTalk would be a very smart move.
jelv (a.k.a Spoon Whittler) Why I have left Plusnet (warning: long post!) Broadband: Andrews & Arnold Home::1 (FTTC 80/20) Line rental: Pulse 8 Home Line Rental (£14.40/month) Mobile: iD mobile (£4/month) |
Re: Plusnet Member Centre not secure!
13-11-2015 10:50 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page