• Hello Guest, welcome to the initial stages of our new platform!
    You can find some additional information about where we are in the process of migrating the board and setting up our new software here

    Thank you for being a part of our community!

Forum is NOT secure

:uh: we're not high on the traffic ratio. If someone wants to hijack pictures of 7/9 cars and hold them for ransom, they have other issues. Most all of us use our phones more here anyways, and understands the NSA watches this site because of the communist views everyone holds.

Most webhosts now are offering https free as standard (All my business's clients automatically have https SSL)

Further more HTTP/2 won't work without https, which we also now provide as a standard.

Chrome will be red address bar'ing (they are still debating, I believe Chromium does it by default) non-https sites sometime late 2017.

The site also has missing images, the cookie settings are incorrect (Which I've tried to inform admins about hell maybe 5 years ago)
 
I'm always open to assistance and advice. I don't have an ego about running this place... I'm ALWAYS begging for people to lend a hand. There are however many factors involved with doing things the way we do. Sometimes people dont realize that.

Getting a basic $50 cert for tbforums.com and then 301 redirecting everyone to that domain from the others would work but then your browser wouldn't be turbobricks.com... or anything else for that matter if we wanted to treat those separately. And maybe thats what we go with when the site and forums are redesigned this summer. Otherwise, if we wanted to leave it 302 and just grab a $150 wildcard cert for *.turbobricks.com we could do that too. Ideally i'd want turbobricks.com control, 301 redirecting everyone to that domain... and use vb4 to manage the site and board and anything else through the cms so that way its only a $50 cert.



But ya know... its just a 'silly' 'unprofessional' car forum.

You do not need to buy SSL.

Feel free to PM me and I can help. I've ran the backend of forums, hosted large websites or was their IT for around 11 years now.

Edit: and that is I'll donate my services/free time as I've had great help/reads on this site since 2010.
 
Last edited:
You do not need to buy SSL.

Feel free to PM me and I can help. I've ran the backend of forums, hosted large websites or was their IT for around 11 years now.

Edit: and that is I'll donate my services/free time as I've had great help/reads on this site since 2010.

Thanks cmanns, let me know if he takes you up on the offer. It's my intention to do a donation of my own Friday...
 
well thats a game changer. :cheers:

edit: ...if i can get certbot installed on the server. Not sure if the host will allow it.

Going to check with my company and see if we can't get this hosted for free. If that's the case, I'd be your admin and we could hook you up with raw access to whatever you need to facilitate the website best. We manage our websites using AWS (Amazon Web Services). You'd never have to pay for hosting, space, or certificates ever again.
 
Last edited:
Going to check with my company and see if we can't get this hosted for free. If that's the case, I'd be your admin and we could hook you up with raw access to whatever you need to facilitate the website best. We manage our websites using AWS (Amazon Web Services). You'd never have to pay for hosting, space, or certificates ever again.

Yeah and get hands on TB and jack it.
I prefer no one else but the current owner have an access to the board/database.
 
I thought we were discussing the annoying complicated task of moving to https... now you want me to move hosts and hand you the keys? :roll:
 
Going to check with my company and see if we can't get this hosted for free. If that's the case, I'd be your admin and we could hook you up with raw access to whatever you need to facilitate the website best. We manage our websites using AWS (Amazon Web Services). You'd never have to pay for hosting, space, or certificates ever again.

:run::run::run::run::run::skullbones::skullbones:
 
It's like:

"I know you don't know me at all but will you hand me over the keys to your house and I'll change the locks so you can't get in anymore while I reconfigure everything inside"

If you think that the site is unsecured then what you're asking the site administrator to do is FAR more dangerous for the security of all TB's users...
 
It's like:

"I know you don't know me at all but will you hand me over the keys to your house and I'll change the locks so you can't get in anymore while I reconfigure everything inside"

If you think that the site is unsecured then what you're asking the site administrator to do is FAR more dangerous for the security of all TB's users...

From wikipedia:
Stages of the con[edit]


Foundation Work
Preparations are made in advance of the game, including the hiring of any assistants required.
Approach
The victim is contacted.
Build-up
The victim is given an opportunity to profit from a scheme. The victim's greed is encouraged, such that their rational judgment of the situation might be impaired.
Pay-off or Convincer
The victim receives a small payout as a demonstration of the scheme's effectiveness. This may be a real amount of money, or faked in some way. In a gambling con, the victim is allowed to win several small bets. In a stock market con, the victim is given fake dividends.
The Hurrah
A sudden crisis or change of events forces the victim to act immediately. This is the point at which the con succeeds or fails.
The In-and-In
A conspirator (in on the con, but assumes the role of an interested bystander) puts an amount of money into the same scheme as the victim, to add an appearance of legitimacy to the scheme. This can reassure the victim, and give the con man greater control when the deal has been completed.
In addition, some games require a "corroboration" step, particularly those involving a "rare item". This usually includes the use of an accomplice who plays the part of an uninvolved (initially skeptical) third party, who later confirms the claims made by the con man.[6]


:-P
 
I mean whatever. The fact is that I DO need to update the security and get these domain redirect issues addressed... they've been on my list for a while now so this was just a good kick to get working on it.
I'll probably just forward everything to tbforums.com and then issue a cert for that domain and call it a day.
 
I don't understand why everyone is jumping overboard, just trying to do something nice.

You already spoke about concern with cost. Also, it's been mentioned that the task at hand is annoying. I have no need to steal the forum. These responses have been really strange from the beginning. I can only guess that they come from a place of ignorance as to how some of the technologies work in their entirety.

The point of the post was to open a dialog about properly securing the site, for all users. That has been completed and a verdict seems to have been reached. The offer to help you otherwise is coming from a place of kindness and friendship. If you have other issues that you'd like to talk about feel free to pm me for my personal information and we can hash it out.

I'm a professional and have delivered no negativity in this thread. However, I can understand everyones position here and your voices have been heard, so I will let it rest.
 
Last edited:
I don't understand why everyone is jumping overboard, just trying to do something nice.

You already spoke about concern with cost. Also, it's been mentioned that the task at hand is annoying. I have no need to steal the forum... I mean, really? These responses have been really strange from the beginning. I can only guess that they come from a place of ignorance as to how this kind of stuff works. I'd be an admin only in the sense that I'd be hosting your website and associated database(s), no different than any other host.

The point of the post was to open a dialog about properly securing the site, for all users. That has been completed and a verdict seems to have been reached. The offer to help you otherwise is coming from a place of kindness and friendship. If you have other issues that you'd like to talk about feel free to pm me for my personal information and you can talk to me man to man.

I mean.. . You've been on this forum for a little more than a year and a half, you have like 30 posts total and you are surprised that some of us are not comfortable with your "offer"?
 
Back
Top