Mozilla is telling me this network connection is insecure and that I am taking a chance of vulnerability by being logged on here ?? :aargh:
Printable View
Mozilla is telling me this network connection is insecure and that I am taking a chance of vulnerability by being logged on here ?? :aargh:
I am logged in on Mozilla, and just opened Chrome and came to SRP through a google search. No warning on Chrome browser. For whatever that is worth.
I don't know Jim...but here is the link that shows up when I log on .... https://support.mozilla.org/t5/Prote...fox/ta-p/27861
I routinely log into straightrazorplace.com using either Mozilla Firefox or Google Chrome and do not see any warning.
However, the SRP forum uses the HTTP protocol vs the encrypted HTTPS protocol. Thus, it might be possible for someone to intercept your user name and password. Sensitive personal information other than your password is not normally sent over the site. You should not be using the same username and password on this website that you are using on any other web site where you might be exchanging sensitive personal or financial information.
It's just a warning that you are running the risk of buying excessive razors, soaps, brushes etc. Nothing to be alarmed about...
Sent from a moto x far far away...
It's a new feature in the most recent edition of firefox and, as far as I can tell, there is no option to manually disable. It's annoying for sure.
It's probably not worth doing (i.e. it's good to know if you are going to submit data that is not encrypted), but I believe there is a 'hidden' option to turn off this warning in firefox. It will turn off the warning for every site. It requires going to about:config and changing the security.insecure_field_warning.contextual.enabled option.
FWIW, SRP probably should support SSL anyway. The overhead is relatively low and free certificates can be had using letsencrypt.
AFAIK there is no situation where $ change hands directly though SRP, where you'd have to enter any sensitive info. Using a password that is not critical would probably be a good idea though.
You don't send the password, just the account name.
I don't see any harm coming from that
For Firefox users who ARE COMFORTABLE with tweaking it, you can turn this new security feature off.
https://www.howto-connect.com/this-c...ecure-firefox/
You are on your own of course. I have done it here on my own computer, but honestly.... the few holdout sites that still do not use SSL should really get on the ball, and that includes sites like SRP. There really is no reason not to with the "Lets Encrypt" project.
I recently started using Firefox and do not get any warnings.
The link to here is the old http and not the "new" htpps. Thus giving this warning. I don't think there is any worry about coming here though... :shrug:
Thanks to those that helped,unsubscribing now. Peace.
It warns me inside my own internal private network in my place, they must want everyone to use HTTPS