Skip to first unread message

Pietro Speroni di Fenizio

unread,
Oct 6, 2013, 1:17:25 PM10/6/13
to vilfredo-deve...@googlegroups.com
Deal all,
we have been asked to make another step toward security. Right now if a person wanted to use https, they could. But nothing really imposed, requested, or pushed you toward it. There was a request to change this, and make sure that each link inside Vilfredo would use it. So if page A would link to page B, it should link to https://B and not just B. Independently if the original page was http://A or https://A.

On the one side I can see why this is important. If you are making a question on an important topic, and you do not want anyone to spy on you. And 10 people are participating. And if 9 of them use https, but one still use http this can make it unsafe for everybody.

On the other side I wonder if there are places where you can only connect through http. And this would break Vilfredo for people working from there.

So I think we should implement this and then see what happens. If someone cannot participate anymore he or she will let us know.



Giovani Spagnolo

unread,
Oct 6, 2013, 4:45:47 PM10/6/13
to vilfredo-deve...@googlegroups.com
This could be a setup option, just like it was in facebook  and others: "enable https/orce https". at the webapp level it can be achieved with .htaccess rewrite rules without hardcoding URL's in the source code.
gs
--
--
You received this message because you are subscribed to the Google
Groups "Vilfredo Develops in Athens" group.
To post to this group, send email to
vilfredo-deve...@googlegroups.com
To unsubscribe from this group, send email to
vilfredo-develops-i...@googlegroups.com
For more options, visit this group at
http://groups.google.com/group/vilfredo-develops-in-athens?hl=en
 
Vilfredo Develops in Athens is the mailing list for the developers of Vilfredo goes to Athens. The website can be found at
http://Vilfredo.org
the code can be found at
https://github.com/pietrosperoni/Vilfredo
On twitter we are @Vg2A
---
You received this message because you are subscribed to the Google Groups "Vilfredo Develops in Athens" group.
To unsubscribe from this group and stop receiving emails from it, send an email to vilfredo-develops-i...@googlegroups.com.
To post to this group, send an email to vilfredo-deve...@googlegroups.com.
Visit this group at http://groups.google.com/group/vilfredo-develops-in-athens.
To view this discussion on the web, visit https://groups.google.com/d/msgid/vilfredo-develops-in-athens/c52bc803-6619-478e-9698-ce352ebda99c%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

Pietro Speroni di Fenizio

unread,
Oct 6, 2013, 5:51:09 PM10/6/13
to vilfredo-deve...@googlegroups.com
Yes, good point about keeping the code universal. But Vilfredo.org should run force https like it has been asked to us, or would this give problems, in your opinion Giovani.


Pietro

Giovani Spagnolo

unread,
Oct 7, 2013, 3:54:41 AM10/7/13
to vilfredo-deve...@googlegroups.com
I would run Vilfredo.org forcing https, surely.
Private installs can choose to enable it, if they need so. Keep in mind that using SSL needs a certificate (unless you do not mind your users getting the ugly red screen warning about self-signed certificates). Some links:
http://webdesign.about.com/od/ssl/tp/cheapest-ssl-certificates.htm



Inviato da iPad

Il giorno 06/ott/2013, alle ore 23:51, Pietro Speroni di Fenizio <20...@pietrosperoni.it> ha scritto:

Yes, good point about keeping the code universal. But Vilfredo.org should run force https like it has been asked to us, or would this give problems, in your opinion Giovani.


Pietro

--
--
You received this message because you are subscribed to the Google
Groups "Vilfredo Develops in Athens" group.
To post to this group, send email to
vilfredo-deve...@googlegroups.com
To unsubscribe from this group, send email to
vilfredo-develops-i...@googlegroups.com
For more options, visit this group at
http://groups.google.com/group/vilfredo-develops-in-athens?hl=en
 
Vilfredo Develops in Athens is the mailing list for the developers of Vilfredo goes to Athens. The website can be found at
http://Vilfredo.org
the code can be found at
https://github.com/pietrosperoni/Vilfredo
On twitter we are @Vg2A
---
You received this message because you are subscribed to the Google Groups "Vilfredo Develops in Athens" group.
To unsubscribe from this group and stop receiving emails from it, send an email to vilfredo-develops-i...@googlegroups.com.
To post to this group, send an email to vilfredo-deve...@googlegroups.com.
Visit this group at http://groups.google.com/group/vilfredo-develops-in-athens.
Reply all
Reply to author
Forward
0 new messages