Why does this website have no security?

Started by SolarRV, September 15, 2022, 02:39:44 PM

Previous topic - Next topic

SolarRV

Hello!
I have noticed that there is no SSL on the forum and that my previous account was hacked. What is going on with Midnight Solar? Going out of business??? Something does not seem right....

ClassicCrazy

What do you mean hacked ? Someone guessed your password and made posts under your account ?
Larry
system 1
Classic 150 , 5s3p  Kyocera 135watt , 12s Soneil 2v 540amp lead crystal for 24v pack , Outback 3524 inverter
system 2
 5s 135w Kyocero , 3s3p 270w Kyocera  to Classic 150 ,   8s Kyocera 225w to Hawkes Bay Jakiper 48v 15kwh LiFePO4 , Outback VFX 3648 inverter
system 3
KID / Brat portable

SolarRV

No I got a notification in my Google account that logins were compromised for Midnight Solar.

Vic

SolarRV, welcome to the Forum (I think).

At least in the olden days,  Security Certificates (probably have a different name, now),  were very expensive ($10-20 K).  It was said that this cost was the primary security that was provided  --  bad persons would not want to invest that amount to be able to steal from site-goers, and so on.  I do not know the state of these matters, today.

This site does do direct commerce (ie, members do not do financial transactions here), so for the first-order, the risks of being a member here, does not seem large (to me).

This Forum has been active for more than a decade.  It seems very far-fetched to equate this site structure, to any impending business failure,  kind of Snarky, really,  IMO.

But, if you feel insecure, would suggest that you not venture here.  I have had no issues with Security of this site, and this is the first I've heard mention of it.

C U Later,  Vic
Off Grid - Sys 1: 2ea SW+ 5548, Surrette 4KS25 1280 AH, 5.25 KW PV, Classic 150,WB, Beta Barcelona, Beta KID
Sys 2: SW+ 5548s, 4KS25s, 5.88 KW PV, 2 ea. Classic 150, WB, HB CC-needs remote Monitoring/Control, site=remote.
 MN Bkrs/Bxs/Combiners. Thanks MN for Great Products/Svc/Support&This Forum!!

SolarRV

You mean snarky like "Welcome to the Forum (I think)" >:( . My questions are more than reasonable. Why no SSL? Expensive? Ya, so what?

I looked. Outback, Schneider, and Victron all have SSL. Cost cutting measure by MS?

ClassicCrazy

Quote from: SolarRV on September 15, 2022, 09:11:01 PM
You mean snarky like "Welcome to the Forum (I think)" >:( . My questions are more than reasonable. Why no SSL? Expensive? Ya, so what?

I looked. Outback, Schneider, and Victron all have SSL. Cost cutting measure by MS?
Probably more like an older version of forums that just hasn't been kept up to date.
Like Vic , I don't think it is a big deal , just use a good password and anonymous ID and don't post anything you don't want to share. It is a public page anyway .
Maybe use a vpn and have an email just for things you don't trust. 
I just looked up on a website that checks if emails have been breached , and I don't see the midnite forums listed under my emails.
Larry
system 1
Classic 150 , 5s3p  Kyocera 135watt , 12s Soneil 2v 540amp lead crystal for 24v pack , Outback 3524 inverter
system 2
 5s 135w Kyocero , 3s3p 270w Kyocera  to Classic 150 ,   8s Kyocera 225w to Hawkes Bay Jakiper 48v 15kwh LiFePO4 , Outback VFX 3648 inverter
system 3
KID / Brat portable

boB


You are right about no SSL here.  It  SHOULD be https.   Not sure why it hasn't been ?

No, MidNite is not going out of business.   Probably just short of resources for the site ?

It is hard to find good help these days for sure.   Non SSL doesn't personally bother me but it should definitely be encrypted like everything else these days.

boB

K7IQ 🌛  He/She/Me

FNG

This is on me, I have about 100 irons in the fire one of them being forum maintenance. I am out of hours in the day and just havent gotten to update SMF or work on a certificate. I will discuss with Managment today and see who else has copius free time and is qualified. Stay tuned

boB


As I was thinking; Not really much time and resources available.  I know it's not THAT expensive though.

Doesn't bother me too much personally as I think that web browser writers worry too much about my safety and security when I can usually take care of myself.

boB
K7IQ 🌛  He/She/Me

Robin

Sorry, I just heard about this. I have contacted our graphic artist who took care of an SSL issue a few years back. We will see what can be done about it ASAP.
Thanks,
Robin
Robin Gudgel

FNG

Our IT dept deployed the certificate today so you should see the redirect to HTTPS now.