GOLFMK8
GOLFMK7
GOLFMK6
GOLFMKV

Anybody else getting this message when opening the forum?

launchd

Drag Racing Champion
I'll take your word for it but a person still wouldn't be secure would they?

There are a handful of nefarious actions that can occur when a certificate expires, both client side and server side. Changing your computer’s clock (to be incorrect) will not make them any easier to accomplish or exploit. However, you could inadvertently break your access to other secure websites or applications by doing this. I wouldn’t recommend it :)
 

timbdotus

New member
I'll take your word for it but a person still wouldn't be secure would they?

SSL certificates only really prevent man in the middle attacks. They just ensure the data is encrypted as it travels from the server to your browser.

In actual fact, they may not even prevent MITM attacks anymore. Depending on the type of certificate, one could theoretically brute force the private keys in a matter of days if they were determined enough and had access to suitable computing power.

Frankly, there’s no real compelling reason a forum like this needs to run SSL full time. You’re not submitting sensitive financial information or anything. Hell, when you log in your password isn’t even transmitted in the clear; it’s hashed client side and that hash is what is sent to the server.

The only reason that basically all sites now run SSL is because Let’s Encrypt made it free and easy to do so. 15+ years ago it cost several hundred dollars a year for VeriSign to sign your certificate, so you only really saw them on eCommerce sites, to guarantee credit card numbers were encrypted in flight.

Source: I spent the 2000’s deep in the web hosting industry. I’m now a development engineer at AWS.
 

IWMTom

Autocross Newbie
Hell, when you log in your password isn’t even transmitted in the clear; it’s hashed client side and that hash is what is sent to the server.
Uh, since when? This isn't common place at all.

Perhaps you've had the privilege of working exclusively with Cognito for too long? 😉
 
Last edited:

videoman

Passed Driver's Ed
me too i got it this morning, on the main index page , however i have seen it a few days ago when googling answers then finding a link to find the answer when the same appeared
 

Attachments

  • 2021-01-06 07_14_43-Mozilla Firefox.png
    2021-01-06 07_14_43-Mozilla Firefox.png
    10.8 KB · Views: 175

randomhobo130

Drag Racing Champion
me too i got it this morning, on the main index page , however i have seen it a few days ago when googling answers then finding a link to find the answer when the same appeared
Mods reached out to the owners of the site. Still no response from them yet probably
 

swcrow

Autocross Champion
Tick tock
 

timbdotus

New member
Uh, since when? This isn't common place at all.

Perhaps you've had the privilege of working exclusively with Cognito for too long? 😉

This has become more common in recent years, but I might be thinking of another piece of forum software that’s a bit more modern.

And yes, I could have been working with Cognito for far too long as well. 😅
 

sterkrazzy

Autocross Champion
It looks like it's been renewed now?
 

Thumper

Autocross Champion
Frankly, there’s no real compelling reason a forum like this needs to run SSL full time. You’re not submitting sensitive financial information or anything.

This was a point I was going to make yesterday but got slammed at work and spent my forum reading time devouring a build thread on vortex lol

There's no personal info stored here, no addresses, bank info (unless you've sent that in a PM and then you've got more issues anyway), no medial info. What POSSIBLE reason would anyone have to imitate a golf forum and snag usernames and passwords? LOL

Yeah if it's a person who just likes breaking stuff or causing havoc, they could then post a bunch of nonsense under your name. Or spam your email with garbage ads. I guess they could sign up your email for a bunch of perverted internet nastiness. But again they would have to A) know the cert was expired or B) be randomly scanning forums checking for it.

And yeah, problem appears fixed, 5 days to fix seems long and would be career ending for mission critical stuff, but again......this is an internet forum about VWs.....that we access for free.......perspective is everything. ;)
 

swcrow

Autocross Champion
I’m back in from work baby, YEA-UH!
 
Top