Skip to content
TORNLIFE More

HTTPS for everyone? Playing securely.

Started by quaffgiggle [2008372] on in Suggestions.

41 replies · 267 views · thread synced · 7 days ago · View on torn.com
About this thread

Posts archived: 42 / 42 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
42
Discussion span
→
Authority score
43 / 100
Historical score
28 / 100
Story score
52 / 100
Engagement score
65 / 100

People posting, likes and official posts are not counted for this thread yet: on threads longer than one page they come from a periodic pass over the archive, which has not covered it.

Most-liked replies

quaffgiggle [2008372]

I have noticed that you run a secure version of the site but you don't have any of the options set to either enable it by default or a ruleset created so those of us who have installed HTTPS Everywhere can automatically get the secure option enabled no matter what links we follow. For instance I may log into the secure site but if I follow a link from the forums or google if it's the unsecured url I am now browsing the unsecured site when my intention was the secure version. Sometimes I'm finding I end up being logged out as well because of this. I know you're busy and I genuinely love this game and all of your obvious hard work put into it but any help with this would be greatly appreciated. Thank you.

More info: https://www.eff.org/https-everywhere/faq#faq-How-do-I-add-my-own-site-to-HTTPS-Everywhere?
quaffgiggle [2008372]

That's a pretty simplistic view on things... also there's no reason you shouldn't be using the secure option in your everyday life. It's just good practice.
quaffgiggle [2008372]

I shouldn't have to explain this to you...here goes nothing. No one needs it but (1) if anyone is snooping around your home network cause you've set a bad password or using an insecure wireless encryption (don't be either of these people), (2) or you have concerns about your connection (any public place with available WiFi free or otherwise - playing at an airport or the dude next to you at McDonald's looks like he's wanking to pron while waiting for some code to finish processing...), (3) or how about especially considering you've got your password for the game and the info for whatever method you may use to support the site via donations. There are reasons. Here's three off the top of my head. Again ultimately you should do it because it's good practice. End of story.
TheChechen [1649392]

this should probably be moved to technology or general as its not really a suggestion in terms of how the suggestions forum works....also quit securing people connections for those of us sniffing packets with wireshark,,,, and ya basically this is noobish
AshleyT [1432316]

If someone really wants to do that, they can get past a secure http connection, really. Only amateurs can't do that. But yes, it is a nice layer to stop just anyone looking but it also causes additional load.
quaffgiggle [2008372]

Well yes of course where there's a will... but that is not the point of my OP. Why is everyone trying to argue the merits of good practices on a daily basis vs sitting online broadcasting all your info for the world to see? I mean if you truly do not care go ahead and reply with your IP, SS#, passport#, or any other personally identifying info here just for funsies in the thread and see how the rest of your day goes.
PhaNToM [1503918]

Do you have a suggestion? Or just a cry baby help me thread?

also my life isn't on torn so it's okay to not use secured version.

ALSOOO. Ched did make it all secured one day. Didn't last long.
Mauk [1494436]

He does have a suggestion and I fail to see why you categorize his thread as "cry baby help me."

I personally can't see a good enough reason for anyone not to use https nowadays.
AshleyT [1432316]

You'd be surprised. I think it should be kept optional at all times. But making it clear where the secure lines end would be nice.
Mauk [1494436]

I would be surprised, because a 1-RTT overhead isn't that much of a hit.

It doesn't matter for this discussion, anyway, as OP suggested an optional setting.
Mauk [1494436]

It's optional but also ad-hoc.

What he suggested (very badly) is an account-wide setting to enforce https. I don't think it's worth it because of the flaws such method brings to the table, but, eh, an HSTS-based solution would be better than nothing.

I'm still an advocate for enforced https everywhere, though. That 1-RTT can be completely negated by a move to HTTP2 anyway, and TLS 1.3 will make 0-RTT https possible.

Also, currently, Torn has lots of low-hanging performance issues that would far outweight the TLS overhead. General html/js optimizations could get them much better benefits than "not moving to https."
AshleyT [1432316]

Enforced https everywhere would completely kill the script community for the most part, as well as put a usually pointless barrier to the interaction, despite it's advantages, you are not transmitting confidential data for the majority of your time In Torn.

Optional methods are fine by me, enforced methods are pointless for the majority.

And while it is possible to create scripts with https, it is a major detriment to any script operating.