Welcome to Doom9's Forum, THE in-place to be for everyone interested in DVD conversion.

Before you start posting please read the forum rules. By posting to this forum you agree to abide by the rules.

 

Go Back   Doom9's Forum > Capturing and Editing Video > Avisynth Development
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread Display Modes
Old 19th August 2017, 15:08   #1  |  Link
LigH
German doom9/Gleitz SuMo
 
LigH's Avatar
 
Join Date: Oct 2001
Location: Germany, rural Altmark
Posts: 6,784
Domain avisynth.nl unavailable via HTTPS

Who is actually the webmaster of the avisynth.nl domain?

The forum software of the German doom9/Gleitz board converts all HTTP links to HTTPS; so all links to https://avisynth.nl/index.php etc. lead to an outdated certificate. Some browsers warn of an insecure connection and discourage an exception, others display an error page in Dutch.

Please forward and notify the responsible person.
__________________

New German Gleitz board
MediaFire: x264 | x265 | VPx | AOM | Xvid
LigH is offline   Reply With Quote
Old 19th August 2017, 20:58   #2  |  Link
wonkey_monkey
Formerly davidh*****
 
wonkey_monkey's Avatar
 
Join Date: Jan 2004
Posts: 2,496
Quote:
The forum software of the German doom9/Gleitz board converts all HTTP links to HTTPS
Wouldn't whoever made that decision, arguably, be the responsible person?
__________________
My AviSynth filters / I'm the Doctor
wonkey_monkey is offline   Reply With Quote
Old 19th August 2017, 21:13   #3  |  Link
LigH
German doom9/Gleitz SuMo
 
LigH's Avatar
 
Join Date: Oct 2001
Location: Germany, rural Altmark
Posts: 6,784
The admin of the Gleitz forum is not the admin of avisynth.nl, though. And links in the Gleitz forum are just one possible example of a reason why someone might try to contact avisynth.nl via HTTPS.
__________________

New German Gleitz board
MediaFire: x264 | x265 | VPx | AOM | Xvid
LigH is offline   Reply With Quote
Old 19th August 2017, 21:21   #4  |  Link
ChaosKing
Registered User
 
Join Date: Dec 2005
Location: Germany
Posts: 1,795
So Gleitz "excludes" ~70% of the web just like that? There are tons of http only websites out there
__________________
AVSRepoGUI // VSRepoGUI - Package Manager for AviSynth // VapourSynth
VapourSynth Portable FATPACK || VapourSynth Database
ChaosKing is offline   Reply With Quote
Old 19th August 2017, 21:35   #5  |  Link
LigH
German doom9/Gleitz SuMo
 
LigH's Avatar
 
Join Date: Oct 2001
Location: Germany, rural Altmark
Posts: 6,784
More and more websites switch to secure transport protocols on their own, instead. Like more and more software does not care anymore about compatibility with obsolete operating systems.

I only recommend the support of modern features, without a demand, for the advantage of the privacy-aware user, assuming that this support may be within the intentions of the domain owner.

Now we are blamed for not being conservative. Why do you protect a flaw? Updating to a valid certificate won't lock out insecure connections.
__________________

New German Gleitz board
MediaFire: x264 | x265 | VPx | AOM | Xvid
LigH is offline   Reply With Quote
Old 19th August 2017, 22:16   #6  |  Link
LoRd_MuldeR
Software Developer
 
LoRd_MuldeR's Avatar
 
Join Date: Jun 2005
Location: Last House on Slunk Street
Posts: 13,248
Quote:
Originally Posted by LigH View Post
all links to https://avisynth.nl/index.php etc. lead to an outdated certificate. Some browsers warn of an insecure connection and discourage an exception, others display an error page in Dutch.
The certificate presented by the server is perfectly valid, but just doesn't match the domain "avisynth.nl", which is why it will be rejected by the web-browser – for good reason!

This happens, e.g., when the same HTTP server is used to serve multiple domains, but the admin missed to configure a matching certificate for each of those domains.

(The same certificate can match different domains – either by using wildcard DNS names or by writing several different DNS names into the Subject Alternative Name extension – but here it doesn't work out)
Attached Images
  
__________________
Go to https://standforukraine.com/ to find legitimate Ukrainian Charities 🇺🇦✊

Last edited by LoRd_MuldeR; 19th August 2017 at 22:38.
LoRd_MuldeR is offline   Reply With Quote
Old 19th August 2017, 23:15   #7  |  Link
LigH
German doom9/Gleitz SuMo
 
LigH's Avatar
 
Join Date: Oct 2001
Location: Germany, rural Altmark
Posts: 6,784
This happens for several domains, some I recently contacted were able to implement acceptable certificates (including my own hoster). "Let's Encrypt" appears to be involved increasingly.
__________________

New German Gleitz board
MediaFire: x264 | x265 | VPx | AOM | Xvid
LigH is offline   Reply With Quote
Old 20th August 2017, 00:38   #8  |  Link
StainlessS
HeartlessS Usurer
 
StainlessS's Avatar
 
Join Date: Dec 2009
Location: Over the rainbow
Posts: 10,980
I presume that this is related:- SSL Report: forum.doom9.org (213.112.23.71)
https://www.ssllabs.com/ssltest/anal...orum.doom9.org

I always have problem on Android 2.3.7 (GingerBread) trying to connect to the D9. [EDIT: Just gotta change https to http]
Just tried with XP IE8, same.
Both in red in above SSL report.

Also, think that Google always provides links with https nowadays.
__________________
I sometimes post sober.
StainlessS@MediaFire ::: AND/OR ::: StainlessS@SendSpace

"Some infinities are bigger than other infinities", but how many of them are infinitely bigger ???

Last edited by StainlessS; 20th August 2017 at 00:41.
StainlessS is offline   Reply With Quote
Old 20th August 2017, 01:46   #9  |  Link
TheFluff
Excessively jovial fellow
 
Join Date: Jun 2004
Location: rude
Posts: 1,100
Quote:
Originally Posted by StainlessS View Post
I presume that this is related:- SSL Report: forum.doom9.org (213.112.23.71)
https://www.ssllabs.com/ssltest/anal...orum.doom9.org

I always have problem on Android 2.3.7 (GingerBread) trying to connect to the D9. [EDIT: Just gotta change https to http]
Just tried with XP IE8, same.
Both in red in above SSL report.
It's not related, except in that both issues are SSL/TLS connection failures. The reason you can't connect with Android 2.3.7 or IE on Windows XP is that neither supports any cipher suites that the D9 server is configured to accept. One of the main issues with TLS/SSL is that it's been around for so long that there are a bunch of very old and now-insecure crypto options available for backwards compatibility reasons, but the D9 server is well-configured and only allows connections with reasonably modern ciphersuites, so that a user cannot be fooled into thinking the connection is secure when it actually might be easily breakable. Android 2.3.7 and IE8 on XP (Chrome on XP is fine because it bundles its own crypto libraries instead of relying on the system's) at least support TLS 1.0 so they're just barely capable of providing moderately secure communication... for now. However, PCI DSS (Payment Card Industry Data Security Standard - requirements for payment processing business that handle credit card info) prohibits the use of TLS 1.0 from June 30, 2018, so it's not going to stick around on a lot of big sites for much longer.

The issue with avisynth.nl is completely unrelated; it simply doesn't have a valid SSL certificate for that domain.

The point of SSL is not only to encrypt traffic so you don't yell out your passwords and credit card numbers so loudly that every single bystander (including anyone mildly interested on the free wifi you're using) can hear it, but also to ensure you know who you're actually talking to. A very common ransomware/virus/malware infection vector these days is clicking some link that looks like it's a familiar site but in fact will take you somewhere that looks legit but steals your data and/or uses exploits to install malware. SSL certificates are therefore completely pointless if they don't match the domain you're connecting to - there's no point in encrypting the traffic if you're talking directly to someone who is interested in eavesdropping on it, after all.

There is no reason for anything except the most trivial static pages on the open internet to use unencrypted HTTP today. It's very hard to overstate just how incredibly vulnerable anything running on plain HTTP is to all kinds of shenanigans, and sending passwords in cleartext over the internet in 2017 is basically ensuring they'll get into one of the gigantic username/password dumps floating around. The only reason you can get away with http on sites like d9 is that they're so obscure that it is unlikely that someone will bother to actually attack them.

Last edited by TheFluff; 20th August 2017 at 02:38.
TheFluff is offline   Reply With Quote
Old 21st August 2017, 02:38   #10  |  Link
FranceBB
Broadcast Encoder
 
FranceBB's Avatar
 
Join Date: Nov 2013
Location: Royal Borough of Kensington & Chelsea, UK
Posts: 2,905
@thefluff and @StainlesS... true. (little ot) Chrome hasn't been updated for quite some time on XP, 'cause Google support ended and has SSL issues with newer certificates. On the other hand, Firefox ESR is supposed to be supported (and updated) at least 'till middle 2018 and its own certificate manager handles pretty much everything. For instance, if you try to access Nyaa.si (popular anime torrent website) using HTTPS on Chrome, it'll end up with an error, while Firefox will load the page flawlessly. (End OT)
FranceBB is offline   Reply With Quote
Old 21st August 2017, 21:32   #11  |  Link
sl1pkn07
Pajas Mentales...
 
Join Date: Dec 2004
Location: Spanishtán
Posts: 496
nyaa.si works for me in chrome/ium
__________________
[AUR] Vapoursynth Stuff
[AUR] Avisynth Stuff
sl1pkn07 is offline   Reply With Quote
Old 22nd August 2017, 00:44   #12  |  Link
FranceBB
Broadcast Encoder
 
FranceBB's Avatar
 
Join Date: Nov 2013
Location: Royal Borough of Kensington & Chelsea, UK
Posts: 2,905
Quote:
Originally Posted by sl1pkn07 View Post
nyaa.si works for me in chrome/ium
On Windows7 and later, yes, on Windows XP nope. Picture

Anyway, the "problem" with avisynth.nl is different.
FranceBB is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 02:59.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.