Security->Technical Details: more info on HTTPS connections

Talk about code development, features, specific bugs, enhancements, patches, and similar things.
Forum rules
Please keep everything here strictly on-topic.
This board is meant for Pale Moon source code development related subjects only like code snippets, patches, specific bugs, git, the repositories, etc.

This is not for tech support! Please do not post tech support questions in the "Development" board!
Please make sure not to use this board for support questions. Please post issues with specific websites, extensions, etc. in the relevant boards for those topics.

Please keep things on-topic as this forum will be used for reference for Pale Moon development. Expect topics that aren't relevant as such to be moved or deleted.
EnDaFresh

Re: Security->Technical Details: more info on HTTPS connecti

Unread post by EnDaFresh » 2014-04-16, 00:21

@NightWing:
You honestly believe the USA allows free discourse anymore?

Try saying something negative about ANY specific Congressional politician or the US President. Post it on your Facebook Wall and say something like you want to throw them out of office. I'll laugh at you when the Secret Service raid your home in the middle of the night. It has happened and you're blind/stupid to think it hasn't happened. I'd link articles here, but for the sake of keeping on topic I'll just say that I absolutely believe we are in a Police State. We no longer have any civil rights that we aren't losing on a daily basis. Blind idiots like you are the reason we've even lost as many rights as we have, so I have no problem with you being one of many victims who are hauled away to Guantanimo sooner or later. Enjoy it there and send me a postcard :P
@ MC:
I understand your point. While I still feel that you could disallow crawlers via edits to the robots.txt, that is up to you. It may help to update the user agreement so that people are aware regarding the insecurity of anything they post here. Your forums, your rules, just keep us posted on things ^_^

"javascript:void(location.href='http://'%20+%20location.host%20+%20'/robots.txt')"
User-agent: *
Disallow: /contact/
Disallow: /images/
Disallow: /stats/
Disallow: /screens/
Disallow: /update/
Disallow: /dl-images/
Disallow: /websetup/

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5174
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Security->Technical Details: more info on HTTPS connecti

Unread post by Night Wing » 2014-04-16, 04:41

Off-topic:
@EnDaFresh

File this in the deep dark recesses of your mind where your fear and paranoia lurk....for future reference.

I don't have a Facebook account, I don't have a Twitter account, I don't have a MySpace account, I don't have an Instagram account, I don't have a Pinterest account or any social BS account.

You're nothing but a paranoid schizo conspiracy blow hard who wouldn't know Reality if it jumped up and bit you on your a$$. Guys like you just like to hear yourselves talk loads of hot air.

Radio personalities like Rush Limbaugh, Sean Hannity, Michael Berry say negative things about President O'Bama and also say negative things about US Senators and Congressmen/women everyday on their weekly radio shows, 5 days a week. Yet, no government entity has raided their homes or taken them away during the middle of the night. And no government entity has asked these radio stations for their call in logs from people who call in to these shows. I can even call in to one of these shows and say O'Bama is a sorry weak willed president with a spine made of Jello and no government entity is going to come to my house. And any government entity can read this post and still nothing is going to happen to me. I imagine the government's Carnivore program reads these posts, but it doesn't bother me.

Now for your so called Police State comment.

Do a little research and find out which country in the world has the most armed population and if you do, you'll find it's the United States. I don't know of any "police state" which allows their armed citizenry to own firearms (and in large quantities) like the United States does . I'll even provide you with a little leg work.

http://www.reuters.com/article/2007/08/ ... 3820070828

Since I've dealt with the ATF many times during my lifetime, the ATF already knows me from filling out a US government Form 4473, 22 separate times (and been approved) which means the ATF knows I've owned 22 firearms (long rifles and handguns) during my lifetime. The local, county and state governments where I live also know I know how to use them very well at both long (300 yards with a 30-06, 25-06 and 270 caliber rifles) and short (up close and personal) distances (with a .357 magnum revolver and 12 gauge semi-automatic and pump action shotguns) since I had to so some qualifying time with them. And I've never been employed with law enforcement in any capacity.

And at the present time, there are more firearms in my home than you have fingers on both of your hands. Since 1973, with the knowledge the AFT has on me, the ATF hasn't raided my home, the FBI hasn't raided my home, the NSA hasn't raided my home, the Secret Service hasn't raided my home, the state police hasn't raided my home, the county sheriff hasn't raided my home and the local city police haven't raided my home.

Police state......my a$$.
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

access2godzilla

Re: Security->Technical Details: more info on HTTPS connecti

Unread post by access2godzilla » 2014-04-16, 05:23

EnDaFresh wrote:While I still feel that you could disallow crawlers via edits to the robots.txt
- robots.txt is just a list of paths that should not be traversed by the bot, but it all depends on its compliance.
- Banning crawlers from the forum would be detrimental for the Pale Moon project.
- If NSA does indeed have a crawler, its not going to cry "NSAbot" in its useragent, so your hopes of "if preg_match("/NSAbot/", $_SERVER['HTTP_USER_AGENT']) { header ("HTTP/1.1 403 Forbidden"); }" are dashed.
- NSA can simply use techniques like deep packet inspection when they're intercepting such a huge amount of traffic, instead of making a crawler.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35648
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Security->Technical Details: more info on HTTPS connecti

Unread post by Moonchild » 2014-04-16, 07:10

I don't want to disallow crawlers. One of the points of running this forum is that posts are public and are indexed in search engines (as already explained).
That is why known bots have a specific access class to allow efficient crawling (which automatically disallows private and irrelevant information). Notice the "Bot"-classified users at the bottom, in the list of "users browsing this forum"?

If you want to discuss forum-encryption in detail and/or the other offtopic side discussion going on (Endafresh/NightWing), please be so kind as to make new topics (one for each in the appropriate board); this has completely derailed from the original topic of this thread.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite