Private Messenger broken?

Anunaki

Active member
Feedback
3 (100%)
Credits
72CR
I'm taken to a "This page is unsafe" page when I go to the Private messenger section. When I choose to ignore this the lay-out is broken

ukvac.JPG
 

Alpha1

Do the Shake and 'VAC
Staff member
vacBacker
Feedback
95 (99%)
Credits
5,420CR
Are you both using chrome?

PM section is https encrypted, it's most likely the browser not likely the cipher suite anymore.

I'm on a train at the minute so can't do anything. Use a different browser in the mean time.
 

Macro

Active member
vacBacker
Feedback
4 (100%)
Credits
1,982CR
In case it helps, Chrome says ...

The connection to this site uses an obsolete protocol (TLS 1.0), a strong key exchange (ECDHE_RSA with P-256), and an obsolete cipher (AES_256_CBC with HMAC-SHA1).
 

funhouse

Active member
vacBacker
Feedback
3 (100%)
Credits
360CR
Yes, I have got that message in Chrome for a while. I think the older ( AES_256_CBC with HMAC-SHA1) encryption has been exploited elsewhere so they are just warning us.

I guess it may be fixed if the forum software is updated but I can imagine that could be a testing time...
smiley26.gif
 

chunksin

Active member
vacBacker
Feedback
21 (100%)
Credits
733CR
If it's a 3rd party cert can't you just get a SHA-2 version reissued ? Rapidssl did that for free when I had to update all of our websites last year to move off SHA-1
 

aeroflott

A different league
Feedback
16 (100%)
Credits
1,025CR
If it helps, Desktop Firefox is OK here, but I get a message when using Chrome on Android:

Your connection is not private: Attackers might be trying to steal your information blah blah blah.
 

big10p

Coins detected in pocket!
vacBacker
Feedback
12 (100%)
Credits
5,636CR
I use chrome and have been bugged with this issue. I deleted all history/cookies and it seems to have sorted it... unless Alpha1 has fixed something, server side?
smiley1.gif
 

dj_yt

Active member
Feedback
3 (100%)
Credits
787CR
Chrome 56.0.2924.87 (64-bit) here.

I've tried deleting all UKVAC cookies and it didn't solve the issue.

As a quick fix, using incognito mode seems to work.
 

big10p

Coins detected in pocket!
vacBacker
Feedback
12 (100%)
Credits
5,636CR
Same version as me. I deleted all backup browsing data (first 4 check boxes) from "the beginning of time".
big10p2017-02-08 14:50:07
 

JohnBud

There's only one JB, only one JB!
Feedback
2 (100%)
Credits
429CR
had an issue this morning but got told all is fine by 2 members on my facebook page. they posted 2 links to the problem

https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html
 

Outrun2

Colonel Outrun
Feedback
5 (100%)
Credits
1,142CR
Chunksin said:
Cheers guys, I just cleared cookies, cached images and hosted app data (the default) and its all back to normal :)

This worked for me, but I had to continue past the 'unsafe' message in order to log in. Once logged back in all seems well - although it does state 'Not Secure' in the address bar when within the private messenger environment (it used to do that even before the update though).
 
Top