Announcement

Collapse
No announcement yet.

PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

    Originally posted by TheCotMan View Post
    Odd troubles reported from some people. One claims SSL negotiation issue, others report errors like this from firefox: "The connection was interrupted" and MSIE: "Zero Sized Reply".

    I've notified DT, but did not call or SMS... I don't want to wake him in his timezone.
    I didn't want to wake him because the servers were running, just not reachable by most people. (Fine distinction. No access and not being able to tell what is wrong could mean all kinds of serious troubles: Is the server room on fire? Did Black Helicopters fly into the server room and land on the servers? Did a singularity form in the server room, and take the network and servers away? Feds? Chinese retaliation for stealing Sun Tsu's Art of War? Japanese mad at us for, Cloverfield? But being able to see servers and content even though most other people can't "see" content means an access issue, and eliminates a large set of horrible problems, including GODZILLA attack... I can't tell you how many times GODZILLA has tried to attack the server room... mostly, because I don't know, but as a count, it is probably a non-negative integer .)

    https://twitter.com/thedarktangent/status/422481672870039552 - Tweet from DT
    Originally posted by tweet
    Looks like a signature update overnight started breaking things. Should be fixed now.
    Last edited by TheCotMan; January 12, 2014, 16:19.

    Comment


    • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

      Mobile style "Full Site" link broken-ness finally diagnosed and solved. Please report new troubles that may be introduced as a result of the fix.
      Yeah. The fix breaks other stuff. There is a defect in the mobile style. I'll fix it in the next shell-visit.
      Last edited by TheCotMan; January 17, 2014, 00:28.

      Comment


      • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

        While continuing to debug the mobile style bug, I broke the forums last night, and then angered the firewall, blocking me from undoing the next round of changes until a few hours ago.

        The bad news is forums did not work well for about 10 hours. The good news is I found the issue because of the debugging, and know how to fix it. I just need to get time away from work to do it.

        Comment


        • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

          Jeff found problem with FW that was blocking access to forums and fixed it. Access should be restored. Let me know if otherwise by email: defconforums@gmail.com

          Thanks!
          -Cot

          Comment


          • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

            In a related note... Now that I have access again, I have implemented a work-around for the mobile-style fail in the link "Full Site" ... This should now result in a redir back to the main page with a full-site style, instead aof a 404 "Super Shark Fin Sad Cat"

            Please report troubles.

            Comment


            • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

              Made a few minor changes to the configuration of the forum server. I do not see any changes in content delivery, but I would like to hear if you see problems.

              Please let me know about troubles on forums here, or by email: defconforums@gmail.com

              Thanks!
              -Cot

              One known difference you may see:
              * When posting, you may have to click the link to continue if your browser does not automatically forward you to the next page.

              What else?
              Last edited by TheCotMan; February 2, 2014, 02:42.

              Comment


              • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                Maintenance at 4:30pm... should be down for less than 30 minutes.

                Comment


                • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                  Originally posted by TheCotMan View Post
                  Maintenance at 4:30pm... should be down for less than 30 minutes.
                  Maintenance completed.
                  Please report troubles here or if you can't then by email for defconforums@gmail.com
                  TIA
                  -Cot

                  Comment


                  • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                    Bleeding stopped!

                    New 4096 Bit EV SHA-2 certificate installed after the Heart Bleed patch was applied.

                    As always we support PFS as well as non-PFS AES-256, but after this I am curious if we should _only_ allow PFS connections?
                    Last edited by The Dark Tangent; April 11, 2014, 22:58.
                    PGP Key: https://defcon.org/html/links/dtangent.html

                    Comment


                    • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                      Originally posted by Dark Tangent View Post
                      Bleeding stopped!

                      New 4096 Bit EV SAH-2 certificate installed after the Heart Bleed patch was applied.

                      As always we support PFS as well as non-PFS AES-256, but after this I am curious if we should _only_ allow PFS connections?
                      Thanks Jeff!

                      All members of forums:

                      Please, at a minimum, logout of ALL web browsers that you have forum accounts still logged in, and then login again. This should invalidate all session ID associated with each login.

                      As a further precaution, and what I did, and what i suggest you do:
                      Also, change your forum account password.

                      Please, please do this.

                      Thanks!
                      -Cot

                      Comment


                      • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                        Forum access was lost for several hours until Jeff restored access at around 10:30am pacific time. Server was not down, and services were running, so no data was lost.

                        There may be another period of down-time later today, where access is denied while he does other maintenance.

                        Thanks!
                        -Cot

                        Comment


                        • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                          A Security enhancement was applied to the forums a month or two ago, but one feature was being masked from display. Jeff fixed this masking last night, and it exposed a new problem when enabled, that caused 3 text fields to appear near login. With this information, I was able to debug this feature and address this problem, and also fix another problem since this feature was enabled, where after posting on the forums, you were not automatically taken to your post, but were required to click a link to return to your post.

                          At this point, after Jeff's work to help reveal a bug, and then time to address and fix it, all of the pre-security enhancement changes from before should be working as expected without feature loss on the forums. Please report loss of features you still see, so I can address those, too.

                          Thanks to [not included] for this report. (Waiting to see if they want public acknowledgement for the bug report that allowed me to fix this.)

                          [Edit: They do not want public acknowledgement for this report. Replaced place-holder literal x's like "XXXXXXXXXX" with [not included] now that I have confirmation. ]

                          Thanks!
                          -Cot
                          Last edited by TheCotMan; May 21, 2014, 10:28.

                          Comment


                          • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                            Originally posted by TheCotMan View Post
                            At this point, after Jeff's work to help reveal a bug, and then time to address and fix it, all of the pre-security enhancement changes from before should be working as expected without feature loss on the forums. Please report loss of features you still see, so I can address those, too.

                            I am working on this again, trying to find a right balance between user security an convenience. Please expect the 3-login box "brokeness" and "fails to redirect after post" to persist for a bit longer today. I am working on trying to find a better balance.

                            Comment


                            • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                              Originally posted by TheCotMan View Post
                              I am working on this again, trying to find a right balance between user security an convenience. Please expect the 3-login box "brokeness" and "fails to redirect after post" to persist for a bit longer today. I am working on trying to find a better balance.
                              Stll working on this, getting closer and closer to something that allows most things to work, and allows browser to take advantage of extra security features with http headers.

                              In other news, username of user "mauvehead" changed to "mauvehed" as the user is in good standing, and the change was trivial.

                              Comment


                              • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                                The media server seems to be down for me. Tried from a few different boxes.
                                https://media.defcon.org/

                                Comment

                                Working...
                                X