Security risk of this forum, which has been labeled insecure

Something on your mind? Want to give us feedback on something in particular or everything in general? Tell us how we are doing!
Post Reply
testy
Posts:43
Joined:Tue Mar 14, 2017 5:10 am
Security risk of this forum, which has been labeled insecure

Post by testy » Wed Mar 22, 2017 2:13 pm

Every time I log onto this forum, I get the warnings shown below from Firefox :

"Insecure password warning in Firefox

What can I do if a login page is insecure?

If a login page for your favorite site is insecure, you can try and see if a secure version of the page exists by typing https:// before the url in the location bar. You can also try to contact the web administrator for the site and ask them to secure their connection.
Not recommended: You can also continue to log in to the website even if the connection is insecure, but do so at your own risk. If you do go this route, try to use a unique password or a password that you don’t also use for other important sites.

Note for developers

For developers looking to learn more about this warning, please see this page. The page explains when and why Firefox shows this warning, and will also provide some details on how to fix the issue. For more information, see this blog post and this Site Compatibility document."

Is there anyway you Ooma experts can add a layer of security to this ?
Last edited by testy on Thu Mar 23, 2017 1:17 pm, edited 2 times in total.

User avatar
southsound
Posts:3519
Joined:Fri Feb 06, 2009 11:31 am
Location:Harstine Island, WA

Re: Security password risk of this forum, which is insecure....

Post by southsound » Wed Mar 22, 2017 9:32 pm

Simple solution - instead of using my usual password "password" for this site, I use a unique one that no one could possibly guess "retne" which is enter backwards. Sometimes I make it really hard by using 3's in place of the e's. Always a work around if you are willing to be smarter than the average cyber crook.

I used to worry about being paranoid until someone told me that you aren't paranoid if they really are watching you.

Image

Image

It's a user forum - not a link to the NSA. Of course, they're probably watching anyways. <<grin>>

Sent from my safe room using mittens to type so I don't leave incriminating prints.
ooma customer since February 2009
VoIP hardware: 2 Telo w/3 handsets & Linx / ooma core
Total Lines: 8 / Numbers: 11 / Handsets: 20
Lifetime Premier Member
Friends don't remember what Landline Integration was or why we did it.

User avatar
RichL
Posts:74
Joined:Tue Feb 07, 2017 4:04 pm
Location:Ohio

Re: Security risk of this forum, which has been labeled insecure

Post by RichL » Thu Mar 23, 2017 4:41 pm

Those are good passwords. :D

So how did you get those nice photos to display ? thanks
Rich

User avatar
southsound
Posts:3519
Joined:Fri Feb 06, 2009 11:31 am
Location:Harstine Island, WA

Re: Security risk of this forum, which has been labeled insecure

Post by southsound » Thu Mar 23, 2017 9:51 pm

Just a few easy steps to insert a picture that resides on the web. With the cursor where you want to place the image, click the Img button then just paste the image URL in between the "" and you are all done! I always use the Preview button to check the results.
ooma customer since February 2009
VoIP hardware: 2 Telo w/3 handsets & Linx / ooma core
Total Lines: 8 / Numbers: 11 / Handsets: 20
Lifetime Premier Member
Friends don't remember what Landline Integration was or why we did it.

geoart
Posts:33
Joined:Thu Oct 30, 2014 6:03 pm

Re: Security risk of this forum, which has been labeled insecure

Post by geoart » Sun Mar 26, 2017 6:13 am

Seems like the forums page uses an invalid certificate meant for saas.appdynamics.com (Cisco company) which Ooma likely uses on the backend. Ooma can simply re-use the same certificate used on my.ooma.com site (which is quite secure) since it's a wildcard certificate *.ooma.com but I'm sure the techs know this. Lately browsers (particularly Google's Chrome) are coming down hard on certificates and the certificate authority itself. In fact, my.ooma's certificate are issued by Symantec which Google just recently announced they will stop allowing in the coming months/years. They already outright block those issued by StartCom.

Post Reply