PDA

View Full Version : C4L Lacks Secure Connection During Credit Card Processing




Tenbatsu
10-01-2008, 09:27 AM
It seems C4L does not have an SSL certificate that allows for a secure connection via https. This needs to be fixed immediately if our credit card numbers are to be secure.

If this has already been posted, I'm sorry.

jake
10-01-2008, 09:28 AM
ouch, MAJOR oversight.

BUMP.

Kade
10-01-2008, 09:29 AM
Too late... Anonymous posted this last night.

Guaranteed it's been hacked.

Lovecraftian4Paul
10-01-2008, 09:32 AM
Too late... Anonymous posted this last night.

Guaranteed it's been hacked.

Not cool. If Anon hasn't gotten to it yet, they will soon. This needs to be fixed ASAP!

Tenbatsu
10-01-2008, 09:32 AM
Can someone who has full membership post on the C4L blog and let everyone know about this?

constituent
10-01-2008, 09:35 AM
Can someone who has full membership post on the C4L blog and let everyone know about this?

meh, go straight to the paul.

Mahkato
10-01-2008, 09:36 AM
Whoa. Crap.

afmatt
10-01-2008, 09:39 AM
Per C4L staff it's being resolved as we speak.

yongrel
10-01-2008, 09:40 AM
Too late... Anonymous posted this last night.

Guaranteed it's been hacked.

Anon got there already? Fuck.

CFL FTL

Danke
10-01-2008, 09:41 AM
They are working on it.

Mahkato
10-01-2008, 10:12 AM
So does this mean my number and other personal data has been likely stolen?

Ack
10-01-2008, 10:17 AM
So does this mean my number and other personal data has been likely stolen?

If you sent your credit card info through the site then it's possible, but not necessarily likely. I'd just keep a close eye on your account activity for fraudulent charges.

yongrel
10-01-2008, 10:18 AM
So does this mean my number and other personal data has been likely stolen?

It's a distinct possibility. Keep an eye on your accounts for now.

JosephTheLibertarian
10-01-2008, 10:19 AM
It seems C4L does not have an SSL certificate that allows for a secure connection via https. This needs to be fixed immediately if our credit card numbers are to be secure.

If this has already been posted, I'm sorry.

I wish I was working at c4l right now. I'dbe on irc with goodies fo sho

Ninja Homer
10-01-2008, 10:24 AM
So does this mean my number and other personal data has been likely stolen?

Most likely not. It means that the data was sent from your computer to the C4L server without being encrypted. There still needs to be someone between your computer and the C4L server to intercept it. Since it just went live, chances of that happening are pretty low, but there's still a chance so do keep an eye on it.

Debbie Hopper
10-01-2008, 10:30 AM
It's fixed.

Mahkato
10-01-2008, 10:32 AM
It's fixed.

Debbie, could we get links to the old blog to redirect to the new addresses? For example, http://www.campaignforliberty.com/blog/?p=647 is currently 404'd.

We'll lose a lot of inbound traffic for a while if this is not fixed.

Matt Collins
10-01-2008, 10:40 AM
I just tried it again and got the following error:
Secure Connection Failed













70.32.73.101 uses an invalid security certificate.

The certificate is not trusted because it is self signed.
The certificate is only valid for campaignforliberty.com

(Error code: sec_error_untrusted_issuer)







* This could be a problem with the server's configuration, or it could be someone trying to impersonate the server.

* If you have connected to this server successfully in the past, the error may be temporary, and you can try again later.

Liberty Rebellion
10-01-2008, 10:41 AM
I just punched "www.campaignforliberty.com" in my browser and then http://70.32.73.101/#. shows up in the address bar

afmatt
10-01-2008, 10:42 AM
Secure Connection Failed
70.32.73.101 uses an invalid security certificate.

The certificate is not trusted because it is self signed.
The certificate is only valid for campaignforliberty.com

(Error code: sec_error_untrusted_issuer)

* This could be a problem with the server's configuration, or it could be someone trying to impersonate the server.

* If you have connected to this server successfully in the past, the error may be temporary, and you can try again later.


Just a heads up - the only reason the certificate seems to be throwing an error is because it is for the CAMPAIGNFORLIBERTY.com site - not the IP address that we are accessing the site through for now.

tekkierich
10-01-2008, 10:44 AM
Self signed certificates do no good in this case.


I suggest you get an EV SSL cert from http://www.networksolutions.com/SSL-certificates/ev-certificate.jsp

Debbie Hopper
10-01-2008, 10:47 AM
Jonathan, I sent your concerns to Adam to fix.

Matt, I spoke with Adam and as I understand it, the security issue has been fixed. Excuse my ignorance, but he said something about the security certificate coming from the new hosting company we switched to.

Please feel free to use the "Help" link on the main menu bar to let Adam know of any problems are concerns that you have with the new site.

Matt Collins
10-01-2008, 11:33 AM
Matt, I spoke with Adam and as I understand it, the security issue has been fixed. Excuse my ignorance, but he said something about the security certificate coming from the new hosting company we switched to.I understand. This stuff gets a bit complicated especially when dealing with multiple vendors across the Net.

MRoCkEd
10-01-2008, 11:37 AM
Uh oh

MRoCkEd
10-01-2008, 11:38 AM
after you're done with that, get terra eclipse to design it or something.
this site is UGGGGLY
the beta one was even better

Kade
10-01-2008, 11:41 AM
I have independently confirmed that CFL was hacked yesterday.

It appears to have been a week of DOS type attacks, followed with a full breach sometime this morning.

I don't know what information was taken, if any. Anonymous is genuinely favorable towards Ron Paul, so this might have only be an attempt to promote a more secure site. Most of Anon is relatively liberty minded, ironically, chances are high there was no theft of people's information.

Soccrmastr
10-01-2008, 11:56 AM
I have independently confirmed that CFL was hacked yesterday.

It appears to have been a week of DOS type attacks, followed with a full breach sometime this morning.

I don't know what information was taken, if any. Anonymous is genuinely favorable towards Ron Paul, so this might have only be an attempt to promote a more secure site. Most of Anon is relatively liberty minded, ironically, chances are high there was no theft of people's information.

If Anon had the chance to destroy their own home 4chan they would. Dont be fooled. They have allegiance to no one but themselves.

Call Me V
10-01-2008, 12:08 PM
Anonymous gets a bad rap.

Most are actually libertarians and very well spoken and opinionated.

Kade
10-01-2008, 12:11 PM
Anonymous gets a bad rap.

Most are actually libertarians and very well spoken and opinionated.

Agreed.

Mahkato
10-01-2008, 02:26 PM
I have independently confirmed that CFL was hacked yesterday.

It appears to have been a week of DOS type attacks, followed with a full breach sometime this morning.

I don't know what information was taken, if any. Anonymous is genuinely favorable towards Ron Paul, so this might have only be an attempt to promote a more secure site. Most of Anon is relatively liberty minded, ironically, chances are high there was no theft of people's information.

So how do you independently confirm this?