Mads Posted May 3, 2016 Report Share Posted May 3, 2016 Chrome is complaining about the security of lavag.org. It has an invalid certificate (encrypted with an outdated cipher).... Quote Link to comment
JKSH Posted May 3, 2016 Report Share Posted May 3, 2016 24 minutes ago, Mads said: Chrome is complaining about the security of lavag.org. It has an invalid certificate (encrypted with an outdated cipher).... Weird. I'm using Chrome (version 49.0.2623.112), and it's telling me that my connection is private. What is the supposedly outdated cipher? Quote Link to comment
Yair Posted May 3, 2016 Report Share Posted May 3, 2016 Seems fine here too (Win 10, FF): It says it expires on April 2019. Quote Link to comment
ShaunR Posted May 3, 2016 Report Share Posted May 3, 2016 It's not the certificate. It is because LavaG only supports TLS 1.0 ciphers and they have been deprecated in the latest Chromium (51?) based browsers. Quote Link to comment
hooovahh Posted May 3, 2016 Report Share Posted May 3, 2016 I think I saw this error when I was on LAVA from chrome on my phone. Quote Link to comment
Neil Pate Posted May 3, 2016 Report Share Posted May 3, 2016 Indeed, I have been getting this error on my phone for a month or so now. Quote Link to comment
Michael Aivaliotis Posted May 3, 2016 Report Share Posted May 3, 2016 Well, see Google is starting to do this because they want to "fix the web". There is nothing seriously broken with LAVA. it's as @ShaunR points out. Less secure because of the outdated TLS 1.0. The problem lies with the web server OS that LAVA runs on. So it's nothing I can quickly fix with my intervention. However, I'm aware of the situation. It's on my mind. I'm trying to figure out what modules and software layers need to change on the server, who can make the change, and how much will it cost me. So what we have is better than no https. But definitely not up to snuff. Quote Link to comment
ShaunR Posted May 4, 2016 Report Share Posted May 4, 2016 (edited) 11 hours ago, Michael Aivaliotis said: Well, see Google is starting to do this because they want to "fix the web". There is nothing seriously broken with LAVA. it's as @ShaunR points out. Less secure because of the outdated TLS 1.0. The problem lies with the web server OS that LAVA runs on. So it's nothing I can quickly fix with my intervention. However, I'm aware of the situation. It's on my mind. I'm trying to figure out what modules and software layers need to change on the server, who can make the change, and how much will it cost me. So what we have is better than no https. But definitely not up to snuff. Centos5 by any chance? This issue is (or at least TLS unable to support greater than 1.0 in Centos5) is the reason I have not moved to TLS on lvs-tools.co.uk yet even though I have the certificate. The problem is that it trains users to ignore privacy and security warnings.. When they are compromised for real, they just carry on without questioning instead of not visiting the suspect site and certainly not putting in user names and passwords..I'm sure there is a proper name for this conditioning but it is the same (but with possibly greater consequences) than T&C dialogues. Edited May 4, 2016 by ShaunR Quote Link to comment
Tony Tran Posted June 5, 2016 Report Share Posted June 5, 2016 (edited) I have faced this issue before, but sometimes, it's a fault from your device, not really from the server or the SSL certificate itself. I realized if the date and time of the device are invalid, it can lead to this error. Or if some application block the SSL connection, this error message will show up. So make sure to check the date and time of your device first. In the next step, temporarily disable/turn off any antivirus software to verify the issue. Source: https://bytebitebit.com/687/your-connection-is-not-private/ Edited April 9, 2020 by Tony Tran Quote Link to comment
Neil Pate Posted June 6, 2016 Report Share Posted June 6, 2016 Whatever the reason, since the upgrade I visit lavag.org far less regularly on my phone, which is a pity. Quote Link to comment
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.