Not Secure

October 30th, 2018
lately this site is not secure, is there a reason for this change?
October 30th, 2018
Oh! I had not noticed that, but had to google it as soon as I saw your post. Apparently this is the result of a Chrome update because Google wants to improve connection security. Here's a short article that explains it: https://www.nytimes.com/2018/08/13/technology/personaltech/what-chrome-means-by-not-secure.html
I logged onto 365 using Safari, and I don't see this notification. I also noticed that in responding to your inquiry that my address bar is showing the "https" protocol, which means that this communication is secure. Not sure which parts of the 365 site are still using just the http and which are using https. I guess Google and Chrome will let us know!
October 30th, 2018
I've seen no messages with Firefox.
October 30th, 2018
Huh ... my daughter just walked past and I asked her why sometimes my Chrome shows "not secure" and sometimes it does not. She said my bookmark was old, with just the "http". She changed my bookmark, and not my address bar always shows the "https" (which is the secure protocol). So, I think 365 is using the secure protocol, but you might want to update your bookmark.
October 30th, 2018
I'm on chrome and safari and both are secure :)
October 30th, 2018
I had to have special permissions to access this site using the Wi-Fi at workplace( in my own lunchtime!)due to its insecurity. The system just blocked it
October 30th, 2018
April is right on this one. You're seeing the not secure message because you loading the page as http://365project.org/ instead of https://365project.org.

When you load a page as https, all the information between your computer and the 365project server is encrypted, meaning no one can read it or modify it. When you load a page as http, anyone on your local network, and everyone along the path the data takes to get to the server can read the data. For a site like this, it's not a too critical because all the data is public anyway.
The biggest risk is if you connect to this site using a http from a public wifi, someone could read your session cookies, then hijack your session and be logged in as you. ( https://en.wikipedia.org/wiki/Session_hijacking).

It may be helpful to install the plugin 'https everywhere' from the EFF. Any time you go to a page, it'll redirect you to https if it's available on for the site. Or the site administrator could set up an https redirect site wide to prevent anyone from accessing it without https.
October 30th, 2018
Thank you everyone for your input!
October 30th, 2018
After bringing it to everyone's attention, I am now secure!
Write a Reply
Sign up for a free account or Sign in to post a comment.