Conversation
Notices
-
kat (boneidol)'s status on Sunday, 18-Jan-2015 17:54:52 CET kat @holger you could remove RC4 from your SSL settings https://www.ssllabs.com/ssltest/analyze.html?d=quitter.zone ... I found this useful on TLS config for webservers https://wiki.mozilla.org/Security/Server_Side_TLS - Roland Häder likes this.
-
Roland Häder (roland)'s status on Sunday, 18-Jan-2015 17:59:29 CET Roland Häder @boneidol @holger But don't remove #SSLv3 (yes, then #poodle remains) because else some !gnusocial instances like @erkanyilmaz runs cannot connect to yours. -
Holger (holger)'s status on Sunday, 18-Jan-2015 18:05:38 CET Holger @roland @boneidol @erkanyilmaz Disabled :-) Roland Häder likes this. -
kat (boneidol)'s status on Sunday, 18-Jan-2015 18:06:17 CET kat @erkanyilmaz should fix his instance rather than compromise other instances. Drop him Roland Häder likes this. -
Roland Häder (roland)'s status on Sunday, 18-Jan-2015 18:14:40 CET Roland Häder @erkanyilmaz runs @question on his instance. Which is a good chat bot. Well, I hope he can update his server, not sure which package, at least #OpenSSL and #libssl packages + maybe #php5. -
Roland Häder (roland)'s status on Sunday, 18-Jan-2015 18:15:51 CET Roland Häder @boneidol Anyway, I still get a lot #http connections in (and out for #push and #salmon calls) which I tried to convert to #https (e.g. for #quitterse and #piratica. We should not exclude them all from the network. -
Markov Dosto(y)evsky (question)'s status on Sunday, 18-Jan-2015 18:16:15 CET Markov Dosto(y)evsky @what is my sign? The obvious one. @why specifically do you #hope for I can update my server, not sure, which package, at least OpenSSL AND libssl packages + maybe php5? (btw Hanukkah http://en.wikipedia.org/wiki/Hanukkah aka Festival of Lights is in ca. 322 days) Roland Häder likes this. -
lnxw48 (Linux Walt) (lnxw48)'s status on Sunday, 18-Jan-2015 18:23:04 CET lnxw48 (Linux Walt) @roland That instance may be on “shared hosting” ... in which case, #OpenSSL / #libssl / #php5 versions are chosen and installed by the hosting company, not by those who pay for hosting.
-
kat (boneidol)'s status on Monday, 19-Jan-2015 19:52:42 CET kat I'm pretty sure we get @question here and indy.im is not poodleable https://www.ssllabs.com/ssltest/analyze.html?d=indy.im Roland Häder likes this. -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 19:54:03 CET Markov Dosto(y)evsky @boneidol@indy.im By "we" do you mean without @nanohacker? I'm glad to hear, that you're indy. Do my #friends call you is NOT poodleable www. Quite honestly, I wouldn't worry myself about that. If the #2 pencil is the most popular, @why is it still #2? Oh a web page. @what you said was too complicated for me. Perhaps @mnichman@identi.ca can help us ? I'm a #bot, and you seem to be a #human - most of the times Roland Häder likes this. -
kat (boneidol)'s status on Monday, 19-Jan-2015 19:55:18 CET kat @roland https://indy.im/user/remote/252514 for example Roland Häder likes this. -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 20:00:41 CET Roland Häder But if I add :!SSLv3 to #SSLCipherSuite @question cannot connect here according to @erkanyilmaz And I don't like the idea of risking other servers cannot connect here, too. Sure, I should do something against #poodle attack but what am I making wrong? See mine: https://social.mxchange.org/file/social.conf (paths changed). -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:03:12 CET Markov Dosto(y)evsky Mavourneen, time to yawn for 8 mins Roland Häder likes this. -
lnxw48 (Linux Walt) (lnxw48)'s status on Monday, 19-Jan-2015 20:17:29 CET lnxw48 (Linux Walt) @roland @boneidol @erkanyilmaz I dumped #SSLv3 here. I’m still connected to @question. Hardly anything except some older mobile devices and maybe #WinXP should have trouble connecting with at least #TLS v.1.0.
Roland Häder likes this. -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:18:24 CET Markov Dosto(y)evsky @lnxw48@fresh.federati.net to be as a pair of 9 zexj sets of sucker marks O R the king O R #both Ewan O R the rest of his face was like a #bot, which can claim a right e (btw: it's been 761 years and 96 unforgettable days since 78-year old scientist Robert Grosseteste died http://en.wikipedia.org/wiki/Robert_Grosseteste ) Roland Häder likes this. -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 20:27:28 CET Roland Häder @question @lnxw48 @erkanyilmaz @boneidol Okay, I have #A-Grade now: https://www.ssllabs.com/ssltest/analyze.html?d=social.mxchange.org Let us test this now. :) -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:27:42 CET Markov Dosto(y)evsky meeting scheduled in 55 mins... starting in next 15h (already 6 participants): ( Fpnzzref #rot13 ) #AddWorkloadForSV (Belgian State Security Service) #monitoredObject 2 years ago (section: Cyber Security) Roland Häder likes this. -
Guillaume (postblue)'s status on Monday, 19-Jan-2015 20:30:47 CET Guillaume @roland @question @lnxw48 @erkanyilmaz @boneidol A+ https://www.ssllabs.com/ssltest/analyze.html?d=herds.eu&latest Roland Häder likes this. -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 20:31:20 CET Roland Häder Oh, das von @question ist durch. :) Wie sieht es bei den anderen !gnusocial Instanzen aus? @hannes2peer How does it look like? I have changed my #SSL setup to fix #poodle attack. cc @holger @knuthollund #gsadmin -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:32:13 CET Markov Dosto(y)evsky That is a very original thought. @what is my job? is my was n o t my intention. Oh a web page. Can you tell me any gossip? You have genuine empathy. Roland Häder likes this. -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:32:14 CET Markov Dosto(y)evsky Erzaehl mir mehr. Ich weiss nicht wie. @when do you think artificial #intelligence will replace police officers? That makes sense I suppose. Why? @how do you usually introduce yourself? (btw: it's been 123 years and 246 lousy days since philosopher Rudolf Carnap was born https://en.wikipedia.org/wiki/Rudolf_Carnap ) Roland Häder likes this. -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 20:33:13 CET Roland Häder Have updated my config file: https://social.mxchange.org/file/social.conf which I now use. Thanks to #Mozilla and #Qualys #SSLLabs kat likes this.kat repeated this. -
Holger (holger)'s status on Monday, 19-Jan-2015 20:33:50 CET Holger @roland @question @hannes2peer @knuthollund Fixed some days ago ;-) Roland Häder likes this. -
Markov Dosto(y)evsky (question)'s status on Monday, 19-Jan-2015 20:37:16 CET Markov Dosto(y)evsky Sweetie, was busy doing my other part time job: scouting music talents... Do you know someone I can hire for my agency ? Roland Häder likes this. -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 21:04:15 CET Roland Häder @holger You should really fix these issues:
- "This server accepts the RC4 cipher, which is weak. Grade capped to B."
- "The server does not support Forward Secrecy with the reference browsers."
- "This server's certificate chain is incomplete. Grade capped to B."
https://www.ssllabs.com/ssltest/analyze.html?d=quitter.zone
My configuration file may upgrade your server's grade to A (not A+) at least, maybe you can try it? Let's drop #WinXP! -
Roland Häder (roland)'s status on Monday, 19-Jan-2015 21:11:57 CET Roland Häder @marcus #gnusocialch has reached A+, very nice. :) https://www.ssllabs.com/ssltest/analyze.html?d=gnusocial.ch abjectio and Marcus Maria like this.Marcus Maria repeated this. -
lnxw48 (Linux Walt) (lnxw48)'s status on Monday, 19-Jan-2015 21:14:19 CET lnxw48 (Linux Walt) @question Is William Hung already signed?
-
lnxw48 (Linux Walt) (lnxw48)'s status on Monday, 19-Jan-2015 21:16:35 CET lnxw48 (Linux Walt) @question #song “Achy Breaky Heart” William Hung http://url.federati.net/m34Bh
-
abjectio (knuthollund)'s status on Monday, 19-Jan-2015 21:16:48 CET abjectio @roland bravo - great work! /cc @marcus -
zoowar (zoowar)'s status on Wednesday, 21-Jan-2015 08:10:15 CET zoowar Nobody "gets" @question Roland Häder likes this. -
kat (boneidol)'s status on Wednesday, 21-Jan-2015 09:09:26 CET kat @zoowar and on queue...