Speed Sudoku

Speed Sudoku - Play web sudoku puzzle games online for free!

Ready to play fast-paced sudoku races online? Create an account & start playing!

security problem

Talk about all things related to Speed Sudoku
Forum rules
Please read the forum guidelines before posting.

security problem

Postby mikewardbarrow on Wed Apr 06, 2011 3:18 pm

I tried to log on to premium membership - and got the following message. Comments please


The security certificate presented by this website was not issued by a trusted certificate authority.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as https://example.com, try adding the 'www' to the address, https://www.example.com.
If you choose to ignore this error and continue, do not enter private information into the website.

For more information, see "Certificate Errors" in Internet Explorer Help.
User avatar
Novice mikewardbarrow
 
Posts: 64
Joined: Tue Jul 07, 2009 5:09 pm
Location: South West England
Medals: 6
Easy Puzzle Medal (1) Medium Puzzle Medal (2) Hard Puzzle Medal (1) Very Hard Puzzle Medal (2)

Re: security problem

Postby achilles on Sun Apr 10, 2011 6:41 pm

Could you clarify if the premium page was on https://www.speedsudoku.com or just https://speedsudoku.com?
User avatar
Beginner achilles
Staff
 
Posts: 101
Joined: Thu Apr 16, 2009 8:56 pm

Re: security problem

Postby mikewardbarrow on Mon Apr 11, 2011 9:13 am

I went to

Player - premium membership - and got this response.
User avatar
Novice mikewardbarrow
 
Posts: 64
Joined: Tue Jul 07, 2009 5:09 pm
Location: South West England
Medals: 6
Easy Puzzle Medal (1) Medium Puzzle Medal (2) Hard Puzzle Medal (1) Very Hard Puzzle Medal (2)

Re: security problem

Postby mikewardbarrow on Mon Apr 11, 2011 9:17 am

what is shown is https://www.speedsudoku.com/player.php?mode=premium with everything except the speedsudoku . com grayed out
User avatar
Novice mikewardbarrow
 
Posts: 64
Joined: Tue Jul 07, 2009 5:09 pm
Location: South West England
Medals: 6
Easy Puzzle Medal (1) Medium Puzzle Medal (2) Hard Puzzle Medal (1) Very Hard Puzzle Medal (2)

Re: security problem

Postby irma on Mon Apr 11, 2011 7:30 pm

Mikewardbarrow, thank you for bringing the security alarm to our attention.

My attempt to log on the website address



confirms your information.

It resulted in the following warning:

Safari can't verify the identity of th website"ww.speedsudoku.com".
You might be connecting to a website that is pretending to be "www.speedsudoku.com",
which would put your confidential information at risk.


Show certificate - brings to the following:

www.speedsudoku.com.
Issued by: Thawte DV SSL CA
Expires: Saturday, 16 June 2012 9:59AM GMT + 10:00

*This certificate was signed by an unknown authority.



As far as I can tell, no such problems with the login on:

http://www.speedsudoku.com/public.php?mode=home

or

http://www.speedsudoku.com/.



Hope this verification is of some help achilles.
User avatar
Intermediate irma
 
Posts: 109
Joined: Mon May 18, 2009 9:14 am

Re: security problem

Postby achilles on Wed Apr 13, 2011 8:04 am

Just like what irma said above.

I believe if you log in through http://www.speedsudoku.com web address and NOT to https://www.speedsudoku.com, you should not have a security issue.
User avatar
Beginner achilles
Staff
 
Posts: 101
Joined: Thu Apr 16, 2009 8:56 pm

Re: security problem

Postby mikewardbarrow on Wed Apr 13, 2011 9:25 am

Hi Achilles
Have just tried as you suggested, and still got the same warning. I have tried going through Play - premium membership only to get the same result.

I have also tried using the Pay premium link on my wall, with the same result.

I'm due to renew my premium membership in May, but I'll not use a site that is unsafe to do so.

Any other way I can pay the $25?
User avatar
Novice mikewardbarrow
 
Posts: 64
Joined: Tue Jul 07, 2009 5:09 pm
Location: South West England
Medals: 6
Easy Puzzle Medal (1) Medium Puzzle Medal (2) Hard Puzzle Medal (1) Very Hard Puzzle Medal (2)

Re: security problem

Postby irma on Wed Apr 13, 2011 6:39 pm

It's the same here achilles.

Furthermore, clicking on the "Premium membership" listed under "Player" on the home page changes data in the browser from:

1) the Protocal - "http" to "https"
2) the file name - " player.php?mode=home" to " php?mode=premium".

resulting in the beforesaid warning.

This IS a real concern that warrants caution and a priority since it puts all members attempting to pay for the membership, as well as those using the file name "php?mode=premium" to log in - at risk.
User avatar
Intermediate irma
 
Posts: 109
Joined: Mon May 18, 2009 9:14 am

Re: security problem

Postby achilles on Thu Apr 14, 2011 11:00 pm

Just to let you know that the webmaster is already looking into this to find out what is causing this security issue.

In the meantime, does it make any difference if you use a different browser from what you are currently using?
User avatar
Beginner achilles
Staff
 
Posts: 101
Joined: Thu Apr 16, 2009 8:56 pm

Re: security problem

Postby irma on Fri Apr 15, 2011 2:43 am

Achilles,

Thank you for keeping us informed.

Using a different browser seems to make no difference.

Affected are:

1) Premium membership (listed under Player)

2) Gift Certificates (Give Premium)

3) Payment security, privacy policy, more...

all on the home page.

Clicking on any of the above will initiate a change in the browser from:


http://www.speedsudoku.com/public.php?mode=home

to

1) https://www.speedsudoku.com/player.php?mode=premium

2) https://www.speedsudoku.com/gift/

3) https://www.speedsudoku.com/forum/viewtopic.php?f=1&t=920

As the protocol changes from "http" to "https", the following warning appears:

This Connection is Untrusted

You have asked Firefox to connect
securely to http://www.speedsudoku.com, but we can't confirm that your connection is secure.

Normally, when you try to connect securely,
sites will present trusted identification to prove that you are
going to the right place. However, this site's identity can't be verified.

What Should I Do?

If you usually connect to
this site without problems, this error could mean that someone is
trying to impersonate the site, and you shouldn't continue.

Technical Details

http://www.speedsudoku.com uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer).




Trying to logging in through the Speed Sudoku: Gift Certificates had the same outcome.


Cheers and good luck! :)
User avatar
Intermediate irma
 
Posts: 109
Joined: Mon May 18, 2009 9:14 am

Re: security problem

Postby mikewardbarrow on Fri Apr 15, 2011 3:37 am

Hi Achilles

Using a different browser does not make any difference.

Thanks for letting us know someone is working on the case.
User avatar
Novice mikewardbarrow
 
Posts: 64
Joined: Tue Jul 07, 2009 5:09 pm
Location: South West England
Medals: 6
Easy Puzzle Medal (1) Medium Puzzle Medal (2) Hard Puzzle Medal (1) Very Hard Puzzle Medal (2)

Re: security problem

Postby achilles on Mon Apr 18, 2011 6:46 pm

I just got word from the webmaster and he said that there was a SSL certificate configuration problem on the server. Everything should be fixed now. Could you try again if the issue still persists for you?
User avatar
Beginner achilles
Staff
 
Posts: 101
Joined: Thu Apr 16, 2009 8:56 pm

Re: security problem

Postby irma on Mon Apr 18, 2011 9:35 pm

Achilles, just a note to let you know that everything seems to be fine. :)
User avatar
Intermediate irma
 
Posts: 109
Joined: Mon May 18, 2009 9:14 am

Re: security problem

Postby achilles on Wed Apr 20, 2011 8:42 am

Thank you Irma. ;)
User avatar
Beginner achilles
Staff
 
Posts: 101
Joined: Thu Apr 16, 2009 8:56 pm

Re: security problem

Sponsor



Return to General Discussion

Who is online

Users browsing this forum: No registered users and 1 guest