Index | Recent Threads | Unanswered Threads | Who's Active | Guidelines | Search |
![]() |
World Community Grid Forums
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
No member browsing this thread |
Thread Status: Active Total posts in this thread: 6
|
![]() |
Author |
|
gQuigs
Cruncher Joined: Dec 3, 2005 Post Count: 4 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
This website uses HTTPS, but the actual BOINC communication does not appear to use HTTPS for WCG. It does for many other projects though.
If I understand correctly this means WCG can't run on newer android? (https://github.com/BOINC/boinc/issues/2466) It also does introduce an easily mitigated vector to PCs that are donating their time. |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
My latest with EMUI 11 fitted android can't. Thousands upon thousands have tagged this as wish listed.
|
||
|
gQuigs
Cruncher Joined: Dec 3, 2005 Post Count: 4 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
I noted you now have HSTS on the website indicating you take it seriously for the browser. Let's make the URL in the client HTTPS too.
|
||
|
knreed
Former World Community Grid Tech Joined: Nov 8, 2004 Post Count: 4504 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Unfortunately, the BOINC client makes this change difficult. Please see the discussion here: https://www.worldcommunitygrid.org/forums/wcg/viewthread_thread,43774
|
||
|
gQuigs
Cruncher Joined: Dec 3, 2005 Post Count: 4 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Awesome! Thanks for leading this. Newer versions can upgrade to HTTPS without issue - https://github.com/BOINC/boinc/commit/b695ca2c05c42814bd832d17134dfefd4c9969ac
Unfortunately, I just found out that BOINC has some issues with some certs since Sept 30th - see https://github.com/BOINC/boinc/issues/4530. I'd encourage people to upgrade once they release a new version -then do the transition some time after. Are you able to see what client versions are connecting? |
||
|
gQuigs
Cruncher Joined: Dec 3, 2005 Post Count: 4 Status: Offline Project Badges: ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
The Windows version 7.6.20 should make the http->https seamless.
Mac/Linux users would still have to do the detach/re-attach dance. |
||
|
|
![]() |