Forums

RS-Linkify Thread is sticky

Quick find code: 261-262-33-65181208

Lil Indecent

Lil Indecent

Posts: 447 Silver Posts by user Forum Profile RuneMetrics Profile
Morgan said :
Enlighten me, Indsy, because I don't know. What's taking Jagex so long to migrate the entire site to HTTPS? Isn't it as easy as installing a SSL certificate and changing a few URLs? Something that could be done in less than 2 hours.

I don't understand why they talk about it like it's a mammoth task.

Hiya Morgypie :)

Sorry for my late reply.

There is a little more too it than that. However it is taking a long time, no surprise tbh.

Two possible reasons come to mind.

Firstly non secure links, pages, APIs that Jagex have no control over. There really shouldn't be too much of that to deal with, but measures need to be taken. Mixed content is a big thing to sort out, particularly if dealing with external sources. Even within their domain there would be many things we don't see (APIs) that need to be changed.

Second thing I can think of is some of their server side stuff might not be up to date thus can't interact with modern SSL certificates. I have seen this with PHP in the past, running older versions that can't even establish a handshake with newer HTTPS standards. Then upgrading PHP breaks a million other things (seen big databases inaccessible after an update). Basically a snowball effect and it escalates really fast. Fixing one thing breaks a number of other things.

I'm not sure if the last point is an issue for Jagex but considering how old the forum software is and perhaps the OS for the server is even older, then it would be a nightmare. It just depends how vigilant they've been over the years. It would come as no surprise if they were running older code that can't work with modern standards.

Things get harder over time if left uncared for. The older the code the harder it is to migrate away from. So maybe that's slowing them down. Of course there are other reason for the delay. They might not be working on it right now, it could be on the on the back burner or even abandoned.

23-May-2018 00:42:53

Morgan

Morgan

Posts: 36,054 Sapphire Posts by user Forum Profile RuneMetrics Profile
I wouldn't be surprised if that's the case. I mean, they spend more time designing their 404 pages than giving their website and servers some proper architecture. I remember when they updated their error 404 pages... like... who even boasts about their 404 pages?!

Also, what does the ".ws" extension in some URLs mean? I've never seen a website with those. I've seen .jsp (JavaServer Pages), .jsf (JavaServer Faces), .php, .html, but never .ws.

23-May-2018 15:07:38

Lil Indecent

Lil Indecent

Posts: 447 Silver Posts by user Forum Profile RuneMetrics Profile
Not sure what the deal is with .ws extension but it is possible write your own custom file extensions in php and tell apache to treat those extensions as .php.

So somefile.mogypie will be shown as is in the address bar, but will handled by the server as somefile.php. I assume this is not unique to apache/php and other operating systems and server side languages can do the same.

One reason to do this is to help hide what language you're running and thus makes it harder to find and use known exploits. On it's own it's pretty much useless but when combined with many other security measures it can act as a decent deterrent, often hackers will be inclined to move on and look for an easier target. Determining the OS and server side language is the first step in finding vulnerabilities. I always just assumed the .ws extension was to do with hardening their security but I don't know for sure.

Yes, I remember how proud they were with their 404 pages. The only page you really don't want anyone to see or land on. All the while other issues were simply ignored, but it's all good as long as your error pages have glowing eyes. I'm surprised they didn't put some ads on it, clearly it's a heavily visited page :)

24-May-2018 11:26:39 - Last edited on 24-May-2018 11:28:22 by Lil Indecent

Sharp-shin

Sharp-shin

Posts: 41,301 Sapphire Posts by user Forum Profile RuneMetrics Profile
Lil Indecent said :
Sharp-shin said :
Yo Indy, can I have my custom title removed please? > )

Done, might take a few hours before it disappears. Hopefully by the time you see this it will have gone :)

Yep, you called it right, thank you! > )
"Volat Accipiter libera est; venandi sua natura est."
~Accipiter striatus

08-Jun-2018 06:34:43

Cyanid
Jan Member 2006

Cyanid

Posts: 24,133 Opal Posts by user Forum Profile RuneMetrics Profile
Saw an old post with my tinfoil partyhat. Good pfp, shoutout to whoever made it for me.

e: just checked it was Lust.


¸¬°™°¬¸
With
¸¬°™°¬¸
Closed Eyes
¸¬°™°¬¸
I §ee
¸¬°™°¬¸
’¸·ˆ·¸
¶¶
`»—«’
¶right¶
`•
†hrøugh
•’
¶¥øu¶
`»—«’
¶¶
¸·ˆ·¸‘

‘•»¸¸«¤°˜¯‘•¸
¶¶¶¶¶
`
¤•¤
¶¶¶¶¶
¸•’¯˜°¤»¸¸«•’

°¬_¸–’
’¸¤·¤¸‘
‘–¸_¬°

23-Jan-2019 18:05:28 - Last edited on 28-Jan-2019 12:35:59 by Cyanid

Quick find code: 261-262-33-65181208 Back to Top