Contact Us/Help!
Handle:
Password:
Forget Your Password?    Join for FREE!
Humaniplex
KY
74 blogs/204 comments
since Mar 18 2008

Level 2
AttributeLevel
Overall2
Safety2
Compliance3
Integrity3
Reliability2
Karma3
See Photo Albums
Welcome to 2020 Part 2
Dec 26 2019 04:46PM more by Humaniplex
Tags: Technical Site Stuff

Happy holidays!

Apologies for the delay, we have been working hard to track this down.

First, to address some of the concerns that members of our community have expressed, we DO use SSL via a secure certificate directly issued by Thawte (do a Google search for Thawte if that is meaningless to you).

Second, we do NOT have any of your personal information. We don't even track or analyze browsing habits haha.

We obviously need to have your email address for recovery and alert purposes. But that is the extent of any information that we have about our users.

We believe is frank honesty, and to that end, we do not know what occurred. Nothing that we have seen during the course of investigation indicates that there is any sort of active security breach. It possibly looks like a very old breach from a few years ago, from what we are seeing.

None of your financial information has ever been in our possession, which is why we use third party processors that are much bigger operations with larger resources than we have.

We do encourage you to update your recovery email addresses (we suggest dedicated email addresses, they are free from basically any service on the planet) and updating your passwords just in case.

We will continue to investigate and report back. In the meantime, please enjoy the holidays!
      
There are 19 comments on this blog.
notsofast
OC, CA
92 blogs/4240 comments
since Mar 12 2007

Level 4
AttributeLevel
Overall4
Safety4
Compliance3
Integrity4
Reliability4
Karma4
See Photo Albums
Dec 26 2019 04:58PM     link to this

Thanks for the update...
nerdvana
Carlsbad, San Diego, CA
1 blogs/57 comments
since Jan 2 2019

Level 1
AttributeLevel
Overall1
Safety2
Compliance1
Integrity0
Reliability0
Karma2
See Photo Albums
Dec 26 2019 05:26PM     link to this

Your server cert is valid, but your installation is incomplete. Do a check using qualys or sslchecker or even digicert (https://www.digicert.com/help/).

You are missing your intermediate certificate and therefore people are connecting to this site unsecured. If you do not have a padlock next to the URL in your browser, then you are not connecting via TLS.

TheRealGuido
Dana Point, OC, CA
1111 blogs/6012 comments
since Jun 20 2007

Level 5
AttributeLevel
Overall5
Safety5
Compliance5
Integrity5
Reliability5
Karma5
See Photo Albums
Dec 26 2019 05:30PM     link to this

I have a padlock next to the url.

flash911
SFV, LA, CA
44 blogs/1324 comments
since Jul 23 2009

Level 2
AttributeLevel
Overall2
Safety3
Compliance3
Integrity3
Reliability3
Karma3
See Photo Albums
Dec 26 2019 05:41PM     link to this

Quality hosting provider, Firewall and Sitelock (or other anti-scripting tool) if possible.

That's about all you can do.
flash911
SFV, LA, CA
44 blogs/1324 comments
since Jul 23 2009

Level 2
AttributeLevel
Overall2
Safety3
Compliance3
Integrity3
Reliability3
Karma3
See Photo Albums
Dec 26 2019 05:43PM     link to this

@TheRealGuido -> padlock = Current SSL cert.

Looks good to me.
nerdvana
Carlsbad, San Diego, CA
1 blogs/57 comments
since Jan 2 2019

Level 1
AttributeLevel
Overall1
Safety2
Compliance1
Integrity0
Reliability0
Karma2
See Photo Albums
Dec 26 2019 05:56PM     link to this

check the report https://www.ssllabs.com/ssltest/analyze.html?d=www.humaniplex.com

there is a misconfiguration with the web server and there is a missing intermediate certificate. This means some people will not be able to connect securely. This check is skipped in some browsers (chrome and Firefox do not skip this btw). It is also possible that some of you have a cached copy of the intermediate cert on your system, thus allowing you to connect securely.

bottom line is, the web server is missing config to explicitely link the intermediate cert with the server cert and the signing CA.

This is my last comment on the topic. The admins can choose to ignore this, or they can go to the digicert site and look at this page that give them easy to follow directions on how to resolve this issue

https://knowledge.digicert.com/solution/SO15690.html
GoBallsDeep
Fullerton, OC, CA
152 blogs/11237 comments
since Dec 12 2019

Level 0
AttributeLevel
Overall0
Safety1
Compliance1
Integrity1
Reliability1
Karma1
See Photo Albums
Dec 26 2019 11:16PM     link to this

^^ what he said
Something def wrong with your cert causing loss of secure connection.
Doesn't mean it's the reason for this breach
But could be for the next one
Also, no doubt you have each discrete users ip address which leads to other info
wyatt
Miramar, San Diego, CA
0 blogs/175 comments
since Aug 25 2008

Level 0
AttributeLevel
Overall0
Safety0
Compliance0
Integrity0
Reliability0
Karma0
See Photo Albums
Dec 27 2019 09:17PM     link to this

Not to be a stick in the mud , there is ALWAYS a Broken Arrow file Hidden deep to be discovered.
All websites have them , kinda like a get outa jail free card. Just ask Ashley Madison
mjcjmjcj
Burbank, SFV, LA, CA
24 blogs/8667 comments
since Jul 20 2013

Level 3
AttributeLevel
Overall3
Safety3
Compliance3
Integrity3
Reliability3
Karma3
See Photo Albums
Dec 27 2019 09:54PM     link to this

Nerd, according to that ssllabs link you provided, there is one intermediate cert, "Thawte TLS RSA CA G1", that is not on the HX server, but is an "extra download". The link you provided says it works properly under Mozilla, Apple, Android, Java, and Windows.

The grade HX gets is a B because of this.

Hardly seems like this missing intermediate cert is causing people to not be able to connect using HTTPS to HX.


HX, can you go ahead and add this additional cert? Seems pretty easy to do. Then you can get a nice shiny A grade. Well until next month when your support for TLS 1.0 and 1.1 knocks it back down to a B.


^Written by my company's IT guy.
GoBallsDeep
Fullerton, OC, CA
152 blogs/11237 comments
since Dec 12 2019

Level 0
AttributeLevel
Overall0
Safety1
Compliance1
Integrity1
Reliability1
Karma1
See Photo Albums
Dec 27 2019 10:02PM     link to this

Is everybody in your company a member?
nerdvana
Carlsbad, San Diego, CA
1 blogs/57 comments
since Jan 2 2019

Level 1
AttributeLevel
Overall1
Safety2
Compliance1
Integrity0
Reliability0
Karma2
See Photo Albums
Dec 27 2019 10:16PM     link to this

@mj, you do not know what you are talking about - the missing intermediate cert is a big deal and can lead to some people not making a secure connection. The missing cert also prevents the admins from enabling other security features, features like HSTS, which should also be enabled.
mjcjmjcj
Burbank, SFV, LA, CA
24 blogs/8667 comments
since Jul 20 2013

Level 3
AttributeLevel
Overall3
Safety3
Compliance3
Integrity3
Reliability3
Karma3
See Photo Albums
Dec 27 2019 10:30PM     link to this

Lol, you provided the link. Now you don't like what the link says?

Can you point out one thing in my comment that is incorrect?
nerdvana
Carlsbad, San Diego, CA
1 blogs/57 comments
since Jan 2 2019

Level 1
AttributeLevel
Overall1
Safety2
Compliance1
Integrity0
Reliability0
Karma2
See Photo Albums
Dec 28 2019 08:51AM     link to this

@mj

"Hardly seems like this missing intermediate cert is causing people to not be able to connect using HTTPS to HX."

the missing cert IS causing some people to not connect securely.

If a simple thing like not configuring your web server properly with the needed intermediate cert, what else is misconfigured?

Turns out just about everything is misconfigured here. Take a look at the security scan from https://pentest-tools.com/website-vulnerability-scanning/website-scanner.
nerdvana
Carlsbad, San Diego, CA
1 blogs/57 comments
since Jan 2 2019

Level 1
AttributeLevel
Overall1
Safety2
Compliance1
Integrity0
Reliability0
Karma2
See Photo Albums
Dec 29 2019 11:17AM     link to this

^^ ok boomer
mjcjmjcj
Burbank, SFV, LA, CA
24 blogs/8667 comments
since Jul 20 2013

Level 3
AttributeLevel
Overall3
Safety3
Compliance3
Integrity3
Reliability3
Karma3
See Photo Albums
Dec 31 2019 02:45PM     link to this

"2 - random guy nerdvana who rarely posts trys to help
3 - asshole "insiders" come out and talk shit and put him down

maybe try a having a little friendly manners and encourage people to participate"


I tried discussing with Nerd the report he linked to and actually agreed with him that HX should fix the intermediate cert issue, but all he could do is personally attack me and say I don't know what I'm talking about.

You would describe that as trying to help, not putting people down, having friendly manners, and encouraging people to participate?
Latnmn30
CA
17 blogs/358 comments
since Jun 7 2013

Level 2
AttributeLevel
Overall2
Safety3
Compliance3
Integrity1
Reliability2
Karma3
See Photo Albums
Jan 9 2020 08:21AM     link to this

Just received a similar email today from a so called. "Elizabeth"
Funtimes69
San Diego, CA
1 blogs/5 comments
since Nov 17 2013

Level 0
AttributeLevel
Overall0
Safety0
Compliance0
Integrity0
Reliability0
Karma0
See Photo Albums
Jan 9 2020 02:08PM     link to this

Just received a similar email today from a so called. "Elizabeth"

Same here and also to my old deleted accounts.
Robustboy
Hollywood, LA, CA
14 blogs/162 comments
since Aug 22 2014

Level 3
AttributeLevel
Overall3
Safety4
Compliance0
Integrity3
Reliability3
Karma4
See Photo Albums
Jan 9 2020 03:11PM     link to this

Yep. Got an email too today from Elizabeth. However it was to my “parent” yahoo account referencing my yahoo account that links to hx
GoBallsDeep
Fullerton, OC, CA
152 blogs/11237 comments
since Dec 12 2019

Level 0
AttributeLevel
Overall0
Safety1
Compliance1
Integrity1
Reliability1
Karma1
See Photo Albums
Jan 9 2020 10:04PM     link to this

Elizabeth is great!
You should respond back to set up a meet!
There are 19 comments on this blog.