Jump to content

NotHereToPlayGames

Member
  • Posts

    7,599
  • Joined

  • Last visited

  • Days Won

    100
  • Donations

    0.00 USD 
  • Country

    United States

Everything posted by NotHereToPlayGames

  1. You can disable mixed content by using command line switches. I recommend all 360Chrome users to learn how to use command line switches. https://peter.sh/experiments/chromium-command-line-switches/
  2. For kicks, I went to Firefox's addons site and right there near the top is Ghostery (1.1 million users), Privacy Badger (0.9 million users), HTTPS Everywhere (0.7 million users), and DuckDuckGo Privacy Essentials (1.4 million users). Read those privacy policies! I wouldn't trust DuckDuckGo any more than Google! When EVERYTHING that you type in the address bar is sent to a DuckDuckGo server, I don't care that they claim they don't "save" that data, the fact remains that the data was sent to them, their computers analyzed that data, and they save the "analysis" even if they don't save the "data" that led to the "analysis". Or something like that...
  3. It's more common than you might think! Firefox and Chrome extensions/addons both do this. "Some" users think it's a good thing, the extension needs to "collect" data in order to "improve". "Most" users have no clue.
  4. Cool. Did you notice that you can click on the Google teapot and it pours tea? But you can't click again to get it to stop pouring.
  5. It is a time zone update for me. My State used to have its own Time Zone. When you install XP, you can select my State. But that went away with Win7 and now it's Eastern Time Zone or Eastern Daylight Time Zone - d@mn "spring forward, fall back" bu!!sh!t we have to do twice a year! So yeah, my 360Chrome is off one hour for 6 months of the year.
  6. Wow! He joined this forum and that is his very first post (and only, so far).
  7. When I click the License agreement link at the bottom, it takes me to here --
  8. I think so, absolutely! I use it on my financial accounts! But "safe" is also always a 'relative' term. Ask an Amish person if YouTube is "safe to log into". I would personally suggest doing a little compare/contrast and witness web browser traffic yourself. For WinXP, grab a copy of Wireshark Portable version 1.10.14 (last version to work under XP) from here -- https://2.na.dl.wireshark.org/win32/all-versions/ Or NetworkTrafficView by NirSoft from here -- https://www.nirsoft.net/utils/network_traffic_view.html Or DNSQuerySniffer also by NirSoft from here -- https://www.nirsoft.net/utils/dns_query_sniffer.html DNSQuerySniffer is probably the "easiest". Turn it on, open the browser that you "used to use" when you logged into YouTube, grab a screencap or select-all and copy-paste into a txt file. Now repeat the same task with 360Chrome then compare the two logs.
  9. Great Find! I normally have View Signatures turned OFF in my profile settings but toggling it to ON (temporarily, it will remain OFF as my default) did show MSFN as "insecure" for the threads with the referenced signature.
  10. Guess I'll know more in a little over a month - below is a screencap of MSFN's Cert Info when I click on the (d@mn [apoligies for that "insert"]) "green padlock". I've done NOTHING "intentionally" between 2018 and 6/21/2021 where MSFN's Cert Info lists the start date for when it is "valid from" - so where did this come from as I didn't "install" it? I'll also do NOTHING "intentionally" after 9/19/2021 when MSFN's Cert Info says it will expire - but now I have a logged screencap where I can see what happens with this (d@mn [crap, there I go again!]) "green padlock" on 9/20/2021. I still feel that POS updates are somehow responsible for "breaking" other XP-users certificate stores - I cannot prove this, but it is my gut feeling.
  11. I sure as Hades hope that my system is *NOT* updating them on its own! If I find that it IS, I will put a stop to that immediately! I do not like anything on this computer performing "updates" of any kind, certainly not "automatically and behind my back without me knowing it". My slipstreamed-XP is dated 2018 (I provided the link several posts up). I do not "revoke" certificates so every certificate that existed in 2018 should still be in my "store". I really can't express it any plainer - the "green padlock" system is FLAWED and is nothing more than a false sense of security. I spend zero time on my end trying to make sure that a flawed system is updated. I don't really know how to check my "store" either - but can't really claim to "care to" either. But, for the sake of this "obsession" that MSFN members are having all of a sudden, if anybody needs me to see if I have a specific cert in my "store", give me details on how to find it and I will gladly hunt it down. Otherwise, to the very best of my knowledge, my cert "store" hasn't changed since 2018. I think that 360Chrome has its own "store" in addition to those from 2018 that are part of XP. But like I have stated, several times, it doesn't really concern me. I am VERY thankful that my NoScript, uMatrix, and Stylus are all doing their jobs. Signature lines are axed by Stylus so signature lines aren't "breaking" that green padlock for me - nice to know, but doesn't really concern me.
  12. Well, since you asked -- I DON'T ! I install my slipstreamed-through-2018 XP and I'm on my merry way. If those slipstreamed hotfixes update certs, so be it, doesn't concern me. I have my web browser settings set to NOT "check for revocation" - if the OS does external to the browser, so be it, doesn't concern me. "Not for everyone", but I personally don't give a rat's a$s if my web browser shows a green padlock or not! And to all that "disagree", do not "lecture" me on this course of action - this is my computer, not yours, and I have my own methods of knowing what web site is "secure" or not. As I have pointed out before, and linked articles to, even fake and identity-stealing web sites know how to get that "green padlock" to show up on their "secure" web site! It honeslty ASTOUNDS ME on the number of people that are "chasing their tail" over whether a green padlock is being shown in this browser versus that browser, this OS versus that OS. But since it is pretty much the "only" topic (I'm exaggerating - "slightly") of late here at MSFN and that I enjoy the people and content here at MSFN, here I am caught up in all of this hoopla. If I create the atmosphere where I "habitually" look for a green padlock, then I've created a FALSE sense of "security" that is NO LONGER savvy enough to detect fake and identity-stealing web sites that know how to get that "green padlock"!
  13. Maybe not in "that" post, but I thought that I did previously discuss that I have never manually installed any certificate that didn't come directly from Microsoft by way of a "KB" hotfix. And since I don't use the POS hack, then that also means I don't have any certificate updates that were never pushed via Windows Update to "real" XP. I'm not familiar with @legacyfan's (?) "cert pack" but it's not my practice to install stuff like that. There might come a day where I will "have" to have something like that, but that day hasn't arrived yet.
  14. Nope. I prefer to "slipstream" all of my updates. That way I am fully updated after a 30min install as opposed to spending 30min to install than 4hrs to update.
  15. Does SP4 and post-SP4 have anything specifically labeled as related to "certificate updates"? Can you pull those out or unstall just that portion of SP4 and post-SP4? Which makes you feel most "secure" -- a green padlock in your web browser or having POS updates? I work with roughly 120 robots at work that all run XP Embedded. They all have POS updates because Microsoft Updates rolls/rolled those out to XP Embedded without any registry hacks that would have flagged not only local IT, but the IT departments on three different CONTINENTS and would have resulted in a Termination Notice. But NONE of those robots have INTERNET access. Intranet, yes... but no internet access!
  16. Update -- as I dig deeper, POS updates are listed in the IE8 Addon starting with 1.5.31. So it turns out that my XP x86 XP3 does have a very small handful of POS updates.
  17. Not sure how this progresses the conversation any, but ALL of those sites listed above show as "secure" for me in v13 360Chrome build 2206, Mypal 27.9.4, NM27, NM28, Basilisk, and BNavigator. And show as "secure" on my XP x86 SP3 and my XP x64 SP2. So something in your "SP4" or your "post-SP4" broke something. I have neither of those installed on my XP x86 SP3. My XP x86 XP3 is built from this -- XPSP3_QFE_UpdatePack for Windows XP Post-SP3 20180109 ... and this -- [Addon] Internet Explorer 8 for 32-bit XP 1.5.42 HOWEVER, my install DVD says that I used IE8 1.5.38 and it has since been updated to 1.5.42. The differences being -- Version 1.5.42 2018-09-17 —5eraph Added KB4457426, replaces KB4343205. Version 1.5.41 2018-08-19 —5eraph Added KB4343205, replaces KB4339093. Version 1.5.40 2018-07-15 —5eraph Added KB4339093, replaces KB4230450. Version 1.5.39 2018-06-13 —5eraph Added KB4230450, replaces KB4103768. KB4230450 == POSReady... I do not install POS... https://www.catalog.update.microsoft.com/Search.aspx?q=KB4230450 KB4339093 == POSReady... I do not install POS... https://www.catalog.update.microsoft.com/Search.aspx?q=KB4339093 KB4343205 == POSReady... I do not install POS... https://www.catalog.update.microsoft.com/Search.aspx?q=KB4343205 KB4457426 == POSReady... I do not install POS... https://www.catalog.update.microsoft.com/Search.aspx?q=KB4457426 I strongly suspect, and I'm not trying to start a lengthy debate, but all the facts seem to point to this -- POSReady2009 is what broke your security certificates! I think that's where we need to start next -- to everyone that is seeing MSFN as "insecure" when using Chromium-based browsers on XP x86 SP3, did you install POSReady2009 hotfixes? Again, I am trying to help, so I hope it is coming across that way.
  18. I can't help but be curious (and at the risk of opening Pandora's Box but in the spirit of leaving no stone unturned) - 360Chrome was developed, at its core, to backport browser functionality specifically to XP. So I guess I find myself of little-to-no surprise that 360Chrome is showing sites as "secure" when in XP but "mileage may vary" when that browser, designed for XP, is tested in Vista and 10. So why even run 360Chrome in Vista or 10 when there are "non-backport" browsers available on those platforms? Vista I kinda get, it too is an "expired" OS. Please don't misread, I'm asking because I am curious. Is it because XP has a larger following than Vista and nobody out there is "backporting" specificly for the Vista Audience? Forgive the curiosity, I'm just trying to place myself in your shoes - my shoes are XP so I understand the path that I walk in those shoes. edit - although, having asked that question, I should also disclose this -- I run Mypal 27.9.4 on my work computer and it runs Win10 x64, I do that for RAM/CPU purposes and for "lighter" extensions.
  19. And your profile says Win10 x64. Ecosia and Discord both show as "secure" for me (XP x64 SP2, v13 360Chrome build 2206). So this really is just another example of where the same exact browser gives different results in different operating systems. Unless I am missing something, that still points to the OPERATING SYSTEM and not the browser. Let's try a different route (I am trying to be of assistance, honestly!, despite my personal conviction that a brower's "padlock" reveals NOTHING about my level of "security", it's a girl in the forest cyring wolf when there is no wolf or crying fire in a movie theater when there is no fire or a car alarm that is set off by a cat sniffing the tire - to each their own, different strokes for different folks). 360Chrome is based on Chrome v86 and this dated October 2020. So what happens for Vista and Win10 for Firefox version 80.0.1 (released September 2020). ie, does a Firefox version release around the same time as Chrome v86 show the same results?
  20. Tracked down and reloaded my Vista VM. It's dated 2019 and official Vista support ended in 2017, so it "should" be fully updated - but I am not 100% on this as I use my Win7 VM much more than my Vista VM. At any rate, here are some findings (these are from v13 360Chrome build 2206 when on Vista VM) -- MSFN == insecure connection Wikipedia == insecure connection Google == insecure connection Roytam's rtfreesoft blog == insecure connection Chromium woolyss (source for ungoogled-chromium) == insecure connection browseraudit.com (a recent test site of recent rave) == insecure connection Base Mark 3.0 (another common test site) == insecure connection microsoft.com (I find this one particularly funny) == insecure connection cloudfare.com == insecure connection mozilla.org (equally funny) == insecure connection linkedin.com == insecure connection adobe.com == insecure connection msn.com == insecure connection reuters.com == insecure connection opera.com (browser download, not a fat lady singing) == insecure connection cnn.com == insecure connection bbc.com == insecure connection nytimes.com == insecure connection bloomberg.com == insecure connection washingtonpost.com == insecure connection ALL of the above show as "secure" in v13 360Chrome build 2206 on XP x64 SP2. ALL of the above show as "secure" in Serpent/Basilisk v52.90 (2021-07-30) when on Vista VM - but as insecure in v13 360Chrome build 2206 when on Vista VM (despite being "secure" on XP x64 SP2). Not sure "where" that gets us, but I offer it to the discussion at hand.
  21. You site that MSFN shows up as "insecure" but did you comapare to ANY other browser? Did BOTH browsers say "insecure" or did only ONE? I will try to expand on my view of this issue - I am not always the best at communication "skills" but we all have our days, lol. I seem to be in the minority but that does not make me "wrong", please allow me to explain because SSL has become a GIGANTIC topic of late here at MSFN. So your browser is claiming to be "insecure" on MSFN and the solution isn't some form of "I can not log in because I can not trust MSFN" but rather "What modifications can I make to my operating system or browser for MSFN to 'appear' "secure" "? To the point of users creating "cert-packs" and moderators yanking them for MSFN Rule Violations -- seriously, ponder that for a second. Isn't this the EXACT OPPOSITE of "secure" -- to blindly trust an MSFN forum member that created their own "solution" then publicly distrubuted it for others to install onto their computers? My official XP x86 SP3 and my official XP x64 SP2 both show MSFN as "secure". So if another user on a different XP says "insecure", that basically tells me that the user broke something - installed some "cert-pack" that I did not, installed POS updates that I did not, hacked their kernel that I did not, et cetera. They may have had the best of intentions, but the end result was that they broke something when they inteded to try to fix something. But you still cannot deny that my XP says "secure" and the hacked-with-best-of-intentions version of XP says "insecure". Maybe the hack was to get YouTube to show as secure and the hack fixed that - but broke MSFN. So is that hack to be trusted or not (I'm on the not-side). Your profile cites Vista Business x64 -- can you install a brand spanking new VirtualBox VM and see if it shows MSFN as "secure"? That would reveal that something is "broken" in your host Vista. Generally speaking, to me at least, when a web browser says "insecure", it is NOT the web browser that is "insecure", it is the OPERATING SYSTEM. That is, unless I can show a DIFFERENT web browser on the SAME computer to show "secure" - which I'm not 100%, but I don't think I've ever witnessed that scenario. Hope that helps.
  22. I do know that the "anti-tracking" feature (which I do not use) is offset by 24hrs and I have fixed this in my release and pointed it out to Humming Owl for his release. Aside from that, my "history" page is off by ONE HOUR but the month/day/year is correct. Had'nt noticed that ONE HOUR difference until just now.
  23. We kind of need an example link to go anywhere with this.
×
×
  • Create New...