[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Array to string conversion
[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Undefined variable: Array
[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Array to string conversion
[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Undefined variable: Array
[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Array to string conversion
[phpBB Debug] PHP Notice: in file [ROOT]/includes/functions_content.php on line 77: Undefined variable: Array
thatBreweryGame.com • View topic - Going Secure!
Page 1 of 1

Going Secure!

PostPosted: Sun Apr 06, 2014 6:33 pm
by Robc
TBG has become a fully secured website! The new security certificates that I have installed were once recommended for use only on websites that handle secure and confidential transactions. And while very little of what we do in game falls in this category, I have nevertheless made the decision to bring us under the protection of an SSL certificate. Why?

1) Many major sites are taking this step. The way was led by Google, Facebook, Twitter, and most other Social Network sites to encrypt all content and use only secure connections.
2) Players have advised me that some work places now block all websites that aren't under the protection of an SSL seal.
3) Many people feel more secure and are more willing to trust a website that is protected, we get additional legitimacy.
4) This paves the way for streamlining label credit purchasing, we can handle secure transactions now. Doing so is both more secure and more convenient for everyone. It is more secure because our encryption algorithms are more powerful and after the transaction we do not save any user financial information whatsoever on our server. An example of convenience for you is that we will soon have more payment options other than Paypal and purchases will be possible without having to navigate a cumbersome online store.

What does it all mean and what is the down side? It means that when you come to TBG pages from now on you will be transfered to our secure content, you will see https:// as the start of all web urls and all content exchange between your browser and our server is encrypted. Encryption uses additional bandwidth and takes up some of the server's processing power. The overhead should be minimal and our server is barely using 5% of its capacity so there should be no slow downs at all. If there is an impact to players it will most likely affect our oversea's players more than domestic (Our server is in Chicago, USA). Your first connection to the site could be slower as encryption methods are negotiated between your browser and the server. Although I don't expect any issues whatsoever in normal game play, if anyone overseas does experience a problem then let me know immediately because we may be able to mitigate it.

Another down side is simply that some of the older code on our site might not yet play well under SSL, I will over time find and ferret out any problems and solve them. Just let me know.

It means that most pages of our website will now be adorned with one of the following seals (note that the images below are copies and are not linked, the actual seals will be at the bottom of the page).

Image
Image

If you don't see the seal the page is still protected, it just means I haven't installed the seal yet on that page or there isn't enough room. As long as you see a small lock image in your browser url and the url starts with https:// then you know the pages are protected. You can click on the seal at anytime to see the status of our secure connections/pages.

Lastly, this is my first experience using SSL web pages. Please be patient and let me know if you experience problems. I am a fast learner and I will solve problems as fast as I can. Thanks for being my eyes and ears and I hope that this update makes everyone feel even better about playing TBG.

Re: Going Secure!

PostPosted: Thu Apr 10, 2014 2:29 pm
by Robc
I know that most of you are not into internet programming or website security but I would like to share the following link. The announcement of this security breach just a couple of days ago has left the web development world stunned. Even if you don't want the technical details, this is a problem for everybody to know about since it affects so many critically important websites.

http://www.newyorker.com/online/blogs/e ... bleed.html

I want also to state that TBG is not and was never vulnerable to the bug. This bug only affects 'secure' websites and we only became a 'secure' site a few days ago, so the two years mentioned in the article are not relevant to our servers. But what is relevant is what happened after we installed our security certificates. I have checked with our certificate provider and have had our site independently checked by a third party security assessment firm and TBG is NOT vulnerable to heartbleed attacks so your passwords and other data are safe here. Our installed version of OpenSSL was already patched with the fix when we started using it. But it was a close call to be sure. Until this bug was discovered the hallmark green padlock and https:// security protocols were considered sound as a rock, I am hopeful that confidence can soon be restored as websites around the globe are rapidly being patched as we speak.

I will be announcing a new online store either today or at the latest in the next couple days. I will mention in that announcement even more safeguards that will be in place in regards to payments and transactions. If you are thinking about buying label credits right now then wait a day or so and it will be much easier.

Re: Going Secure!

PostPosted: Fri Apr 11, 2014 6:14 pm
by gray75th
Are we there yet? LOL! I am itching to get some creds.

Re: Going Secure!

PostPosted: Fri Apr 11, 2014 8:48 pm
by Robc
The new store is up and running! So don't hold back anyone, thanks for supporting the game!