What is this?

  • Lapiz
    6th Jul 2015 Member 1 Permalink

    I just recently got to knew the existance of the Powder Toy.

     

    When I registered an account, my Computer said that the site was dangerous (Your security is at risk). Is their anything with the site? All of my setting (PC/Web Browser) are default.

     

    I had to create a certificate to register.

     

    Is the site really suffering from a security risk? Or is it the Creator's mistake?

     

    Thank you in advance.

    Edited 2 times by Lapiz. Last: 6th Jul 2015
  • mniip
    6th Jul 2015 Developer 0 Permalink
    Could you get a screenshot of the certificate message you're describing?
  • boxmein
    6th Jul 2015 Former Staff 1 Permalink
    @Lapiz (View Post)
    We've known that the site's HTTPS certificate is a bit broken in that some computers don't trust it.

    There's a chain of trust going from powdertoy's SSL certificate up to a select few called "certificate authorities". Their certificates are automatically trusted on all computers, which also means that all certificates they sign can be trusted. They're the authorities on which certificates are good or not.

    Except, your computer has forgotten that TPT's specific certificate authority is real, so it can't really check if TPT can be trusted. This throws up many red flags because that usualy means someone hasn't bothered to get a true certificate from an authority and might be attacking your computer. In this case, you can go get the authority's certificate yourself from GeoTrust's website https://www.globalsign.com/support/installcert.php . This means you aren't blindly trusting TPT to not be under attack, but at the same time are making sure you can use TPT's login safely.

    Otherwise, if you're good at reading hexadecimal, check that the certificate TPT is sending you has the fingerprint of
    19:28:30:9F:47:A6:39:72:79:1C:A6:54:4D:0E:39:33:2A:50:3E:F5:5F:2D:42:6E:68:3B:32:97:F2:65:CD:2C

    Edited once by boxmein. Last: 6th Jul 2015
  • Mrprocom
    6th Jul 2015 Moderator 0 Permalink
    @mniip (View Post)
    I couldn't get it to give me the warning message, but I assume that it looks like this: https://techiecode.files.wordpress.com/2013/05/cibm_certificate_chrome.png?w=520&h=245

    I remember it used to give me a lot of these whenever I visit the login page.
  • jacob1
    6th Jul 2015 Developer 0 Permalink
    @Lapiz (View Post)
    I told Simon about it and he fixed it. There was never really a security issue, the server was just setup wrong.
  • Alt-Factorial
    7th Jul 2015 Member 0 Permalink

    Lel I had the same problem when registering