I think that it's high time that chipmusic.org added SSL and all traffic used secure connections. Our traffic here might not seem "important" but I think these days that all web traffic ought to be secure and it's no longer prohibitively expensive to do.

Thanks to the EFF and Let's Encrypt the process is now free and relatively easy. I've been using Let's Encrypt signed certificates on all of my websites for a while now and I'm more than happy to answer any questions about how to go about the process if any of the admins have questions.

I was going to bring this up. The ios app doesn't like connecting to insecure websites anymore.

Auto-renew on the Let's Encrypt certs is really handy too! I do a fair bit of pen-testing for work, so if there are some other issues that come up, I would be happy to assist with.

i'll bring it up in the super secert mod lobby

jeff: Currently, chipmusic.org runs on a Site5 account. There's ssh access but I believe it's managed hosting, so no access to root or global server config. According to their FAQs, LE is not supported at this time. If you have information on how to get LE working on Site5 in particular I'd be willing to listen. But otherwise, switching to a different provider is unfortunately something that neither me nor Tim has the time to do atm.

We are actually running a VPS, which should support SSL. I need to look that stuff up.

What service are you guys using? Hostgator, DigitalOcean, Linode, or something else?

Site5, but currently planning to move the site because of this discussion.

on a related note: Chrome now blocks flash, which in turn blocks the music players here (and on weeklybeats btw).  you have to right-click the container element and clck "Run this plugin" in order to play a song.  it's worse on weeklybeats because the flash widget is crammed into a 1x1 pixel area.

i know that this flash component was used mainly to avoid having to encode everything in more than just mp3 and browser wars were muddying up the possibility of just sticking with mp3.  however, http://caniuse.com/#search=mp3 shows that all browsers support MP3 now (except for Opera Mini but i'd say it's close enough).

so what's the over-under on swapping the flash player with a fully HTML5 player?  i can help source a suitable player (though it's not hard to just make one from scratch, with the <audio> element and a few well-placed JS handlers)

sorry to hijack the thread if this is too off-topic

Last edited by bryface (January 26, 2017 7:31 am)

+1 bryface.
Ok for using ssl (my CM.O account is so precious I wouldn't have it stolen), but before that I think it'd be wiser to focus developements on using html5 replay.

nitro2k01 wrote:

jeff: Currently, chipmusic.org runs on a Site5 account. There's ssh access but I believe it's managed hosting, so no access to root or global server config. According to their FAQs, LE is not supported at this time. If you have information on how to get LE working on Site5 in particular I'd be willing to listen. But otherwise, switching to a different provider is unfortunately something that neither me nor Tim has the time to do atm.

I'm not familiar with the specifics of that host but looking at the FAQ it seems to use SiteAdmin or cPanel? Both have some form of SSL Manager in the options that'll let you upload and configure your SSL/TLS. Most managed hosting doesn't allow you to directly touch Apache/server configs but the management interface almost always allows SSL/TLS configuration.

Forcing https:// is just a few simple lines in your .htaccess, something like this:

RewriteEngine On
RewriteCond %{SERVER_PORT} 80
RewriteRule ^(.*)$ https://chipmusic.org/$1 [R=301,L]
bryface wrote:

so what's the over-under on swapping the flash player with a fully HTML5 player?  i can help source a suitable player (though it's not hard to just make one from scratch, with the <audio> element and a few well-placed JS handlers)

I built my website's music player on jPlayer and it's API is both comprehensive and logical. It requires jQuery, so if you prefer plain js then you'd want to look elsewhere.

Last edited by jefftheworld (January 27, 2017 3:01 am)

I like how you guys still care for the site despite low activity. Keep it up guys, there's plenty of good tips in here (Just hoping all the information  in the threads dosen't get lost like 8bc)