• Welcome to Smashboards, the world's largest Super Smash Brothers community! Over 250,000 Smash Bros. fans from around the world have come to discuss these great games in over 19 million posts!

    You are currently viewing our boards as a visitor. Click here to sign up right now and start on your path in the Smash community!

Smashboards Update - SSL and You!

Around a month ago we made a very important change to the way Smashboards is accessed by all of our users. This change should have been completely transparent and generally unnoticed but there were a couple bumps along the way.


Smashboards is now accessed over https, or SSL. This means that your connection and traffic on Smashboards is encrypted between you and our server.


A few technical restrictions prevented us from rolling this out sooner, but we're very glad to finally give our users this additional layer of security.

An important aspect of this change is that all content on the site must be served over https from Smashboards. Some of you may have noticed an issue with images related to this. There were two factors for this issue.


The first factor: Due to the above limitation, all images and links have to be proxied through Smashboards. A misconfiguration during the initial rollout caused some images to fail to be grabbed by the server.

The images affected by this were attachments and off-site images over 5MB. The first issue has been fixed, and the size limit has been temporarily been increased to 20MB. This size limit may be decreased in the future back to 5MB or 10MB, so we recommend you compress any large images in your posts or convert any gifs to more modern and efficient video formats. As well, any services that disallow image hotlinking will fail to be grabbed. In the past, these images already did not work, but since you had already seen it it would appear to embed fine, but only for you.


The now dreaded image failed to load icon

The second factor: The amount of images that would be proxied from this change was underestimated. Smashboards previously was storing uploaded file attachments, avatars, event graphics, rankings bracket images and news article images with some of these things dating back for years. Adding proxied images to this list more than doubled the necessary filespace required overnight.

This was unexpected and as a result some images may have failed to be grabbed by the server when allocated space ran out and will not be a problem moving forward.

I apologize for the inconveniences during this update but it was an important change to make for the security of our users and it will allow for performance improvements going forward as well!

----------

On a closing note, October is National Cyber Security month in the US! As a reminder to all our users, your password on every website and service should be different. The password you use on Smashboards should be totally unique and not used anywhere else! This can be a daunting task of course, and there are very useful, trusted tools to handle this process for you like LastPass and KeePass.

Updating your password periodically is also generally recommended, so be sure to do that once in a while too! You can do so right now on your Account Security page.
 
Warchamp7

Comments

The Electronic Frontier Foundation has a great browser extension that requests HTTPS at all times. You don't always get HTTPS, but you automatically ask for it regardless. It's free software in both senses of the word (gratis, free as in beer, and libre, free as in speech)

The W3C is considering requiring HTTPS for all traffic and deprecating "normal" unsecured traffic in future versions of the HTML standard. I can only hope that it ends up happening, as the current method where servers will sometimes fall back from HTTPS to HTTP over a bad connection leaves users vulnerable to man-in-the-middle attacks.
 
Using HTTPS and SSL is indeed a good move. I like it. This should help security on the boards, here.

The Electronic Frontier Foundation has a great browser extension that requests HTTPS at all times. You don't always get HTTPS, but you automatically ask for it regardless. It's free software in both senses of the word (gratis, free as in beer, and libre, free as in speech)
I'm glad I'm not the only one who has interest or at least knowledge in free software in terms of libre and gratis. I might check that browser extension out.
 
Top Bottom