Jump to content

Wikipedia:Reference desk/Archives/Computing/2018 July 17

From Wikipedia, the free encyclopedia
Computing desk
< July 16 << Jun | July | Aug >> July 18 >
Welcome to the Wikipedia Computing Reference Desk Archives
The page you are currently viewing is an archive page. While you can leave answers for any questions shown below, please ask new questions on one of the current reference desk pages.


July 17

[edit]

Browser Security

[edit]

Have I been Hacked? I received a pop-up while on Wikipediathat says: Your Browser's Connection Security is Outdated ________________________________________ English: Wikipedia is making the site more secure. You are using an old web browser that will not be able to connect to Wikipedia in the future. Please update your device or contact your IT administrator. ________________________________________ We are removing support for non forward secret ciphers, specifically AES128-SHA, which your browser software relies on to connect to our sites. This is usually caused by using some ancient browsers or user agents like old Nokia smartphones or Sony Playstation3 gaming consoles. Also it could be interference from corporate or personal "Web Security" software which actually downgrades connection security. You must upgrade your browser or otherwise fix this issue to access our sites. This message will remain until Aug 1, 2018. After that date, your browser will not be able to establish a connection to our servers at all. See also the HTTPS Browser Recommendations page on Wikitech for more-detailed information.

I have Safari Version 11.1.2 (12605.3.8.1) MacOS Sierra Version 10.12.6

Is this message legitimate? Does it apply to me? Where can I get useful info on this? Is this the correct place to ask this question? 72.234.59.29 (talk) 02:07, 17 July 2018 (UTC)[reply]

  • The message complains about your browser trying to create a secure connection (HTTPS) using an old, outdated cryptographic protocol likely to be broken (hence not secure at all). It is virtually certain that Safari 11.x has support for newer ciphers (unless you played with it - any weird addons installed?) so something sounds fishy.
I see two possibilities, neither of which strike me as probable. One is that the WP server is somehow misconfigured (it could happen) in which case you should go to WP:VPT. Another is that someone is pulling a downgrade attack between you and the server. Which network are you accessing Wikipedia from? TigraanClick here to contact me 17:20, 17 July 2018 (UTC)[reply]
I see the hostname for your IP is "udp002833uds.hawaiiantel.net" and it looks like a static IP assigned to Hawaiian Telcom. This suggests to me a simply home internet connection. Am I right? If so who owns or set up the computer you are using? If it is a work computer, as the message says it could be some corporate security software. If this is a home computer, while this is MacOS X and I believe such software are a lot rarer, are you sure you haven't installed some security software or as Tigraan mentioned a browser plugin that may interfere? Nil Einne (talk) 04:16, 18 July 2018 (UTC)[reply]