LO page security concerns
Greatly appreciated,
Comments
-
Sam Li:
More and more we are asked by the donors why the pages we have are not secure (mostly due to many of the browser now being more strict on getting warnings out for anything that's not associated with a https). Have any of you ever got asked this question by someone who also happened to work in the internet security industry? What would your standard responses be when asked?
Greatly appreciated,Sam, this is often due to images within the email or pages, I've found. If your images are in the LO Image Library, they can be/should be https:// based - go to the library and Preview any image you have stored there. If you look at its URL in the preview, it says https://secure3.convio.net/[your-org]/admin/ImageLibrary... BUT! If you look at the code for your page or email, I've found, the "s" part of https has been stripped out, and suddenly the URL has changed to http://cjp.convio.net/images/content/pagebuilder/image-name...
Perhaps a BB person could answer this? why this happens, and how to repair so that images from the Image Library don't trigger the security warnings?
Cheers,
Gurukarm
0 -
Gurukarm Khalsa:
Sam Li:
More and more we are asked by the donors why the pages we have are not secure (mostly due to many of the browser now being more strict on getting warnings out for anything that's not associated with a https). Have any of you ever got asked this question by someone who also happened to work in the internet security industry? What would your standard responses be when asked?
Greatly appreciated,Sam, this is often due to images within the email or pages, I've found. If your images are in the LO Image Library, they can be/should be https:// based - go to the library and Preview any image you have stored there. If you look at its URL in the preview, it says https://secure3.convio.net/[your-org]/admin/ImageLibrary... BUT! If you look at the code for your page or email, I've found, the "s" part of https has been stripped out, and suddenly the URL has changed to http://cjp.convio.net/images/content/pagebuilder/image-name...
Perhaps a BB person could answer this? why this happens, and how to repair so that images from the Image Library don't trigger the security warnings?
Cheers,
GurukarmGurukarm, the URL decides whether you're requesting a secure or non-secure resource. Any give image is available at two URLs:
NON-SECURE: http://orgname.convio.net/images/path/to/file.jpg
SECURE: https://secureX.convio.net/orgname/images/path/to/file.jpg
Most of LO also comes in both non-secure and secure flavors as well (also triggered by the format of the URL). For example, pagebuilder can be accessed at...
NON-SECURE: http://orgname.convio.net/site/PageNavigator/pagebuilder_name_here.html
SECURE: https://secureX.convio.net/orgname/SPageNavigator/pagebuilder_name_here.html
...but there is a setting you can turn on to force these pages to redirect to a secure version (manage the PB page, click the "edit page attributes" button, and it's number 6 on the "Identify page" screen). If you've got "This is a secure Page that will be encrypted via SSL" checked, then the first url will automaticallly forward to the second one.
Sam, the other thing that can happen is if you have a form embedded on a page that isn't secure. Only really comes up if you've had some customization work done, though.
1 -
Gurukarm Khalsa:
Sam Li:
More and more we are asked by the donors why the pages we have are not secure (mostly due to many of the browser now being more strict on getting warnings out for anything that's not associated with a https). Have any of you ever got asked this question by someone who also happened to work in the internet security industry? What would your standard responses be when asked?
Greatly appreciated,Sam, this is often due to images within the email or pages, I've found. If your images are in the LO Image Library, they can be/should be https:// based - go to the library and Preview any image you have stored there. If you look at its URL in the preview, it says https://secure3.convio.net/[your-org]/admin/ImageLibrary... BUT! If you look at the code for your page or email, I've found, the "s" part of https has been stripped out, and suddenly the URL has changed to http://cjp.convio.net/images/content/pagebuilder/image-name...
Perhaps a BB person could answer this? why this happens, and how to repair so that images from the Image Library don't trigger the security warnings?
Cheers,
GurukarmThanks Gurukarm, as Jeremy pointed out, the domain should be available in both forms, and my concern is not really the absolute linking (hardcoded href to an insecure form of the image/doc location) but rather LO's default custom pages. When coding in LO, relative links are always recommended.
0 -
Jeremy Reynolds:
Gurukarm, the URL decides whether you're requesting a secure or non-secure resource. Any give image is available at two URLs:
NON-SECURE: http://orgname.convio.net/images/path/to/file.jpg
SECURE: https://secureX.convio.net/orgname/images/path/to/file.jpg
Most of LO also comes in both non-secure and secure flavors as well (also triggered by the format of the URL). For example, pagebuilder can be accessed at...
NON-SECURE: http://orgname.convio.net/site/PageNavigator/pagebuilder_name_here.html
SECURE: https://secureX.convio.net/orgname/SPageNavigator/pagebuilder_name_here.html
...but there is a setting you can turn on to force these pages to redirect to a secure version (manage the PB page, click the "edit page attributes" button, and it's number 6 on the "Identify page" screen). If you've got "This is a secure Page that will be encrypted via SSL" checked, then the first url will automaticallly forward to the second one.
Sam, the other thing that can happen is if you have a form embedded on a page that isn't secure. Only really comes up if you've had some customization work done, though.Do you have experience with a custom secure domain implemented by BB? Our instance recently added that feature, which should in term remedy a lot of the insecurity but also resulted in some issues. Often time, when one sets up the pagebuilder page, the SSL encryption attr was not checked off, and some script only can be run in the http environment. Plus, the default LOTR pages are still not encryted with SSL. And yeah, hacked survey on a pagebuilder page is a huge problem too.
0 -
Gurukarm Khalsa:
Sam Li:
More and more we are asked by the donors why the pages we have are not secure (mostly due to many of the browser now being more strict on getting warnings out for anything that's not associated with a https). Have any of you ever got asked this question by someone who also happened to work in the internet security industry? What would your standard responses be when asked?
Greatly appreciated,Sam, this is often due to images within the email or pages, I've found. If your images are in the LO Image Library, they can be/should be https:// based - go to the library and Preview any image you have stored there. If you look at its URL in the preview, it says https://secure3.convio.net/[your-org]/admin/ImageLibrary... BUT! If you look at the code for your page or email, I've found, the "s" part of https has been stripped out, and suddenly the URL has changed to http://cjp.convio.net/images/content/pagebuilder/image-name...
Perhaps a BB person could answer this? why this happens, and how to repair so that images from the Image Library don't trigger the security warnings?
Cheers,
GurukarmIt could also be the search function, if you have one! We had converted all our images and links and our page was still being marked as "Not Secure". It ended up being the search function redirecting to http://www.ourdomain.org instead of https. Fixing this seems to have fixed our security problems.
0
Categories
- All Categories
- Shannon parent
- shannon 2
- shannon 1
- 21 Advocacy DC Users Group
- 14 BBCRM PAG Discussions
- 89 High Education Program Advisory Group (HE PAG)
- 28 Luminate CRM DC Users Group
- 8 DC Luminate CRM Users Group
- Luminate PAG
- 5.9K Blackbaud Altru®
- 58 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 409 bbcon®
- 2.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- donorCentrics®
- 1.1K Blackbaud eTapestry®
- 2.8K Blackbaud Financial Edge NXT®
- 1.1K Blackbaud Grantmaking™
- 527 Education Management Solutions for Higher Education
- 1 JustGiving® from Blackbaud®
- 4.6K Education Management Solutions for K-12 Schools
- Blackbaud Luminate Online & Blackbaud TeamRaiser
- 16.4K Blackbaud Raiser's Edge NXT®
- 4.1K SKY Developer
- 547 ResearchPoint™
- 151 Blackbaud Tuition Management™
- 1 YourCause® from Blackbaud®
- 61 everydayhero
- 3 Campaign Ideas
- 58 General Discussion
- 115 Blackbaud ID
- 87 K-12 Blackbaud ID
- 6 Admin Console
- 949 Organizational Best Practices
- 353 The Tap (Just for Fun)
- 235 Blackbaud Community Feedback Forum
- 55 Admissions Event Management EAP
- 18 MobilePay Terminal + BBID Canada EAP
- 36 EAP for New Email Campaigns Experience in Blackbaud Luminate Online®
- 109 EAP for 360 Student Profile in Blackbaud Student Information System
- 41 EAP for Assessment Builder in Blackbaud Learning Management System™
- 9 Technical Preview for SKY API for Blackbaud CRM™ and Blackbaud Altru®
- 55 Community Advisory Group
- 46 Blackbaud Community Ideas
- 26 Blackbaud Community Challenges
- 7 Security Testing Forum
- 1.1K ARCHIVED FORUMS | Inactive and/or Completed EAPs
- 3 Blackbaud Staff Discussions
- 7.7K ARCHIVED FORUM CATEGORY [ID 304]
- 1 Blackbaud Partners Discussions
- 1 Blackbaud Giving Search™
- 35 EAP Student Assignment Details and Assignment Center
- 39 EAP Core - Roles and Tasks
- 59 Blackbaud Community All-Stars Discussions
- 20 Blackbaud Raiser's Edge NXT® Online Giving EAP
- Diocesan Blackbaud Raiser’s Edge NXT® User’s Group
- 2 Blackbaud Consultant’s Community
- 43 End of Term Grade Entry EAP
- 92 EAP for Query in Blackbaud Raiser's Edge NXT®
- 38 Standard Reports for Blackbaud Raiser's Edge NXT® EAP
- 12 Payments Assistant for Blackbaud Financial Edge NXT® EAP
- 6 Ask an All Star (Austen Brown)
- 8 Ask an All-Star Alex Wong (Blackbaud Raiser's Edge NXT®)
- 1 Ask an All-Star Alex Wong (Blackbaud Financial Edge NXT®)
- 6 Ask an All-Star (Christine Robertson)
- 21 Ask an Expert (Anthony Gallo)
- Blackbaud Francophone Group
- 22 Ask an Expert (David Springer)
- 4 Raiser's Edge NXT PowerUp Challenge #1 (Query)
- 6 Ask an All-Star Sunshine Reinken Watson and Carlene Johnson
- 4 Raiser's Edge NXT PowerUp Challenge: Events
- 14 Ask an All-Star (Elizabeth Johnson)
- 7 Ask an Expert (Stephen Churchill)
- 2025 ARCHIVED FORUM POSTS
- 322 ARCHIVED | Financial Edge® Tips and Tricks
- 164 ARCHIVED | Raiser's Edge® Blog
- 300 ARCHIVED | Raiser's Edge® Blog
- 441 ARCHIVED | Blackbaud Altru® Tips and Tricks
- 66 ARCHIVED | Blackbaud NetCommunity™ Blog
- 211 ARCHIVED | Blackbaud Target Analytics® Tips and Tricks
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- Luminate CRM DC Users Group
- 225 ARCHIVED | Blackbaud eTapestry® Tips and Tricks
- 1 Blackbaud eTapestry® Know How Blog
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)
- 1 Blackbaud K-12 Education Solutions™ Blog
- 280 ARCHIVED | Mixed Community Announcements
- 3 ARCHIVED | Blackbaud Corporations™ & Blackbaud Foundations™ Hosting Status
- 1 npEngage
- 24 ARCHIVED | K-12 Announcements
- 15 ARCHIVED | FIMS Host*Net Hosting Status
- 23 ARCHIVED | Blackbaud Outcomes & Online Applications (IGAM) Hosting Status
- 22 ARCHIVED | Blackbaud DonorCentral Hosting Status
- 14 ARCHIVED | Blackbaud Grantmaking™ UK Hosting Status
- 117 ARCHIVED | Blackbaud CRM™ and Blackbaud Internet Solutions™ Announcements
- 50 Blackbaud NetCommunity™ Blog
- 169 ARCHIVED | Blackbaud Grantmaking™ Tips and Tricks
- Advocacy DC Users Group
- 718 Community News
- Blackbaud Altru® Hosting Status
- 104 ARCHIVED | Member Spotlight
- 145 ARCHIVED | Hosting Blog
- 149 JustGiving® from Blackbaud® Blog
- 97 ARCHIVED | bbcon® Blogs
- 19 ARCHIVED | Blackbaud Luminate CRM™ Announcements
- 161 Luminate Advocacy News
- 187 Organizational Best Practices Blog
- 67 everydayhero Blog
- 52 Blackbaud SKY® Reporting Announcements
- 17 ARCHIVED | Blackbaud SKY® Reporting for K-12 Announcements
- 3 Luminate Online Product Advisory Group (LO PAG)
- 81 ARCHIVED | JustGiving® from Blackbaud® Tips and Tricks
- 1 ARCHIVED | K-12 Conference Blog
- Blackbaud Church Management™ Announcements
- ARCHIVED | Blackbaud Award Management™ and Blackbaud Stewardship Management™ Announcements
- 1 Blackbaud Peer-to-Peer Fundraising™, Powered by JustGiving® Blogs
- 39 Tips, Tricks, and Timesavers!
- 56 Blackbaud Church Management™ Resources
- 154 Blackbaud Church Management™ Announcements
- 1 ARCHIVED | Blackbaud Church Management™ Tips and Tricks
- 11 ARCHIVED | Blackbaud Higher Education Solutions™ Announcements
- 7 ARCHIVED | Blackbaud Guided Fundraising™ Blog
- 2 Blackbaud Fundraiser Performance Management™ Blog
- 9 Foundations Events and Content
- 14 ARCHIVED | Blog Posts
- 2 ARCHIVED | Blackbaud FIMS™ Announcement and Tips
- 59 Blackbaud Partner Announcements
- 10 ARCHIVED | Blackbaud Impact Edge™ EAP Blogs
- 1 Community Help Blogs
- Diocesan Blackbaud Raiser’s Edge NXT® Users' Group
- Blackbaud Consultant’s Community
- Blackbaud Francophone Group
- 1 BLOG ARCHIVE CATEGORY
- Blackbaud Community™ Discussions
- 8.3K Blackbaud Luminate Online® & Blackbaud TeamRaiser® Discussions
- 5.7K Jobs Board