<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Hi Sebastian,</p>
<p><br>
</p>
<p>You're right this is an issue. The correct people to contact are
the ACT maintainers (ACT is the underlying system that powers the
conference site) and they are available via the ACT mailing list:</p>
<br>
<a class="moz-txt-link-abbreviated" href="mailto:act@mongueurs.net">act@mongueurs.net</a>
<div class="moz-cite-prefix"><br>
I have cc'd them into this email so that they are aware of it. I
am fairly certain that they know there is an issue but it is
always good to open the dialogue as there may be a way for others
to help.<br>
<br>
Kind regards<br>
<br>
Mark<br>
<br>
On 05/07/2018 19:41, Sebastian Strajan wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CY1PR1201MB111513CC7DAA5BB63AEE4E9AF9400@CY1PR1201MB1115.namprd12.prod.outlook.com">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
<div id="divtagdefaultwrapper" style="font-size: 12pt; color:
rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif,
EmojiFont, "Apple Color Emoji", "Segoe UI
Emoji", NotoColorEmoji, "Segoe UI Symbol",
"Android Emoji", EmojiSymbols;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Hi <span>Mark,</span></p>
<p style="margin-top:0;margin-bottom:0"><span><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span>I'm contacting you
because I couldn't find a contact form for the <a
href="http://act.perlconference.org/tpc-2018-glasgow/"
class="OWAAutoLink" id="LPlnk222646" previewremoved="true"
moz-do-not-send="true">http://act.perlconference.org/tpc-2018-glasgow/</a> website.</span><br>
</p>
<p style="margin-top:0;margin-bottom:0"><span>I found out that
you published some feeds in <a
href="http://act.perlconference.org/tpc-2018-glasgow/atom/en.xml"
class="OWAAutoLink" id="LPlnk580811" previewremoved="true"
moz-do-not-send="true">http://act.perlconference.org/tpc-2018-glasgow/atom/en.xml</a> and
I tough that you may be able to help me or at least
recommend somebody else for this.</span><br>
</p>
<p style="margin-top:0;margin-bottom:0"><span><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span>It seems that the
website doesn't provide an HTTPS version.</span></p>
<p style="margin-top:0;margin-bottom:0">My concern is because
the website provides a login page which sends the credentials
in clear text, which can be captured with ease by somebody
else and after that they can track everything in my account.</p>
<p style="margin-top:0;margin-bottom:0">Also for users that
reuse passwords this is a hazard, because all their/multiple
accounts can be compromised because of logging on the
conference website from an unsecure network (almost any public
WIFI can be categorized as unsecure).</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Moving from HTTP to
HTTPS shouldn't be that hard, and now it can be done freely
via <a href="https://letsencrypt.org" class="OWAAutoLink"
id="LPlnk975331" previewremoved="true"
moz-do-not-send="true">https://letsencrypt.org</a></p>
<p style="margin-top:0;margin-bottom:0">If you are unfamiliar
with the <a href="https://letsencrypt.org" class="OWAAutoLink"
id="LPlnk748688" previewremoved="true"
moz-do-not-send="true">https://letsencrypt.org</a> here are
more details:</p>
<p style="margin-top:0;margin-bottom:0">- can generate for free
a HTTPS certificate that you can use for your website(s)</p>
<p style="margin-top:0;margin-bottom:0">- you can use the <a
href="https://certbot.eff.org" class="OWAAutoLink"
id="LPlnk451817" previewremoved="true"
moz-do-not-send="true">https://certbot.eff.org</a> to
generate the certificate via CLI in a Linux box (you just need
a webserver that can host temporarily a file - in order for
letsencrypt to be able to validate that you are the owner of
the domain for which the certificate is generated)</p>
<p style="margin-top:0;margin-bottom:0">- certificate is valid
for 90 days (this should be enough for manual generation -
until the conference ends this will be valid, and after that
the certificate will ensure encryption for the traffic, but
the browser will tell you that the certificate has expired -
it can be renewed if it is needed with the same process)</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
If you need more info or help please let me know and I'll do my
best in helping you.<br>
<p style="margin-top:0;margin-bottom:0"><span><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span>In case I need to
contact somebody else please let me know.</span></p>
<p style="margin-top:0;margin-bottom:0"><span></span></p>
<p style="margin-top:0;margin-bottom:0"><span><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span>Thanks,</span></p>
<p style="margin-top:0;margin-bottom:0"><span>Sebastian Strajan</span></p>
</div>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Mark Keating | Writer, Photographer, Cat-Herder
Director | Shadowcat Systems Limited
Enlightened Perl Organisation
Lancaster and Morecambe Makers
FLOSSUK (UKUUG Limited)
Community Contributor | The Perl Foundation
Enlightened Perl Organisation
Lancaster and Morecambe Makers
FLOSSUK
Digital Lancaster
Independent Lancaster
Lancaster Hour
Ethical Small Trader's Association
Social Links | <a class="moz-txt-link-freetext" href="http://shadow.cat/blog/mark-keating/">http://shadow.cat/blog/mark-keating/</a>
<a class="moz-txt-link-freetext" href="http://linkedin.com/in/markkeating">http://linkedin.com/in/markkeating</a>
@shadowcat_mdk
Shadowcat Systems Limited
Is a Company registered in England and Wales.
Company address: The Barracks, White Cross, South Road, Lancaster, LA1 4XQ.
Company Registration Number: 05420396.
Company VAT Number: 868 9313 71
Disclaimer
This email and any attachments to it may be confidential and are intended solely for the use
of the individual to whom it is addressed. Any views or opinions expressed are solely those of
the author and do not necessarily represent those of Shadowcat Systems Limited.
If you are not the intended recipient of this email, you must neither take any action based
upon its contents, nor copy or show it to anyone. Please contact the sender if you believe you
have received this email in error immediately and do not disclose the contents to anyone or
make copies thereof.
</pre>
</body>
</html>