Error - Not Secure / Privacy Error

Its not a particullary hard fix so they will get it sorted

These days there’s really no excuse for letting your main certificate expire - unless you need EV (which QuickFile doesn’t) then basic certificate renewal can and should be 100% automated. The norm these days is 90 day certificates that attempt to renew 15-30 days before expiry and notify someone in plenty of time if the renewal fails.

For those who don’t know what this means, it is not good. Assuming this is what it appears to be, it means that QF’s website SSL certificate has expired (on a bank holiday) which means your data from your device to and from the QF servers (if they are working) may be being sent as plain text (non-encrypted), including any passwords (e.g. login) or financial data you send. (This is indicated by the URL/web address showing as http: and not https: - s stands for Secure.) It does not mean that “attackers are trying to steal your information” BUT this makes it easier for any malicious entity or software trying to do so to sniff the internet traffic on your local network and see that data. It also makes it easier for what is called a man in the middle attack where a malicious entity can set themselves up as, for example, a wifi service you connect to and see the internet traffic you are sending to the QF servers, or pretend to be the QF service. It means that such a malicious entity could make the web pages appear differently to intended and insert malicious scripts or ads, for example. It also means that if your ISP is keeping a log of internet traffic from you with QF then that plain text may be recorded in a log somewhere under the ISP’s control. The same goes for potential logging of unencrypted data by the wifi service provider you might be using.

I am not qualified to give advice but because I can delay what I am doing on QF today to tomorrow, I will not be logging on until they fix this. I consider my QF business financial data way too sensitive to risk it if I don’t have to. (Personally, as an aside, I think the government’s push for everyone to use cloud computing, and everyone’s acceptance of it, for such sensitive data was a massive mistake in the first place, for exactly this type of circumstance, for example. There was absolutely nothing wrong with locally installed distributed software; it just then becomes the responsibility of the user to keep backups (encrypted to the cloud, if you like), which should be a basic understanding of anybody using a digital storage device anyway.) Notepad and pencil out for anything urgent today to list everything I need to do later.

If you must/can logon today then I would suggest you change your password as soon as this has been fixed. It will not help if such a malicious entity is quick to act (as an AI would be, for example), and it also will not help with stopping a malicious entity, if present, seeing the traffic you communicate with QF until it is fixed, nor will it stop your data potentially being potentially logged by an intermediate service (your ISP or the wifi service provider). I repeat, though, it does not mean that someone is definitely stealing your data, it is just that it is at significantly increased risk.

Any experts out there who want to correct me on anything here, feel free. Just thought I would try to be helpful for the less tech-savvy users. (Oh, and apparently using a VPN is not really much of a fix for this.)

I was going to go through my accounts to do my year end today. I guess that is not the best idea :frowning:

I guess this is a message from a higher authority telling me to do something else on a Bank Holiday

Ok but is it fixed? And how did it happen?

Thank you.

Regards

Michael.

I don’t know how they let the certificates expire - maybe an automated process failed?

It looks like they are not working on a bank holiday as there has not been a resolution or response yet, despite a few people tagging the support team on that other ticket.

We have the issue SSL expired on the 25th May, not great can you get sorted ASAP, not something we would expect from a professional organisation

Yep, me also on both Edge and Chrome.

This is a ridiculous situation to be in, and I can’t make any recommendations as to whether this is safe or not, but as a workaround if you set your computer’s date to yesterday it fixes the problem.

Same- our IT has advised:- It seems that the six month duration SSL security certificate has expired (at some point today already).

Hopefully they sort it soon.

You can access the account by clicking advance and continuing to the site. If that helps for now.

I keep getting an error trying to login “your connection is not private” NET::ERR_CERT_DATE_INVALID this is happening on multiple devices and browsers. All settings have been checked for auto Date time update and there are no issues.

I am concerned for the safety of my data and obviously I don’t want to login until this is resolved.

I am struggling to login and getting a “your connection may not be private” error. This is happening on multiple devices. All settings etc my end have been checked

This is flat wrong - if you choose the option along the lines of “I accept the risk, proceed anyway” then everything is exactly as it was yesterday, with the same level of encryption and the same certificate. The only difference is that said certificate’s expiry date happens to be the early hours of this morning.

If you view the actual certificate (in my browser it’s accessible via the “not secure” button in the address bar, where the padlock would normally be) then you can confirm that it still has the right domain name, it was issued six months ago in November and it expired today. So all this certificate actually tells you is that whoever requested it was in control of the quickfile.co.uk domain name in November (when the certificate was issued). It’s no less safe six-months-and-one-day after that point than it was six months after, and on balance if you do need to get in to your QuickFile urgently today to meet a deadline then you’re probably fine to “accept the risk and proceed anyway”.

Most modern certificate management systems with automated renewals use much shorter lifetimes, no more than 90 days at a time and usually renewed 15-30 days before expiry, so you have a much more recent assurance of domain control.

Looks like @QFSteve has been on merging messages to this one so I’m optimistic it will be resolved soon.

@QFSupport Can you please look into this issue ASAP? Thanks!

So am i best not using Quickfile until the SSL certificate has been updated?

We are currently investigating a network issue affecting access to some QuickFile accounts and subdomains.

Our developers are actively working on the issue and we expect service to be restored shortly.
We apologise for the inconvenience and appreciate your patience.

Thanks for update. i’m happy to hang fire.

So why bother to renew the certificate at all?