I saw that our domain was now down to a C on
Qualys's SSL test, so I did some updating today. After some tweaking, and advice from sites like
this one, I've gotten it back up to an A+. The downside is that it could potentially hinder very old browsers and/or non-standard browsers that can't deal with modern ciphers, but we'll see.
I'm getting more and more concerned about this site's security in general. One of my other forums was hacked not so long ago, and there is no easy method to protect this site without significantly upgrading and/or migrating it. I can get all of the content somewhere else, but the years of mods, tweaking, and fun additions that we've all grown accustomed to here will at least initially be quite a loss. It's one of those things that I know I have to do at some point, but I've been dragging my feet for so long because it will be painful on me and potentially on members. I did create the
www.crf250l.org site using XenForo a few years ago as a bit of a preview of what I might do here, and it's worked reasonably well. That site I just updated a few years of backlog this past weekend, so it's reasonably up to date on the forum side, as well as the underlying OS side. But there are way fewer mods on that site, it's close to stock, and way fewer members to notice or complain as well.
Nothing brewing here in the very near future, absent something surprising catching me off guard security wise, but I know it has to come due at some point.