Forum Settings
Forums
New
Aug 16, 2016 11:59 PM
#1
Overlord

Offline
Nov 2004
5752
Hello everyone. About a year ago I made mention that we were working on adding HTTPS/SSL support to MyAnimeList. I’m pleased to announce that it’s finally here! At approximately midnight tomorrow (August 17 11:59pm PST) Now, you’ll be able to securely browse MAL through HTTPS. This functionality will also be available for our mobile users.

One side effect of this new feature is we will, unfortunately, no longer be able to provide our Daisuki videos for streaming. While we have had a great partnership, their service is not compatible with HTTPS. We hope to see their videos back in the future.

Also, in order to allow our 3rd party developers ample time to update their applications, we’ve decided to allow our API to support both HTTP and HTTPS for about 3 weeks. Please update your application(s) as soon as possible. By mid-September, the API endpoints will only use HTTPS.

Finally, if you are using any custom userscripts with a browser add-on like TamperMonkey, you may find that your URLs need to be updated to HTTPS.

We hope everyone enjoys this added security and that your browsing experience is not hampered in any way. Please let us know if you experience any issues!


Update August 18
Our HTTPS transformation sequence is on pause due to technical difficulties. Tune in next week for our final form.
The thread will be updated once the new release date has been scheduled.


Update August 23
SSL is now live!


Update August 25
Trouble logging in? / Getting 400 errors? Please whitelist myanimelist.cdn-dena.com in your script blockers. This is not a 3rd party website (MAL is owned by DeNA).

CSS import problems for anime/manga list designs? Please host your CSS file(s) on a website which supports HTTPS (e.g. Dropbox). Unfortunately, it is not possible for us to enable HTTP imports on anime/manga lists.

Why doesn't the "secured" symbol appear on profile/forum pages? This is due to mixed content on the pages (images in the About Me / posts which are from non-HTTPS sources). We decided it would be unnecessarily restrictive to require all images embedded by users to come from HTTPS sources.
KinetaAug 25, 2016 2:43 AM
Pages (3) [1] 2 3 »
Aug 17, 2016 12:01 AM
#2

Offline
Jan 2009
92250
holy shit its finally happening

you said on your reddit AMA that it will only take 2 months but better late than never XD

EDIT:

btw do you have plans to change your advertisement partners to a faster loading one? im using an adblocker because of how slow the ads here on MAL are and the ads on the sides takes too much space on my small display/screen that it gives scrolling bars at the bottom

i hope ads will improve next so that i can disable adblock here on MAL as well as making the whole site automatically resize depending on the screen size/resolution of the users monitor

but thanks for the continued improvements on MAL
degAug 17, 2016 12:10 AM
Aug 17, 2016 12:06 AM
#3
Offline
Sep 2015
5
Yas finally!! Thank you so much. :D
Aug 17, 2016 12:07 AM
#4

Offline
Jul 2012
48248
Congrats, y'all
Aug 17, 2016 12:12 AM
#5

Offline
Oct 2014
27152
Yesss, thank you.. :D

read from right to left
Aug 17, 2016 12:13 AM
#6

Offline
Mar 2014
8503
Thank you and congratulations!! :D



"What?"
Aug 17, 2016 12:31 AM
#7

Offline
Jul 2016
21
Im glad to hear that sir
Aug 17, 2016 12:37 AM
#8

Offline
Jul 2014
23
Thank you very much!
Aug 17, 2016 12:52 AM
#9

Offline
Aug 2015
3777
Finally!! Good Job! 👍👍
Aug 17, 2016 1:07 AM

Offline
Jul 2013
36274
Ooh nice, so it's finally happening. I do have a question though. Will the ssl/tls be implemented along with HSTS?
Well, I guess I'll see when the change is made since it's a simple http response header ^^
For those who seek perfection, there can be no rest on this side of the grave.
Hope is the first step on the road to disappointment.
Aug 17, 2016 2:03 AM

Offline
Jun 2014
51
Hmm... i guess this news is so good that i might as well make my first post on the forums to say thanks. :D

Thanks for adding HTTPS! ^^
I should probably make a forum signature someday...
Aug 17, 2016 2:07 AM
Aug 17, 2016 2:29 AM

Offline
Feb 2013
24143
I have no idea what that means.
Do I have to do something to keep using MAL?
Aug 17, 2016 2:49 AM
Offline
Mar 2016
631
it's a nice thing for those who wants security. I believe this is useful to those who don't want their account hacked or those who wants more privacy.
Ulquiorra said:
I have no idea what that means.
Do I have to do something to keep using MAL?
You can ignore this thing if you don't care about https, ssl, and safety features.
Aug 17, 2016 2:55 AM

Offline
Feb 2013
24143
crx07 said:
it's a nice thing for those who wants security. I believe this is useful to those who don't want their account hacked or those who wants more privacy.
Ulquiorra said:
I have no idea what that means.
Do I have to do something to keep using MAL?
You can ignore this thing if you don't care about https, ssl, and safety features.


I see, thanks.
Aug 17, 2016 2:56 AM

Offline
Mar 2013
1829
Great work :)
Aug 17, 2016 2:58 AM

Offline
Feb 2011
2489
Ulquiorra said:
I have no idea what that means.
Do I have to do something to keep using MAL?

https://en.wikipedia.org/wiki/HTTPS
it should be about encrypting any data traveling between you and the server,
so that even if an hacker cuts the cable of your internet line and looks at anything moving on it they won't be able to understand what is being sent :u
it's mostly important with wireless connections, since it's very easy to look to what is being transmitted when the data moves in the air

Fixes to make the Profile more bearable after "the Modern★Profile★Update★★Rip★Profile★"
Aug 17, 2016 3:25 AM

Offline
Jul 2015
1583
Very nice! MAL gets bigger and better throughout the years
Aug 17, 2016 4:05 AM

Offline
Sep 2015
1728
I read about improvement, securely browsing, security so whatever this update means I guess it is a good thing I think.

Congrats and great work.

Tobacco Causes Severe Health Problems, Smoke Moderately While Respecting Others.
Aug 17, 2016 4:08 AM

Offline
Apr 2014
3113
Welp, Don't really get it but congrats still!
Aug 17, 2016 4:25 AM

Offline
Nov 2012
2045
Nice update.
Aug 17, 2016 4:29 AM

Online
Feb 2012
6699
Thank you based Xinil and other devs working on MAL.

Keep it up.
Aug 17, 2016 4:37 AM

Offline
Jun 2015
2258
Finally something good! Good job everyone c:

set by secret santa ; thank you! ily ♥️
Aug 17, 2016 4:43 AM

Offline
Sep 2012
3601
Good job everyone.
Aug 17, 2016 4:58 AM

Offline
Jul 2014
174
Just finished updating all my userscripts. Great job!
Aug 17, 2016 5:13 AM

Offline
May 2016
55
omedetou :)
I don't care
Aug 17, 2016 6:27 AM

Offline
Jan 2015
327
Would people even bother hacking a anime list though. You get nothing from it. I just don't understand.
Aug 17, 2016 6:41 AM

Offline
Sep 2013
2420
So comes the reign of SSLMaster.

MasterOfCoin said:
Would people even bother hacking a anime list though. You get nothing from it. I just don't understand.
You wouldn't imagine.
Aug 17, 2016 6:59 AM

Offline
Apr 2015
3
At last! Thank you!!
Aug 17, 2016 7:27 AM
Laughing Man

Offline
Jun 2012
6683


Will this SSJMaster, though?
Aug 17, 2016 7:47 AM

Offline
Mar 2013
9551
MAL is the best site for updating your list's thanks :)
Aug 17, 2016 7:50 AM

Offline
May 2015
79
Good job team !
Signature removed. Please follow the signature rules, as defined in the Site & Forum Guidelines.
Aug 17, 2016 7:59 AM
Offline
Sep 2015
490
Congrats on evolving MAL :)
Aug 17, 2016 8:36 AM

Offline
Mar 2013
5831
BatoKusanagi said:
Will this SSJMaster, though?

I assume you meant to ask if this will prevent SSJMaster's hijacking attempts. The answer is no.

SSJMaster gained access to accounts via phishing, the last I've heard. Secure HTTPS only really prevents man-in-the-middle attacks and eavesdropping by encrypting data, so each individual is not really any safer than they were before if they were to be targeted individually through means such as phishing.
Aug 17, 2016 8:53 AM

Offline
Dec 2015
59
Great work! How about responsive design next? The current mobile site is pretty buggy (not to mention that some stuff, like profile descriptions and friends lists aren't visible at all) and so I usually end up using the desktop site on mobile too.
Aug 17, 2016 9:25 AM
Offline
Jun 2014
95
Encryption helps protecting user's privacy. Good job!
Aug 17, 2016 10:35 AM

Offline
Oct 2014
3645
finally
Aug 17, 2016 10:37 AM
Offline
May 2015
7
j0x said:
holy shit its finally happening

you said on your reddit AMA that it will only take 2 months but better late than never XD

EDIT:

btw do you have plans to change your advertisement partners to a faster loading one? im using an adblocker because of how slow the ads here on MAL are and the ads on the sides takes too much space on my small display/screen that it gives scrolling bars at the bottom

i hope ads will improve next so that i can disable adblock here on MAL as well as making the whole site automatically resize depending on the screen size/resolution of the users monitor

but thanks for the continued improvements on MAL

+1 on the ads. I really don't want to use an adblocker but the ads do really do slow down the site.
Aug 17, 2016 11:13 AM

Offline
Oct 2014
14720
So a SIX year old suggestion was implemented. Splendid progress MAL keep it up!

Edit - RIP Mathematics.
IizyAug 17, 2016 11:30 AM
I don't know why people write that they are approachable persons,
if you were you wouldn't be on MAL.
----------------------------------------------------------------------------
Extended families or lovers on MAL are a farce.
----------------------------------------------------------------------------
Aug 17, 2016 11:22 AM
Anime Moderator
᠎ Master Öqvily᠎

Offline
Aug 2014
4096

Six*

Anyhow, thanks for the improvement! I'll gladly take it with open arms. :)



Forum set made by my
secret santa, Nate!
Aug 17, 2016 2:57 PM

Offline
Jan 2012
31481
Zeando said:

https://en.wikipedia.org/wiki/HTTPS
it should be about encrypting any data traveling between you and the server,
so that even if an hacker cuts the cable of your internet line and looks at anything moving on it they won't be able to understand what is being sent :u
it's mostly important with wireless connections, since it's very easy to look to what is being transmitted when the data moves in the air


thnx for info but lol why would someone hack ur profile , what precious info he gonna get (nothing).

u don't buy nothing from mal.

Aug 17, 2016 3:42 PM

Offline
Feb 2011
2489
AllenVonStein said:
Zeando said:

https://en.wikipedia.org/wiki/HTTPS
it should be about encrypting any data traveling between you and the server,
so that even if an hacker cuts the cable of your internet line and looks at anything moving on it they won't be able to understand what is being sent :u
it's mostly important with wireless connections, since it's very easy to look to what is being transmitted when the data moves in the air


thnx for info but lol why would someone hack ur profile , what precious info he gonna get (nothing).

u don't buy nothing from mal.

yep, on most sites implementing it it's not needed (but people are paranoid and want to feel secure, but don't tell them)
expecially since it's about having secure connections, it's not even about hacking profiles, but about what you are sending/receiving to the site

what are you sending to the site?
-logins
-forum posts
-list edits
-recommendations/reviews
...and other stuff likely
where most of them are publicly visible anyway once they are received by the server (login and settings excluded)

...yes, the most sensible information is maybe the login, or the mail used(once one gets in), but even that, doubt anyone is keeping their bank id into their profile notes...
i don't think it's to prevent theft of informations(since there aren't any of value), but at most theft of accounts (social medias are sensible to thefts of identity, and since mal is 'socializing' itself..)

oh right, there is also the facebook/google/twitter login integration, eavesdropping those means getting two accounts violated at once, oh the progress (mmm, but those should be already under secure connection protocols, so it's not even that)
ZeandoAug 17, 2016 4:13 PM

Fixes to make the Profile more bearable after "the Modern★Profile★Update★★Rip★Profile★"
Aug 17, 2016 5:21 PM

Offline
Aug 2015
2468
HOLY SHIT! anybody know exact time for this?
Aug 17, 2016 6:21 PM

Offline
Aug 2013
73
MasterOfCoin said:
Would people even bother hacking a anime list though. You get nothing from it. I just don't understand.

You probably weren't around, but it has already happened a few times.

That said, thank goodness we're finally getting secure connection.

ultravigo said:
HOLY SHIT! anybody know exact time for this?

Read the post again.

j0x said:
holy shit its finally happening

you said on your reddit AMA that it will only take 2 months but better late than never XD

EDIT:

btw do you have plans to change your advertisement partners to a faster loading one? im using an adblocker because of how slow the ads here on MAL are and the ads on the sides takes too much space on my small display/screen that it gives scrolling bars at the bottom

i hope ads will improve next so that i can disable adblock here on MAL as well as making the whole site automatically resize depending on the screen size/resolution of the users monitor

but thanks for the continued improvements on MAL

This. The site is pretty hard to use on mobile thanks to the pages never fully loading.
Toshiya_Aug 17, 2016 6:26 PM
Aug 17, 2016 6:24 PM
Offline
Oct 2014
12
One side effect of this new feature is we will, unfortunately, no longer be able to provide our Daisuki videos for streaming. While we have had a great partnership, their service is not compatible with HTTPS. We hope to see their videos back in the future.


Not supporting HTTPS for video in 2016, really?
Aug 17, 2016 6:50 PM

Offline
Aug 2014
2
Finally! About time MAL gets secured!
A Little Bit Closer
Aug 17, 2016 8:10 PM

Offline
Jan 2015
1037
hype!
Aug 17, 2016 9:40 PM
Offline
Dec 2015
21
I dont get it , but sounds good. GRATZ MAL!!
Aug 17, 2016 10:22 PM

Offline
Nov 2015
3673
Hurray (finally) ! now a safe place for all shut-ins and introvert otakus :' )
Aug 18, 2016 1:24 AM

Offline
Dec 2015
48
Wow,thank you for this! Any plans for HSTS preloading, or will that occur when the API goes SSL only?
cwade12cAug 18, 2016 1:35 AM
Pages (3) [1] 2 3 »

More topics from this board

» Heavenly Easter Delusion: Devil and Dolce ( 1 2 3 4 5 ... Last Page )

Kineta - Mar 27

3341 by Terra_strong »»
10 hours ago

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 )

Kineta - Feb 23

197 by Avengerlight »»
Yesterday, 12:38 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

211 by Kauam_ »»
Apr 16, 8:37 AM

» MAL Game "Fantasy Anime League" Opens for Spring 2024 ( 1 2 3 )

Kineta - Mar 17

144 by The_real_maomao »»
Apr 9, 4:26 PM

» English Titles Added to Desktop; Moving Towards a Romanized/English Toggle ( 1 2 3 )

Kineta - Feb 12, 2020

121 by Vaturna »»
Apr 4, 5:31 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login