Pdf Xchange Website

Forum for the PDF-XChange Editor - Free and Licensed Versions

Moderators: TrackerSupp-Daniel, Tracker Support, Paul - Tracker Supp, Vasyl-Tracker Dev Team, Chris - Tracker Supp, Sean - Tracker, Ivan - Tracker Software, Tracker Supp-Stefan

Post Reply
dalacor
User
Posts: 29
Joined: Thu Sep 01, 2016 9:04 am

Pdf Xchange Website

Post by dalacor »

I am not sure if this is the correct forum for this issue.

I have been testing disabling insecure and obsolete cipher suites in Firefox. 99% of the websites work perfectly with ciphersuites that support perfect forward secrecy and strong ciphers.

pdf-xchange.com website however seems to require this ciphersuite for all the content to load properly.

TLS_RSA_WITH_AES_256_CBC_SHA

The main website itself seems to load with all the text content using secure ciphersuites that support perfect forward secrecy so parts of the website is using secure ciphers. The images and formatting part seems to coming from a website that is using an older ciphersuite.

When you renew your certificate, could you update the certificates to use gcm and something like ECDHE. Sha1 and CBC ciphers have long been considered insecure.

Thank you
User avatar
TrackerSupp-Daniel
Site Admin
Posts: 8624
Joined: Wed Jan 03, 2018 6:52 pm

Re: Pdf Xchange Website

Post by TrackerSupp-Daniel »

Hello, dalacor

Thank you for the post, Either here on the Forums or contact by email <Support@PDF-XChange.com> is perfect for such items. I have informed out Web team about your concerns here, and they will be looking into it, to determine if anything needs to change.

Kind regards,
Dan McIntyre - Support Technician
Tracker Software Products (Canada) LTD

+++++++++++++++++++++++++++++++++++
Our Web site domain and email address has changed as of 26/10/2023.
https://www.pdf-xchange.com
Support@pdf-xchange.com
User avatar
TrackerSupp-Daniel
Site Admin
Posts: 8624
Joined: Wed Jan 03, 2018 6:52 pm

Re: Pdf Xchange Website

Post by TrackerSupp-Daniel »

Hello again!

While we cannot force anyone to trust any website, including our own, please find below our Rating through SSLLabs:
https://www.ssllabs.com/ssltest/analyze ... change.com
Our Web team is aware of a handful of areas we have room to improve in and will be looking at them case by case in the future. At the moment, some more pressing projects are taking their time, so I cannot promise how long it will be before a change in cipher comes along.

Kind regards,
Dan McIntyre - Support Technician
Tracker Software Products (Canada) LTD

+++++++++++++++++++++++++++++++++++
Our Web site domain and email address has changed as of 26/10/2023.
https://www.pdf-xchange.com
Support@pdf-xchange.com
dalacor
User
Posts: 29
Joined: Thu Sep 01, 2016 9:04 am

Re: Pdf Xchange Website

Post by dalacor »

Thank you for your prompt response.

It is not a pressing problem. I just wanted to make you aware of the issue. Oddly enough the website seems to be working perfectly today - even with that cipher disabled. Either somebody has already fixed the problem before I had a chance to report it, or there was another issue with the website on that day, that appeared to be related to that cipher.

At the moment, it seems to be working despite the fact that it was not working with old ciphers disabled a couple of days back. Anyway, your website developers can look into the issue when they have time. All I can say is that the text of the website loaded perfectly, but the images and the formatting was not working unless that particular cipher was enabled. So I am happy to close this topic, particularly as the website now appears to be working 100% with only modern ciphers enabled.

Regards Robert
User avatar
Jordan - Tracker Supp
Site Admin
Posts: 91
Joined: Mon Jul 03, 2023 3:10 pm

Pdf Xchange Website

Post by Jordan - Tracker Supp »

:)
Best regards,
Jordan
dalacor
User
Posts: 29
Joined: Thu Sep 01, 2016 9:04 am

Re: Pdf Xchange Website

Post by dalacor »

I think I have realised why it's working now and wasn't the other day. The website uses Cloudflare or some other CDN. I suspect that the CDN being used the other day uses the older cipher and the CDN that my pc is using today supports the newer ciphers. I recall having a similar issue a few years back with sending email to one company. It worked intermittently and the reason was because they had different mail servers and one of the mail servers only supported obsolete ciphers. So it's probably one of the CDN's that is the issue. that would make more sense.

Thanks
Robert
User avatar
Tracker Supp-Stefan
Site Admin
Posts: 17960
Joined: Mon Jan 12, 2009 8:07 am
Location: London
Contact:

Re: Pdf Xchange Website

Post by Tracker Supp-Stefan »

Hello dalacor,

Yes - we do use some cloud services, and it might indeed have had an effect. We've contacted our providers and are working with them on the improvements Daniel mentioned above!

Kind regards,
Stefan
Post Reply