So, currently I have a patched and up to date FluxBB forum running on my private server. I’ve contacted OSM admins to see if there is still a server available and to prepare the move.
I’m told that the server which is reserved for the forum is currently powered-down due to a power shortage in the rack earlier this year. It will take some time to get it running again.
While I full respect the hard work of the admins, but IMHO we were pretty patient for 2 years on this issue. Today, we still leak our OSM credentials via unsecured HTTP at the forum login.
Please check, how to switch to HTTPS only! It’s 2016 and letsencrypt is ready for production. Maybe it’s better to work with an non unified certificate hierachie, than ever user of the forum is endangered