I’ve not read this yet, just passing it along, as it looks really interesting.

I’m not affiliated in any way with this.

ETA: If anyone has read it / bought a copy, a review would be very appreciated.

You are viewing a single thread.
View all comments View context

I might have missed it, but it doesn’t look like their site accepts payment data, or has a login of any kind.

Why would the lack of SSL concern you?

permalink
report
parent
reply
6 points
*

The site is encrypted but you can also access the site over http. The author hasn’t configured any kind of HTTPS upgrade. This is an easily correctable oversight that a self proclaimed “self hosting expert” should have accounted for.

permalink
report
parent
reply
1 point

They should just block port 80

permalink
report
parent
reply
2 points

Or not have the website listen on port 80, or redirect connections from http to https on connect. Lots of very simple ways to correct this problem.

permalink
report
parent
reply
3 points

Why would the lack of SSL concern you?

Because it means my traffic to that site is in the clear. And while we’re not transacting anything sensitive necessarily. It’s still best practice to limit sniffing.

Automatically swapping to https should be default behavior for every website.

permalink
report
parent
reply

There’s no need to encrypt this data. Any entity that is watching you knows how to see the domains you visit, and everything on this site is on the main page, or a click away from it.

An SSL here is nothing more than security theater, or marketing.

permalink
report
parent
reply
5 points

An SSL here is nothing more than security theater, or marketing.

Or like I already said… is best practice.

permalink
report
parent
reply
3 points

Why wouldn’t that concern you? That means it is totally plain text with zero verification of incoming data or encryption. It is really easy to tamper with http traffic.

permalink
report
parent
reply
1 point
*

The site links to a site that accepts payment data. So because the author’s site is http, a MITM attacker could change the payment links from lulu.com to site-that-actually-steals-your-credit-card.com.

That’s one huge thing https provides over http… assurance of unadulterated content, including links to sites that actually deal in sensitive data.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 4.9K

    Monthly active users

  • 3.6K

    Posts

  • 81K

    Comments