Bitcoin Forum
May 02, 2024, 05:15:45 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Site's Security Grade: A-  (Read 2415 times)
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
February 24, 2014, 10:50:09 PM
 #21

I forget what the problem was specifically and there's no way to look back either.

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
1714626945
Hero Member
*
Offline Offline

Posts: 1714626945

View Profile Personal Message (Offline)

Ignore
1714626945
Reply with quote  #2

1714626945
Report to moderator
1714626945
Hero Member
*
Offline Offline

Posts: 1714626945

View Profile Personal Message (Offline)

Ignore
1714626945
Reply with quote  #2

1714626945
Report to moderator
1714626945
Hero Member
*
Offline Offline

Posts: 1714626945

View Profile Personal Message (Offline)

Ignore
1714626945
Reply with quote  #2

1714626945
Report to moderator
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 04, 2014, 07:20:28 PM
 #22

So how about implementing HSTS?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12908


View Profile
March 04, 2014, 07:52:45 PM
 #23

So how about implementing HSTS?

It is implemented, just not long-term.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 04, 2014, 08:01:50 PM
 #24

So how about implementing HSTS?

It is implemented, just not long-term.
How come?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 05, 2014, 06:28:00 PM
 #25

So how about implementing HSTS?

It is implemented, just not long-term.
How come?
?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12908


View Profile
March 05, 2014, 11:10:48 PM
 #26

How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
March 05, 2014, 11:16:33 PM
 #27

How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.

How would it cause a problem?  If you don't have the ability to operate using https you simply shouldn't be operating (this goes for any site which needs to secure communication between server and client).   If something results in you losing your TLS cert for a period of time it would be better to not operate the site until it is restored.   If anything the only useful value for HSTS would be infinite (i.e. NEVER UNTIL THE END OF TIME CONNECT TO THIS DOMAIN INSECURELY) but since that is not an option a very long HSTS value is used as a proxy.
Xer0
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


°^°


View Profile
March 06, 2014, 03:00:27 PM
 #28

A? good joke
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!