Bitcoin Forum
May 02, 2024, 01:28:59 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Site's Security Grade: A-  (Read 2415 times)
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
February 24, 2014, 10:50:09 PM
 #21

I forget what the problem was specifically and there's no way to look back either.

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
1714613339
Hero Member
*
Offline Offline

Posts: 1714613339

View Profile Personal Message (Offline)

Ignore
1714613339
Reply with quote  #2

1714613339
Report to moderator
1714613339
Hero Member
*
Offline Offline

Posts: 1714613339

View Profile Personal Message (Offline)

Ignore
1714613339
Reply with quote  #2

1714613339
Report to moderator
The grue lurks in the darkest places of the earth. Its favorite diet is adventurers, but its insatiable appetite is tempered by its fear of light. No grue has ever been seen by the light of day, and few have survived its fearsome jaws to tell the tale.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 04, 2014, 07:20:28 PM
 #22

So how about implementing HSTS?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12908


View Profile
March 04, 2014, 07:52:45 PM
 #23

So how about implementing HSTS?

It is implemented, just not long-term.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 04, 2014, 08:01:50 PM
 #24

So how about implementing HSTS?

It is implemented, just not long-term.
How come?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
goozman96 (OP)
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
March 05, 2014, 06:28:00 PM
 #25

So how about implementing HSTS?

It is implemented, just not long-term.
How come?
?

BTC: 19DKtsdGfQyFzNiEze9KuFQrWGiLDvg6F1 | LTC: LbV6UGyjYbVP49NvQFmuAnkADcaFYvNagK | NMC: NDCdMJmTmGH54Cezmo3CwSxAC7grAoZJbj
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12908


View Profile
March 05, 2014, 11:10:48 PM
 #26

How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
March 05, 2014, 11:16:33 PM
 #27

How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.

How would it cause a problem?  If you don't have the ability to operate using https you simply shouldn't be operating (this goes for any site which needs to secure communication between server and client).   If something results in you losing your TLS cert for a period of time it would be better to not operate the site until it is restored.   If anything the only useful value for HSTS would be infinite (i.e. NEVER UNTIL THE END OF TIME CONNECT TO THIS DOMAIN INSECURELY) but since that is not an option a very long HSTS value is used as a proxy.
Xer0
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


°^°


View Profile
March 06, 2014, 03:00:27 PM
 #28

A? good joke
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!