4 ms·
I've been using S3 static sites more and more and I think that exposing any kind of CMS control panel to the internet is a bad idea. Take a look at the list of
by ogig 10y ago
I've been using S3 static sites more and more and I think that exposing any kind of CMS control panel to the internet is a bad idea.
Take a look at the list of security concerns Airship tries to manage. Most can be avoided by separating the content creation aspect and the publishing platform. Content creators represent the smallest audience group your site has, why then have a full application exposed to the internet running only for them to easily change content? Content creators should have an offline app, make changes, press publish and have those changes uploaded to a static server. The whole CMS control panel paradigm seems kinda flawed to me.
- devwastaken 10y agoHardly is it that static content is the way to go when you're working with any sort of dynamic data. If you're just making blog posts, Airship most likely isn't for you. An offline app would cause a number of its own problems in that regard, because now you're actually having to design a backend that interface with your webserver and puts the content to it. What happens when you have multiple editors? You're now pulling information from a central resource, which is going to be over the internet, whether its on a different server or not. Not to mention, by having it 'offline', you can't have mobile apps to edit content on your site. Static definetely has advantages, but when scaled and working with data its not that simple.
- CiPHPerCoder 10y agoOne of the projects on our to do list is actually creating a static publishing module that can be used for either: - Offline editing for online publishing - Static mirrors to resist censorship in the face of DDoS Updates would be sent from an Airship to a static hub, using challenge-response authentication, with Ed25519 signatures. Aside from the API that receives data and triggers an update (which is intended to be set up on a different vhost), the attack surface will be minimal. The only reason this isn't already a thing is that I've had other projects that were higher priority, including one I'll be releasing in a month or so (but probably not submitting to HN; it's an entirely commercial project).