3 ms·
It's not just security, it is also privacy. But even if it was just security, it would be irresponsible to offer something (a blog) and knowingly compromise se
by mAritz 9y ago
It's not just security, it is also privacy.
But even if it was just security, it would be irresponsible to offer something (a blog) and knowingly compromise security for anyone who is interested.
- Joeboy 9y agoHow am I compromising anybody's privacy or security by hosting information about my defunct bare metal Raspberry Pi project? What is the threat model?
- Cthulhu_ 9y agoDoes it have an admin interface? Without encryption, your username / password are broadcast unencrypted; if intercepted by whoever, they can hijack your blog and post spam / spread malware / subtly inject some JS to mine some dank monero.
- Joeboy 9y agoNope.
- mAritz 9y agoThe traffic can be intercepted and changed. If someone trusts you (say you gave them the link) but the content they are being served is not the content you intended to be shared, is that not a security issue? ISPs have been known to inject ads for example.
- Joeboy 9y agoThe former is not likely to be an issue for the site I'm talking about. Ad injection is shitty but I don't think it makes my blog "irresponsible".
- ozim 9y agoMeltdown/Spectre kind of vulnerability plus injecting Javascript to anything that is http only by rouge ISP employee or user on open rouge wifi. It is not about targeted attacks it is about low hanging fruit which any http site is and bots, automated hacking/injecting. Like people saying that changing SSH port on your VPS is not security. Setup one Linux VPS and see how many bots are trying to brute force your password. Just change the port so they stop trying.