4 ms·
Hey u/trevelyan, any particular reason why the site isn't secured over https?
by jonnismash 8y ago
Hey u/trevelyan, any particular reason why the site isn't secured over https?
- craftyguy 8y agoOh the irony in releasing a service that depends on cryptography..
- trevelyan 8y agohey craftyguy -- thanks for the reply and for taking a look at Saito. You can access the server over https if you'd like at http://demo.saito.tech http://demo.saito.tech (this runs through a reverse proxy that layers on SSH) although this may break some links in our live demo. The reason the demo defaults to plain http is that the server that feeds out the applications is part of the full-node software and it does not support HTTPS yet. We are intent on fixing this, but it didn't seem like a critical thing to worry about for this dev release, which is focused on getting people a working version that can be run on localhost and give people the tools to build genuinely distributed applications. We hope to get this fixed in the next two months before launching our public testnet and DNS system. Right our biggest dev focus is overhauling the network code for multiclient connections. With that said, in the long-run it won't matter if users http or https to connect to the blockchain. Saito is not vulnerable to MITM attacks and users can use Diffie-Hellman key exchange mechanisms to swap keys directly over the blockchain. We can think of it as an improved version of TCP/IP that is actually secure but that will cost a few fractions of a cent for every message we need to send to unknown and anonymous peers.
- jonnismash 8y agoWow that sounds pretty damn great, I look forward to seeing the dev happen as time rolls. I will always call out non-SSL specifically when discussing all crypto-things but clearly you and the team have thought this out as per your detailed reply. Good luck on the project, I am for sure going to give the demo a test run.
- trevelyan 8y agoHi Jonnie, There is actually -- see comment blelow -- but if you're concerned about SSL just go through our reverse proxy that adds it. Some links may break: https://demo.saito.tech https://demo.saito.tech We should have default SSH in the full-node client itself by the time we launch our public testnet in a few months.