4 ms·
Thanks for the info - it sounds like you've got things locked down pretty well already. The key bit as you say is the fact that the emails are stored on a syste
by jamieweb 8y ago
Thanks for the info - it sounds like you've got things locked down pretty well already. The key bit as you say is the fact that the emails are stored on a system that is not publicly accessible.
My biggest worry with anything like this is that if there is a breach at Blogsend that affects the readers of my blog, I'm still responsible for it as I'm the one who put the form on my site and encouraged my readers to enter their email address.
The last thing I want to have to do is use Blogsend to send a "Notice of data breach" email! :)
I've run my own similar system before (just for my blog) where readers could enter their email address, verify it and then receive notifications when I post. However, I discontinued this system as I didn't want the burden of storing personal data like that.
One think you could check out is adding security HTTP response headers - your site is pretty clean and simple so it should be relatively easy to get it locked down tightly. See https://securityheaders.com/ https://securityheaders.com/.
- fiiv 8y ago> The last thing I want to have to do is use Blogsend to send a "Notice of data breach" email! :) No one wants to have to send any of those emails, least of all me/Blogsend ;) > One think you could check out is adding security HTTP response headers - your site is pretty clean and simple so it should be relatively easy to get it locked down tightly. See https://securityheaders.com/ https://securityheaders.com/. Thanks for the tip! I've added this to my todos!