5 ms·
Thank you for your kind words! In closing I can assure you that your creations will live forever on 1MB as long as you don’t delete your account and follow ever
by 1mbsite 7y ago
Thank you for your kind words! In closing I can assure you that your creations will live forever on 1MB as long as you don’t delete your account and follow everything outlined on https://policy.1mb.site https://policy.1mb.site. Also pride ourselves in being more secure than your average free website host
- hopscotch 7y agoHave you had a proper security review? I don't think you would have made that mistake with user-websites being able to log out the user if you had designed with security as an important objective. Like, it's OK that you didn't, but maybe you should check that your entire public API (all microservices, UI, etc) will really be secure. You will probably struggle to get a secure interface while user content is served from the same domain as your UI.
- 1mbsite 7y agoFor reference @hopscotch appears to be referring to this post: https://forum.1mb.site/?t=1556326142930 https://forum.1mb.site/?t=1556326142930 I think the interaction in this forum thread says a lot about my focus on security. An issue was reported and I jumped on it immediately. I’m not going to sit here and claim to be perfect, but I am going to tell you that I work really hard to make sure I do stuff right and fix my mistakes ASAP. I have had white hat hackers review my API by the way and have patched reported security vulnerabilities.
- halter73 7y agoKudos for quickly adding an anti-csrf token to logout, but I agree with the grandparent that hosting arbitrary user content on the same TLD as the management interface is still problematic security-wise. See github.com vs github.io[1], amazon.com vs. elasticbeanstalk.com, azure.com vs azurewebsites.net, etc... Every major company I know of that hosts arbitrary user content dedicates a TLD to it that's not shared by the management APIs. [1] https://github.blog/2013-04-05-new-github-pages-domain-github-io/ https://github.blog/2013-04-05-new-github-pages-domain-githu...
- bugmen0t 7y agoYou likely want a separate domain indeed. See https://security.googleblog.com/2012/08/content-hosting-for-modern-web.html https://security.googleblog.com/2012/08/content-hosting-for-...
- 1mbsite 7y agoSites like Tumblr do it and are fine, and they allow custom HTML and JS also. Cookies are HTTP only and inaccessible with JavaScript. And framing is blocked.
- lol768 7y ago>I don't think you would have made that mistake with user-websites being able to log out the user if you had designed with security as an important objective. Really? In my experience not many people care about logout CSRF, it's the lowest of low risk vulns that infosec consultants write in a report when they don't have any real vulnerabilities. I'm not sure its presence really says much about the site overall. Effort is much better spent elsewhere - strict Content-Security-Policy, for example. Or, if there are 'real' CSRF vulns that actually do damage
- p1necone 7y agoHow are you guaranteeing that sites on 1MB will live forever?
- 1mbsite 7y agohttps://news.ycombinator.com/item?id=19774834 https://news.ycombinator.com/item?id=19774834
- chippy 7y agoThey are redefining "forever" to mean "until the service closes".
- p1necone 7y agoThis reminds me of "lifetime" warranties on products where "lifetime" is defined as some arbitrary lifetime of the product, rather than the lifetime of the buyer.
- mikestew 7y agoThat's...pretty much the guarantee for any product that claims "lifetime". The Tilley clothing company (best known for their hats) warrants many of their items "forever" as in (and I quote) "leave it in your will". That all goes out the window if Tilley goes out of business, however.
- p1necone 7y agoI don't know, that analogy doesn't quite seem right. This company is providing a service, not producing a product - it's more like if the Tilley clothing company said something like "we will continue manufacturing hats forever".
- markdown 7y ago> In closing I can assure you that your creations will live forever on 1MB I can assure you that the opposite is true. Tumblr deleted half their content. MySpace lost all their content. GeoCities lost everything. Facebook "accidentally" lost Zuckerberg's old posts and with all the money and software "engineers" in the world can't recover them. Startups and corporations that had the kind of money and technical expertise you could only dream of can't keep data forever. Don't get carried away and make promises there is no way you can keep. EDIT: I see you've redefined forever in the fine print: > 1MB is not a big company. This is a project funded, developed, and maintained by an individual. By subscribing to Pro you are helping keep this project online for years to come. > (1) Forever or for the life of the project. 1MB isn't going anywhere, but we also can't predict the future. No refunds!
- et-al 7y ago> GeoCities lost everything. Small nitpick, but Yahoo deleted everything. Let's not forget how poorly run Yahoo is.
- markdown 7y agoThanks for the clarification. For the purposes of my argument, the reason why the data no longer exists is irrelevant.
- mr__y 7y agoWhile I'm not trying to invalidate your point, it seems that given the size of 1MB sites you could have a backup of a few milions of websites for under $1[0]. Also, while the maximum size is 1mb not all sites would use all available quota so the actual average size will probably be lower than 1 megabyte driving the cost down even further. This means that that even without VS's or other investors a single person would be able to cover the costs of keeping those sites. Well, assuming there is a will to do so. [0] For example,archive storage at OVH runs at 0.0026$ per GB, so having a backup of 4 million 1mb sites would cost 1.04$/month for three copies of data.
- dvfjsdhgfv 7y ago> software "engineers" The quotes aren't necessary. They definitely have a few good software engineers, and this issue definitely isn't a technical one.
- tluyben2 7y agoI ran one of the larger free hosts and managed and hosted around 100 others; security is a big issue. If you get mildly popular the number of attacks will jump up. Hope you know more than I did and that the tech evolved enough; the hosts I built and managed were 10+ years ago and I had to create my own freehost specific patches to php, apache and mysql to protect from abuse. You do not do dynamic so that makes a large difference, still they will try! Edit; we also made custom scanners for porn and phishing; especially phishing, at that time had a simply pattern; the phishing page(s) would have keywords in them and would not be linked anywhere on the domain while not being the index.html. That allowed us to move almost all of them automatically.