Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dolfje
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
dolfje
11y ago
I find this the most interesting part: "As we look at the data about outdated software, we see a real trend. (We used the alexa top lists) The top 10 most visited sites are ‘fully safe’. They don’t leak a lot of software information, b
92.
▲
One in three servers have outdated software
(patrolserver.com)
3 points
by
dolfje
11y ago
|
1 comments
93.
▲
by
dolfje
11y ago
That is because wordpress has just had another update. So basically everyone is outdated at the moment. But luckily the automatic updates of Wordpress will update most in the following hours/days. So it will become green ;)
94.
▲
by
dolfje
11y ago
We will come back with some more details, but at the moment we are having an internal discussion of how many details can be published. So expect it somewhere next week.
95.
▲
by
dolfje
11y ago
Indeed the problem is solved. The mobile stylesheet wasn't loaded on production. Sorry for the inconvenience. But glad you noticed and warned us ;)
96.
▲
by
dolfje
11y ago
Thanks everybody! 1 day on Hacker News, 1574 uniques, 103 signups, 15% signup rate and 53% total vulnerability rate. You all have some fixing to do. If you have more feedback, let us know (or spread the love).
97.
▲
by
dolfje
11y ago
Thanks, solved ;)
98.
▲
by
dolfje
11y ago
Good question! As you already hinted, we will not disclose all our security measures. But our platform is secured on multiple levels. First of all, all communication between you and our server is encrypted. No eaves-dropping possible. So
99.
▲
by
dolfje
11y ago
There is more logic to it. We try to detect if you use ubuntu/debian and suggest those updates. From the moment we know the exploits, we show them. Probably you're talking about PHP? For PHP 5.5.25 there are the following exploits
100.
▲
by
dolfje
11y ago
We indeed compare versions against the latest version of the software. Though we also keep track of which versions are supported and also create an inventory with the CVEs and their risk. There are also vulnerability scanners incorporated.
101.
▲
by
dolfje
11y ago
Thank you very much for the feedback! We have had multiple meetings about the security concern of mail communication. And we opted (for now) to send the information by mail, just for the convenience and rapid delivery to the end user. Also
102.
▲
Show HN: PatrolServer – Continuous updates of the vurnabilities on your servers
(patrolserver.com)
12 points
by
dolfje
11y ago
|
16 comments
103.
▲
by
dolfje
11y ago
I encourage all people to check their website. On our checker ( http://security.uwsoftware.be/logjam ) we see that 59% is still vulnerable (<= 1024 key). Even after checking most people don't upgrade. Note: the soluti
104.
▲
by
dolfje
11y ago
So for a full test, I would recommend https://tls.so/ or https://www.ssllabs.com/ssltest/ . But if you just want to check if your server has the logjam vulnerability, I would suggest http://