Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔒 Website needs HTTPS support #307

Open
tantek opened this issue Mar 29, 2017 · 1 comment
Open

🔒 Website needs HTTPS support #307

tantek opened this issue Mar 29, 2017 · 1 comment

Comments

@tantek
Copy link

tantek commented Mar 29, 2017

Apologies if this is already on someone's to-do list somewhere.

Just noticed today when signing-in and liking some proposals, that opensourcebridge.org (and all the JS served from it) is HTTP-only (no HTTPS).

Besides all the usual reasons (see https://indieweb.org/HTTPS#Why) since the site has logins (even if OpenID / IndieAuth), it needs to support HTTPS to mitigate the Firesheep vuln.

Hopefully https://indieweb.org/HTTPS#How_to (in particular the LetsEncrypt pointers) can be helpful here.

Thanks for your consideration!

(full disclosure I too need to add proper HTTPS support to my own site, beyond the self-signed cert I'm using)

@reidab reidab modified the milestone: Open Source Bridge 2017 Apr 16, 2017
@reidab reidab changed the title Website needs HTTPS support 🔒 Website needs HTTPS support Apr 17, 2017
@gabelula gabelula assigned gabelula and 0xBEEB and unassigned gabelula Apr 30, 2017
@reidab
Copy link
Member

reidab commented May 31, 2017

As we figure this out, we should coordinate with @ChrisFreeman to get the volunteer app secured.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants