6 ms·
You are right. But you can play with our platform this weekends, and on next week we'll opening agent to open-source and enable security. We have some delay wit
by lastbackend 11y ago
You are right. But you can play with our platform this weekends, and on next week we'll opening agent to open-source and enable security. We have some delay with SSL delivery. :(
- antocv 11y agoI, for one, aint playin with anything you build. You aint coming close to having sudo on any of my machines if I can help it. This shit with "enable security" as after-thought has to stop.
- deleted 11y ago[deleted]
- meddlepal 11y agoI agree. Basically makes me distrust the whole thing inside and out; who knows what other bs engineering practices were used in non visible parts of the stack? Shipping is great, but please don't ship insecure stuff as a product you want customers to use. Please.
- lastbackend 11y agoWe are enabled HTTPS. THX for your comments. Next: installer update. Give us few minutes.
- meddlepal 11y agoGreat. Glad to see you're taking this seriously and hopefully it is a good lesson learned for the future!
- pauloschilling 11y agoHere: https://www.ssllabs.com/ssltest/analyze.html?d=app.lastbackend.com https://www.ssllabs.com/ssltest/analyze.html?d=app.lastbacke... Overall Rating: C This server is vulnerable to the POODLE attack. If possible, disable SSL 3 to mitigate. Grade capped to C.
- tpg 11y agoWhen I see security as a second-class citizen on user-visible elements, I assume that the same philosophy was applied on the parts I can't audit, even after the front-end stuff was fixed.
- deleted 11y ago[deleted]
- runlevel1 11y agoJust get a free cert from StartSSL while you wait for your other cert to go through. It's better than nothing. Asking people on HN to send their passwords in the clear is suicide.