Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enroll all Bisq infrastructure in HSTS preload lists #6

Open
7 of 9 tasks
wiz opened this issue Aug 13, 2020 · 6 comments
Open
7 of 9 tasks

Enroll all Bisq infrastructure in HSTS preload lists #6

wiz opened this issue Aug 13, 2020 · 6 comments
Assignees

Comments

@wiz
Copy link
Member

wiz commented Aug 13, 2020

All the Bisq infrastructure should enroll in HSTS preload list if not already done so:

@sqrrm
Copy link
Member

sqrrm commented Aug 14, 2020

Could you explain what this does? It seems to complain about sqrrm.net, not surprising as it's not point anywhere.

@devinbileck
Copy link
Member

bisq.services is pending submission.
I have a dummy site on netlify that I added the header to.

@Emzy
Copy link
Contributor

Emzy commented Aug 15, 2020

emzy.de is now pending inclusion in the HSTS preload list.

@wiz
Copy link
Member Author

wiz commented Aug 15, 2020

@sqrrm HSTS just disables non-https HTTP protocol in web browsers for the domain name, which is best practice these days to prevent MITM attacks by malicious Tor exit nodes

@wiz
Copy link
Member Author

wiz commented Aug 22, 2020

FYI it seems that adding bisq.network to the HSTS list a year ago in bisq-network/bisq-website#210 most likely protected Bisq from this recent MITM attack from Tor exit nodes: https://blog.torproject.org/bad-exit-relays-may-june-2020

@mrosseel
Copy link
Member

Status: vante.me is pending submission to the preload list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants