ContentMine / contentmine.org

The static site
1 stars 4 forks source link

Require HTTPS for subdomains of contentmine.org #12

Open ghost opened 7 years ago

ghost commented 7 years ago

Similar to #7, but for subdomains, e.g. discuss.contentmine.org .

Currently, https://discuss.contentmine.org gives a connection error, whereas http://discuss.contentmine.org serves its content as expected.

As Discourse (the software being run at discuss.contentmine.org) requires users to be logged in, and to enable JavaScript, in order to be able to post, the lack of HTTPS puts ContentMine developers at highly increased risk of Firesheep-style attacks and JavaScript injection attacks, especially when using shared WiFi.