nvk / walletsrecovery.org

Information about wallet defaults for external recovery
https://walletsrecovery.org/
115 stars 96 forks source link

Enforce HTTPS for walletsrecovery.org #8

Closed ericallam closed 4 years ago

ericallam commented 4 years ago

Github Pages has an option for forcing HTTPS which will redirect clients that request http://walletsrecovery.org to https://walletsrecovery.org. See more here.

This prevents walletsrecovery.org from being trivially MITM'ed, which would allow an attacker to provide incorrect wallet recovery information which may give them access to a user's seed.

nvk commented 4 years ago

It's on the list of things to todo.

nvk commented 4 years ago

done.